Invest1 publisher3 min readPublished
Beijing turns Anthropic's Claude complaint into a data-export investigation of DeepSeek
The Cyberspace Administration of China has questioned all seven labs Anthropic named in September. It is deciding whether relaying Chinese users' prompts to Claude broke the country's cross-border data rules.
The Investor · Invest desk

What happened
- Chinese regulators are investigating DeepSeek and Moonshot AI over allegations that both firms secretly routed sensitive user queries to Anthropic's Claude models without telling their customers.
- Anthropic said that during the July window it examined, DeepSeek rerouted more than 12.1 million of its own users' queries to Claude over 14 days.
- Moonshot forwarded almost 300,000 customer requests to Claude across ten days through 5,380 fraudulent accounts that mostly appeared to be located in Singapore and Japan, according to Anthropic.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
- exposure Any company whose staff used DeepSeek's hosted service in July has to assume some of those prompts were answered by a US vendor's model while the interface said otherwise, and that assumption now belongs in a data inventory.
- constraint Because the Cyberspace Administration is testing this against China's cross-border data rules, the enforcement path runs against the Chinese labs under Chinese law and delivers Anthropic nothing for the copying it alleges.
- contradiction Every volume figure comes from the company that sells the model it says was copied, while Beijing's officials call the distillation complaint an attempt to hold back China's AI sector, so the regulator's finding is the first independent test of the numbers.
- precedent If routing user prompts offshore through 5,380 foreign-registered accounts counts as an unlawful cross-border transfer, every Chinese vendor quietly reselling foreign frontier capacity sits under the same rule.
Divide 12.1 million by 14 and the July relay runs at about 864,000 queries a day [5][1]. Moonshot's almost 300,000 over ten days is about 30,000 a day [7][2], so DeepSeek moved roughly 29 times as much traffic per day [3]. Moonshot's went through 5,380 accounts Anthropic called fraudulent, which is about 56 requests each over the ten days [7][4]. In my view the account count is the design: 56 requests from a key registered in Singapore looks like a developer trying things out, and 300,000 from one key does not.
Anthropic's heaviest user of the seven was Alibaba, with more than 151 million exchanges between May and July 2026 [11]. Across the 92 days of those three months that is about 1.6 million a day, near twice DeepSeek's July rate [5][6]. The investigation reported by Cryptopolitan covers DeepSeek and Moonshot, and the Cyberspace Administration called in representatives of all seven firms Anthropic named for several rounds of questioning [1][2]. The two allegations sit under different law. Buying 151 million exchanges to train a student model is Anthropic's commercial injury; a Chinese user's prompt travelling to a US server is a matter for China's rules on moving data across its borders [4].
What crossed, on Anthropic's account, included information tied to a Chinese technology firm's AI program, data linked to a Russian government agency, and records from a Chinese municipal police system [9]. Anthropic also said DeepSeek extracted Claude's hidden reasoning steps, which it calls a "thinking signature", and used that to help train its own systems [10]. Anthropic judged one Moonshot-linked user likely affiliated with the Chinese military, using the service to review surveillance footage [17].
For anyone buying inference, the exposure described here sits at the endpoint. Both allegations concern requests users sent to DeepSeek's and Moonshot's own services, where the answers came from Claude while the user believed they were using DeepSeek's models or Kimi [6][16]. Weights downloaded and run on your own hardware cannot forward a prompt to a third party. The question to put to a vendor is where the inference happens, not which checkpoint is loaded.
Anthropic is the sole source for every volume in this story, it detected them on its own systems, and it sells the model it says was copied; its September 2026 report covers activity it detected and shut down between December 2025 and August 2026 [13]. Two outcomes would break the data-export reading: the Cyberspace Administration finishing its questioning without a penalty [2], or DeepSeek and Moonshot producing terms that disclosed third-party routing all along. Anthropic said it was unable to confirm whether Moonshot's users knew their queries were being rerouted [8].
US and Chinese officials have agreed to keep talking about AI safety and emergency communication, with another meeting expected in Shenzhen within two months [15].
What to watch
- A penalty notice from the Cyberspace Administration, or the questioning closing without one, would settle whether cross-border transfer is the actual charge.
- Any of the other five summoned firms being added to the investigation alongside DeepSeek and Moonshot.
- Terms of service from either company showing third-party routing was disclosed to users all along.