China Probes DeepSeek, Moonshot Over Alleged Data Privacy Risks From Claude Routing

Abeerah Hashim  - Security Expert
Last updated: September 24, 2026
Share
  • China’s top web agency is looking into DeepSeek and Moonshot AI over claims that user data went to Anthropic.
  • Anthropic says DeepSeek sent requests from engineers building a case system for a Chinese police bureau to Claude.
  • The probe follows Anthropic’s claim that both Chinese labs sent millions of user requests to Claude without telling customers.

China’s internet regulator is looking into DeepSeek and Moonshot AI after Anthropic said both firms sent user data to Claude. The Cyberspace Administration of China, or CAC, sent staff to question leaders and workers at both firms, The Information said.

The probe came after Anthropic’s Sept 10 report. The U.S. AI firm said seven Chinese firms used Claude on a large scale to help build their own AI models. They were DeepSeek, Moonshot, Alibaba, Zhipu, SenseTime, MiniMax, and Xiaomi. Anthropic said the work led to almost 190 million chats.

The Information said CAC first questioned all seven firms named by Anthropic. It later focused on DeepSeek and Moonshot. The probe does not mean the agency has found a breach. It is still checking what data moved, who sent it, and why.

Police data was allegedly sent to Claude

One of the key cases involves DeepSeek. Anthropic said engineers building a case system for a city police bureau used DeepSeek. The system could match a person’s moves with police files using national ID numbers.

Anthropic said DeepSeek sent those requests to Claude. So data used to build the police system may have reached Anthropic without the users knowing. However, Anthropic did not say a data breach took place. Its report says the routed chats were used to gather Claude answers for training.

Anthropic said DeepSeek sent more than 12.1 million chats to Claude in 14 days in July. The company also cited a worker at a Chinese tech firm who used DeepSeek to study work files. Another case involved a Russian state agency tied to its Defense Ministry. According to Anthropic, those chats exposed live login keys for a Russian state database.

Moonshot case involved surveillance data

Anthropic made similar claims about Moonshot, the firm behind Kimi. It said Moonshot sent user requests to Claude rather than Kimi. It then showed Claude’s answers to users, Anthropic said.

In one 10-day span, Anthropic found almost 300,000 user requests that Moonshot sent to Claude. It said Moonshot used 5,380 fake accounts to get access. Most seemed to be in Singapore and Japan.

From May through July, Anthropic linked more than 23 million chats to Moonshot. The report also described a camera case. Anthropic said a user it judged likely linked to the People’s Liberation Army used Kimi to study CCTV video. The video tracked one person across hundreds of cameras in Chengdu. Some cameras were near PLA sites, defense labs and a large state-owned firm.

Anthropic said Moonshot sent the request and video to Claude without the user knowing. That does not show the material was secret or that China had a confirmed data breach. Anthropic is the source for this account, and Moonshot has not confirmed it.

Why the probe matters

Anthropic says DeepSeek and Moonshot used Claude to help build their own AI systems. This practice, called distillation, uses answers from a stronger AI model to train another one. Anthropic called the work unauthorized. It said the firms used many accounts and proxy services to reach Claude.

The security concerns surrounding DeepSeek extend beyond its use of external AI models. A separate report, DeepSeek AI faces security concerns over alleged jailbreak method, examines claims that a jailbreak method could bypass safeguards in the AI system.

In February, Anthropic said DeepSeek, Moonshot and MiniMax made more than 16 million chats through about 24,000 fake accounts. Its September report added more claims. It said the firms also sent some real user requests through Claude. That creates a new issue for Beijing.

China has strict rules for data sent abroad. The state also sets tight rules for AI firms and data. If private Chinese data left the country without approval, the firms could face data and rule checks. But the probe has not shown that any such rule was broken.

No penalties have been announced

The CAC probe is still underway, The Information said. Officials are checking how serious the data claims are and why they may have happened.

The agency has not announced fines or other penalties. Neither firm has given a full public reply to Anthropic’s claims. The Information also reported that CAC had not decided whether to penalize either company. The probe comes as Beijing and Washington get set for talks on AI risks and ties.

DeepSeek is also due to brief the U.N. Security Council on AI and world security this week, Reuters reported. Senior Anthropic staff are also due to join the meeting. For now, the main question is still open: did Chinese user data reach Anthropic through DeepSeek and Moonshot, and how much? China’s probe may provide the answer. Until officials publish their findings, Anthropic’s claims remain unproven.

Share this article

About the Author

Abeerah Hashim

Abeerah Hashim

Security Expert

Abeerah is a passionate technology blogger and cybersecurity enthusiast. She yearns to know everything about the latest technology developments. Specifically, she’s crazy about the three C’s; computing, cybersecurity, and communication. When she is not writing, she’s reading about the tech world.

More from Abeerah Hashim

Comments

No comments.