Product1 publisher3 min readPublished
China's internet regulator questions DeepSeek and Moonshot staff over data Anthropic may have received
The Information reports that the Cyberspace Administration has questioned staff at both labs after Anthropic named seven Chinese companies for relaying customer requests through Claude. No penalty has been decided.
The Product Desk · Product desk

What happened
- The Information's Jing Yang and Qianer Liu reported that the Cyberspace Administration of China is investigating DeepSeek and Moonshot over user data that may have reached Anthropic, and that regulators have questioned staff at both.
- All seven China-based labs named in Anthropic's report were summoned by the regulator before the inquiry settled on DeepSeek and Moonshot, on the strength of the examples the report detailed.
- According to The Information, one example had a user Anthropic assessed as likely PLA-affiliated ask Kimi to track a person across hundreds of Chengdu police cameras, with the footage passed to Claude without telling the user.
- Neither company has commented publicly, no penalty has been decided, and TNW says it has not independently verified The Information's report.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
- exposure A product whose route ends at a Chinese-hosted Kimi or DeepSeek endpoint now depends on a licensing regulator that can order a service withdrawn without a court, on its own timetable.
- decision Anyone weighing self-hosted weights against a vendor API has reason to price that difference while the timing of the switch is still theirs to choose.
- constraint With the probe open and nothing ruled, a rollout owner has no finding to plan against and has to make the call on the possibility of one.
- precedent An American vendor's threat report has become the evidentiary base for a Chinese regulator's inquiry. The next such report is a compliance problem for every lab it names.
A team that put Kimi behind a fallback route in July has a narrower problem than the one in the headlines. It needs to know whether the endpoint answers on Monday, and whether there is a new checkpoint to upgrade to next quarter. The Cyberspace Administration of China licenses AI services for the domestic market, polices what leaves the country in the way of data, and can order products withdrawn [4]. It does not need a court to act [4].
The conduct at issue is a relay. Anthropic said seven China-based labs pushed customer requests through Claude and harvested the output, a practice it calls illicit distillation [6]. With Moonshot, Anthropic said the requests were forwarded silently and the answers shown to users as though Kimi had written them [13]. Beijing's complaint runs the other way from Anthropic's, and is about Chinese users' data landing on an American company's servers without those users knowing [17].
The inquiry did not follow the volumes. Alibaba's logged total of more than 151 million exchanges [9] is about 80 per cent of the roughly 190 million in the published report [8][1]. DeepSeek and Moonshot together come to about 35 million, or roughly 18 per cent [2]. Jing Yang of The Information wrote that the probe narrowed because of the examples Anthropic detailed, not the totals [14]. Police camera footage and material tied to defence institutes sit in the categories China's own cross-border data rules treat most carefully [16].
DeepSeek's campaign was short and heavy: more than 12.1 million exchanges inside 14 days in July [11], about 864,000 a day, against roughly 250,000 a day for Moonshot's 23 million spread across May to July [10][3]. The account handling is the part a platform team will recognise. Anthropic counted almost 300,000 Moonshot requests in one ten-day window across 5,380 fraudulent accounts [13], about 56 requests per account [4]. I think that traffic was shaped to stay under per-account limits.
The powers in the account are domestic ones: licensing for the Chinese market, and the power to withdraw a product there [4]. Nothing in it touches weights already downloaded, or availability outside China. Anthropic's window on the alleged misuse runs from December 2025 to August 2026 [7].
Two other names on the list had their own week. Zhipu apologised on Monday after a developer found its ZCode tool uploading encrypted snapshots of local code repositories without consent [19]. Xiaomi published the highest-scoring open-weight model yet released on Tuesday and has not answered the Anthropic allegation [20].
The split I'd draw is between where the model reaches you from and what depends on the call. Weights on your own hardware keep serving whatever the CAC decides; a vendor-hosted endpoint inside China sits behind a licence that can be pulled [4]. Cross that with whether the call is a fallback or the only path behind a feature a customer sees. A fallback going dark costs you a slower response. A sole path going dark costs you the feature. Count the hours it takes to repoint that route before the regulator decides anything.
What to watch
- Whether the CAC names a violation, and whether it lands on cross-border data transfer or on service licensing.
- Whether DeepSeek, Moonshot or Xiaomi answer Anthropic's allegation on the record.
- Whether the summonses to Alibaba, MiniMax, Zhipu and SenseTime turn into active investigations as well.