The Cyberspace Administration of China is investigating DeepSeek and Moonshot AI over allegations that they routed users’ requests to Anthropic’s Claude models, according to The Information.
Officials have reportedly interviewed executives and employees at both companies as they examine whether sensitive information was transferred to Anthropic without users’ knowledge.
The probe follows Anthropic’s 154-page report published Sept. 10, which accused seven Chinese AI companies of using Claude to improve their own models. The companies named were Alibaba, Moonshot, DeepSeek, Zhipu, MiniMax, Xiaomi and SenseTime. China’s regulator reportedly summoned representatives from all seven before narrowing its attention to DeepSeek and Moonshot.
Anthropic said it observed more than 23 million exchanges linked to Moonshot between May and July and more than 12.1 million linked to DeepSeek over 14 days in July. It accused both companies of forwarding some customer requests to Claude and using the resulting exchanges to improve their own models through distillation.
The data question is bigger
The investigation introduces a separate issue from whether Chinese AI companies improperly used Claude’s capabilities: whether their users’ information was sent to an outside AI provider without their knowledge.
Anthropic said some Moonshot requests included sensitive material. One example involved surveillance footage from hundreds of cameras in Chengdu, including cameras outside People’s Liberation Army facilities and defense-linked institutions. Another involved a DeepSeek user working with Russian government data whose requests exposed live database credentials, according to Anthropic.
Anthropic also said some DeepSeek customers’ requests involved police surveillance systems and sensitive corporate information. Across the labs covered in its report, Anthropic said some relayed exchanges contained names, email addresses and company data.
Neither company has publicly commented on the reported investigation, and Chinese authorities have not announced penalties.
A complicated moment for China’s AI push
The probe matters because China has been building an AI ecosystem designed to reduce reliance on US technology. Anthropic’s allegations suggest that at least some Chinese developers may nevertheless have been using Claude as an outside source of model capabilities.
That creates an unusual regulatory problem: the same activity can raise two different concerns. Anthropic sees its model being used to develop competing systems, while Chinese regulators are examining whether information from Chinese users traveled to a US company.
The distinction could become important for AI developers everywhere. Using an outside model as part of an AI system is one thing; silently forwarding customers’ private prompts to that model is another. The case shows why companies deploying AI services need to know not only which model they advertise, but which model actually processes customer data.
More must-read AI coverage
- SS&C Intralinks DealCentre AI vs. Datasite: Which platform is built for the future of dealmaking?
- SS&C Intralinks FundCentre AI vs. Juniper Square: Which platform better supports modern private markets fund managers?
- Why Data, Not Models, Determines AI Success
- The Rise of the AI-Native Factory: How Physical AI Is Transforming Manufacturing
What this means for everyday users
For ordinary users, the central issue is where a chatbot request actually goes.
A person using a Chinese AI service may reasonably assume that their prompt is being processed by that service. Anthropic’s allegations suggest that, in some cases, requests could instead have been sent to Claude without users knowing.
That makes transparency important. Users handling company information, credentials, personal records or sensitive material should understand which systems process their data and whether information can be transferred to third-party AI providers.
Chinese authorities have not announced a finding against either company. For IT teams, the practical question is whether an AI vendor or routing service sends prompts to another model provider. Check that path before allowing credentials, customer records or internal documents into the service.
Read more: US agencies’ earlier allegations about Chinese AI model distillation explain the model-access dispute behind the reported probe and the questions enterprise customers should ask about AI routing.