Wednesday Sep 23

China Probes The Labs Anthropic Named

23SEP
190M EXCHANGESTHE REPORTTHE PROBE

Anthropic said seven Chinese labs relayed 190 million requests through Claude. Twelve days later, China's internet regulator summoned all seven. The probe now centers on DeepSeek and Moonshot.

The Information broke it: the Cyberspace Administration of China questioned staff at both companies. No penalty yet. Neither has commented. On September 10 Beijing had called the US distillation advisory unfounded.

Why those two: one example in the report had a suspected PLA-linked user ask Moonshot's Kimi to track a person across hundreds of Chengdu police cameras. Kimi quietly passed the footage to Claude.

The complaint flipped direction. Anthropic's grievance was output leaving Claude. Beijing's is Chinese data landing on American servers. Same evidence, opposite reading. Moonshot is prepping a Hong Kong IPO.

full brief & sources

⚡ Why this matters

  • A US lab's threat report became a Chinese regulator's evidence file. Anthropic did not ask for that, and cannot control what Beijing does with it.
  • Data sovereignty now cuts both ways. Alibaba banned Claude Code in July for sending data abroad. Now Chinese labs are in trouble for the same thing in reverse.
  • Distillation is no longer only an IP fight. Once relayed requests include police footage, it is a national security matter in both capitals.

🔍 What happened

  • Anthropic's September 10 threat intelligence report named Alibaba, Moonshot AI, DeepSeek, Zhipu, MiniMax, Xiaomi and SenseTime, covering roughly 190 million exchanges relayed through Claude between December 2025 and August 2026.
  • Alibaba accounted for more than 151 million exchanges. Moonshot about 23 million. DeepSeek's campaign was smaller but denser: 12.1 million in 14 days in July.
  • The Information reported September 22 that the CAC summoned all seven and is investigating DeepSeek and Moonshot over user data that may have reached Anthropic. Staff at both were questioned. No penalty has been decided.
  • One detailed example: a user Anthropic assessed as likely PLA-affiliated asked Kimi to analyze surveillance footage following a person across hundreds of Chengdu police cameras, including near PLA facilities. Moonshot passed it to Claude without telling the user.
  • DeepSeek briefs the UN Security Council this week. Moonshot is working toward a Hong Kong listing, where an open investigation must appear in the prospectus.
  • Zhipu spent last week apologizing for its ZCode tool uploading local code repositories without consent. Xiaomi released the highest-scoring open-weight model to date on Tuesday.

💬 Smart takes

  • Jing Yang, The Information: "While the CAC summoned all 7 companies namechecked by Anthropic's report, the probe quickly zeroed in on DeepSeek and Moonshot due to the examples the report detailed."
  • Alina Maria Stan, TNW: "China is not endorsing Anthropic's complaint. It has found its own inside the same evidence."
  • Skeptic: the largest campaign in the report belongs to Alibaba, which is not under investigation. This may be a probe of the politically convenient, not the worst offender.

🧭 Where this goes

  1. LikelyMoonshot's Hong Kong listing slips a quarter while the investigation stays open.
  2. LikelyChina's regulator adds explicit rules on relaying user data through foreign models.
  3. PossibleAnthropic's next threat report names fewer companies, or names them less specifically.
  4. Wild CardBeijing fines DeepSeek days before or after its UN Security Council briefing.

🥄 The Spoon Take

Anthropic wrote a report about theft and Beijing read it as a report about leakage. Both readings are true. The lesson for anyone shipping AI across borders is that a relay is a data export, whichever way the request travels. Alibaba escaping the probe while running the biggest campaign tells you this is politics wearing a compliance badge.

🤔 Pushback

The report is from The Information, unverified by TNW, with no comment from either company, and no penalty has been decided.