metir
metir
Docs
Download on App StoreGet it on Google PlayLoginSign Up
Back to Blog
DeepSeek
Moonshot AI
Anthropic
China AI
AI Regulation

China Probes DeepSeek and Moonshot Over Data Routed to Claude

China's internet regulator has opened an investigation into DeepSeek and Moonshot after Anthropic alleged the two secretly routed millions of user requests to Claude. The case sits at the intersection of model distillation, data sovereignty and US-China diplomacy.

Metir AI TeamSeptember 23, 20269 min read
China Probes DeepSeek and Moonshot Over Data Routed to Claude

China's Cyberspace Administration has opened an investigation into DeepSeek and Moonshot AI following allegations by Anthropic that the two companies secretly routed millions of user requests through Claude, according to reporting from The Information, Quartz, Decrypt and South China Morning Post published on September 22 and 23, 2026. The case is unusual because it inverts the more familiar story of Chinese firms copying Western models. Here, a Chinese regulator is scrutinizing its own national champions, and the trigger was a report from a US AI lab. Underneath the headline sit three separate issues that are easy to conflate: model distillation, live request routing, and data sovereignty.

DeepSeek logoDeepSeek
Moonshot AI logoMoonshot AI
Anthropic logoAnthropic
Claude logoClaude
The dispute pits two of China's leading AI labs against Anthropic, whose September threat report set the investigation in motion.
23M+Exchanges Moonshot allegedly routedThrough 5,380 fraudulent accounts, per Anthropic
12.1M+Exchanges DeepSeek allegedly routedIn a 14-day window in July, per Anthropic
7China-based labs namedIn Anthropic's September 10 report
2Labs now under formal probeDeepSeek and Moonshot

What Anthropic actually alleged

On September 10, 2026, Anthropic published a threat intelligence report accusing seven China-based AI labs of what it called illicit distillation. The claim has two layers, and the difference between them is the whole story.

The first layer is distillation itself: using a competitor's model outputs to train your own. A developer queries a stronger model at scale, collects its answers, and uses them as training data to teach a cheaper model to imitate it. This violates most model providers' terms of service, and accusations of it have circulated around several labs for years. On its own it is a commercial and contractual dispute.

The second layer is the one that turned this into a regulatory matter. Anthropic alleged that DeepSeek and Moonshot did not merely harvest Claude's outputs for training, but routed requests from their own live users to Claude. In that account, a person using a Chinese company's app, believing their query was being handled by a Chinese model, would have had that query processed by Anthropic's model on US infrastructure. Anthropic put specific numbers on the scale: Moonshot allegedly routed more than 23 million exchanges through 5,380 fraudulent accounts, and DeepSeek generated more than 12.1 million exchanges in a 14-day window in July.

“

The distinction that matters is between training on a rival's outputs and silently sending your users' live requests to that rival.

On the two layers of Anthropic's allegation

It is important to be precise about the status of these figures. They are allegations from one party, published in that party's own report, and the accused companies had not, at the time of the reporting cited here, publicly responded in detail. The Chinese regulator's investigation is precisely an attempt to establish whether they are accurate.

Why the regulator cares, and it is not about Anthropic

The reflexive reading is that Beijing is defending Anthropic's intellectual property. It is almost certainly the opposite. What reportedly alarmed the Cyberspace Administration is the data-sovereignty implication: if Chinese users' requests were being sent to servers in the United States, then potentially sensitive Chinese data left the country without authorization.

The example that has drawn the most attention involves government work. Reporting describes engineers building a case-management system for a municipal Public Security Bureau, China's local police, whose requests were allegedly relayed to Claude, including data used to compare an individual's movements against police records and national identification numbers. Whether or not that specific account holds up, it illustrates the regulator's concern cleanly: a routing arrangement invisible to the end user becomes a channel through which police, military or state-linked corporate data could cross a border. For a government that has built an extensive legal regime around data localization, that is a first-order national security question, entirely separate from any harm to Anthropic.

The horseshoe-shaped table and mural of the United Nations Security Council chamber in New York
The UN Security Council chamber. DeepSeek was due to brief the Council on AI risks in the same week China's regulator narrowed its probe, one of several threads placing the case on a diplomatic stage.

The diplomatic timing is not a coincidence

The investigation surfaced in a crowded diplomatic week. DeepSeek was scheduled to brief the UN Security Council on AI risks, and President Trump was set to meet Xi Jinping on September 24, with AI reported to be among the topics. Moonshot, for its part, had filed confidentially for a Hong Kong initial public offering on September 3, reportedly targeting around $3 billion, which raises the commercial stakes of any finding against it considerably.

Three weeks in September

How the allegations, the regulatory response and the diplomatic backdrop lined up in the same month.

Sep 3

Moonshot files confidentially for a Hong Kong IPO, reportedly targeting about $3 billion.

Sep 10

Anthropic publishes a threat report accusing seven China-based labs of illicit distillation and of routing user requests to Claude.

Sep 22 to 23

China's Cyberspace Administration summons the seven named companies, then narrows its probe to DeepSeek and Moonshot.

Sep 23

DeepSeek is due to brief the UN Security Council on AI risks.

Sep 24

President Trump is set to meet Xi Jinping, with AI reported to be on the agenda.

None of that context proves anything about the underlying allegations, but it does shape the incentives. A public investigation lets Beijing demonstrate that it enforces its own data rules against its own companies, a useful position to hold going into talks where data governance and AI competition are live issues. It also signals to Chinese firms that routing domestic user data abroad, whatever the technical convenience, carries regulatory risk. The timing turns a corporate-integrity question into a piece of statecraft.

The distillation question no one can fully answer

Sitting beneath the specific case is a genuinely hard technical problem: distillation is extremely difficult to prove. Modern models are trained on overlapping public data and increasingly on synthetic data generated by other models, so two models sounding similar is weak evidence of copying. Detecting that one model was trained on another's outputs usually relies on statistical fingerprints, watermarks, or, as in this case, access-log analysis showing suspicious query patterns from accounts that appear to belong to a competitor. Access logs are stronger evidence than stylistic similarity, which is likely why Anthropic leaned on account-level data, but they establish that queries were made, not necessarily how the results were used.

This is why the routing allegation is the more consequential of the two. Training on scraped outputs is a contract violation that is hard to prove and, for a regulator, largely a private matter. Silently sending live user requests to a foreign model is a factual claim about data flows that logs can substantiate and that implicates a body of law a government cares about enforcing. The investigation will likely turn on the second question far more than the first.

Sep 3Moonshot files for HK IPOReportedly targeting about $3B
Sep 10Anthropic publishes its reportSeven labs named
Sep 24Trump-Xi meetingAI reported to be on the agenda

The takeaway

Strip away the geopolitics and the case comes down to a question every user of any AI product should be able to answer: when you send a request to a model, do you know which company's model actually processes it, and where? The allegation against DeepSeek and Moonshot, whether or not it is ultimately upheld, describes a world in which the answer was hidden from the people asking the questions, and in which that opacity created a cross-border data flow a government considered a security risk. As AI services increasingly route, proxy and subcontract requests behind the scenes, provenance and data residency stop being back-office details and become the substance of both trust and compliance. Being able to see and choose which model handles a given task, and where that processing happens, is not a niche enterprise concern. It is the transparency that makes the rest of the system accountable, and it is a principle Metir AI treats as foundational in how it routes work across models.

Sources:

  • China Probes DeepSeek and Moonshot Over Alleged Data Leaks to Anthropic's Claude | Decrypt
  • China probes DeepSeek, Moonshot over user data sent to Anthropic | Quartz
  • China Probes DeepSeek, Moonshot AI Over Anthropic's Claims They Route Requests to Claude | Gizmodo
  • Moonshot, DeepSeek secretly routed user requests to Claude, Anthropic claims | South China Morning Post
  • China Probes DeepSeek, Moonshot Over Potential Data Leaks to Anthropic | The Information
  • DeepSeek, Moonshot Reportedly Face China Scrutiny Over Anthropic Claims Ahead Of Trump-Xi AI Talks | Yahoo Finance

Image credits

  • Hero and in-body figure: United Nations Security Council chamber. Source: Wikimedia Commons. Reviewed before publication; the photograph depicts the UN Security Council chamber, referenced because DeepSeek was due to brief the Council on AI risks the same week. Full per-file licence and attribution recorded in this folder's credits.md.

Ready to experience AI that adapts to you?

metir brings together the world's best AI models in one seamless experience. Start for free today.

Get Started Free
metir

Agentic Operating System for Professionals buried in meetings, emails and docs.

© 2026 metir. All rights reserved.

Product

  • Features
  • Pricing
  • Research
  • Docs
  • Blog
  • Enterprise

Company

  • Docs
  • Support
  • Careers

Legal

  • Terms of Service
  • Privacy Policy

Personalisation is powerful. Privacy is non-negotiable.

Status: All systems operational