China's Cyberspace Administration has opened an investigation into DeepSeek and Moonshot AI following allegations by Anthropic that the two companies secretly routed millions of user requests through Claude, according to reporting from The Information, Quartz, Decrypt and South China Morning Post published on September 22 and 23, 2026. The case is unusual because it inverts the more familiar story of Chinese firms copying Western models. Here, a Chinese regulator is scrutinizing its own national champions, and the trigger was a report from a US AI lab. Underneath the headline sit three separate issues that are easy to conflate: model distillation, live request routing, and data sovereignty.
DeepSeek
Moonshot AI
Anthropic
ClaudeWhat Anthropic actually alleged
On September 10, 2026, Anthropic published a threat intelligence report accusing seven China-based AI labs of what it called illicit distillation. The claim has two layers, and the difference between them is the whole story.
The first layer is distillation itself: using a competitor's model outputs to train your own. A developer queries a stronger model at scale, collects its answers, and uses them as training data to teach a cheaper model to imitate it. This violates most model providers' terms of service, and accusations of it have circulated around several labs for years. On its own it is a commercial and contractual dispute.
The second layer is the one that turned this into a regulatory matter. Anthropic alleged that DeepSeek and Moonshot did not merely harvest Claude's outputs for training, but routed requests from their own live users to Claude. In that account, a person using a Chinese company's app, believing their query was being handled by a Chinese model, would have had that query processed by Anthropic's model on US infrastructure. Anthropic put specific numbers on the scale: Moonshot allegedly routed more than 23 million exchanges through 5,380 fraudulent accounts, and DeepSeek generated more than 12.1 million exchanges in a 14-day window in July.
The distinction that matters is between training on a rival's outputs and silently sending your users' live requests to that rival.
On the two layers of Anthropic's allegation
It is important to be precise about the status of these figures. They are allegations from one party, published in that party's own report, and the accused companies had not, at the time of the reporting cited here, publicly responded in detail. The Chinese regulator's investigation is precisely an attempt to establish whether they are accurate.
Why the regulator cares, and it is not about Anthropic
The reflexive reading is that Beijing is defending Anthropic's intellectual property. It is almost certainly the opposite. What reportedly alarmed the Cyberspace Administration is the data-sovereignty implication: if Chinese users' requests were being sent to servers in the United States, then potentially sensitive Chinese data left the country without authorization.
The example that has drawn the most attention involves government work. Reporting describes engineers building a case-management system for a municipal Public Security Bureau, China's local police, whose requests were allegedly relayed to Claude, including data used to compare an individual's movements against police records and national identification numbers. Whether or not that specific account holds up, it illustrates the regulator's concern cleanly: a routing arrangement invisible to the end user becomes a channel through which police, military or state-linked corporate data could cross a border. For a government that has built an extensive legal regime around data localization, that is a first-order national security question, entirely separate from any harm to Anthropic.

The diplomatic timing is not a coincidence
The investigation surfaced in a crowded diplomatic week. DeepSeek was scheduled to brief the UN Security Council on AI risks, and President Trump was set to meet Xi Jinping on September 24, with AI reported to be among the topics. Moonshot, for its part, had filed confidentially for a Hong Kong initial public offering on September 3, reportedly targeting around $3 billion, which raises the commercial stakes of any finding against it considerably.
Three weeks in September
How the allegations, the regulatory response and the diplomatic backdrop lined up in the same month.
Moonshot files confidentially for a Hong Kong IPO, reportedly targeting about $3 billion.
Anthropic publishes a threat report accusing seven China-based labs of illicit distillation and of routing user requests to Claude.
China's Cyberspace Administration summons the seven named companies, then narrows its probe to DeepSeek and Moonshot.
DeepSeek is due to brief the UN Security Council on AI risks.
President Trump is set to meet Xi Jinping, with AI reported to be on the agenda.
None of that context proves anything about the underlying allegations, but it does shape the incentives. A public investigation lets Beijing demonstrate that it enforces its own data rules against its own companies, a useful position to hold going into talks where data governance and AI competition are live issues. It also signals to Chinese firms that routing domestic user data abroad, whatever the technical convenience, carries regulatory risk. The timing turns a corporate-integrity question into a piece of statecraft.
The distillation question no one can fully answer
Sitting beneath the specific case is a genuinely hard technical problem: distillation is extremely difficult to prove. Modern models are trained on overlapping public data and increasingly on synthetic data generated by other models, so two models sounding similar is weak evidence of copying. Detecting that one model was trained on another's outputs usually relies on statistical fingerprints, watermarks, or, as in this case, access-log analysis showing suspicious query patterns from accounts that appear to belong to a competitor. Access logs are stronger evidence than stylistic similarity, which is likely why Anthropic leaned on account-level data, but they establish that queries were made, not necessarily how the results were used.
This is why the routing allegation is the more consequential of the two. Training on scraped outputs is a contract violation that is hard to prove and, for a regulator, largely a private matter. Silently sending live user requests to a foreign model is a factual claim about data flows that logs can substantiate and that implicates a body of law a government cares about enforcing. The investigation will likely turn on the second question far more than the first.
The takeaway
Strip away the geopolitics and the case comes down to a question every user of any AI product should be able to answer: when you send a request to a model, do you know which company's model actually processes it, and where? The allegation against DeepSeek and Moonshot, whether or not it is ultimately upheld, describes a world in which the answer was hidden from the people asking the questions, and in which that opacity created a cross-border data flow a government considered a security risk. As AI services increasingly route, proxy and subcontract requests behind the scenes, provenance and data residency stop being back-office details and become the substance of both trust and compliance. Being able to see and choose which model handles a given task, and where that processing happens, is not a niche enterprise concern. It is the transparency that makes the rest of the system accountable, and it is a principle Metir AI treats as foundational in how it routes work across models.
Sources:
- China Probes DeepSeek and Moonshot Over Alleged Data Leaks to Anthropic's Claude | Decrypt
- China probes DeepSeek, Moonshot over user data sent to Anthropic | Quartz
- China Probes DeepSeek, Moonshot AI Over Anthropic's Claims They Route Requests to Claude | Gizmodo
- Moonshot, DeepSeek secretly routed user requests to Claude, Anthropic claims | South China Morning Post
- China Probes DeepSeek, Moonshot Over Potential Data Leaks to Anthropic | The Information
- DeepSeek, Moonshot Reportedly Face China Scrutiny Over Anthropic Claims Ahead Of Trump-Xi AI Talks | Yahoo Finance
Image credits
- Hero and in-body figure: United Nations Security Council chamber. Source: Wikimedia Commons. Reviewed before publication; the photograph depicts the UN Security Council chamber, referenced because DeepSeek was due to brief the Council on AI risks the same week. Full per-file licence and attribution recorded in this folder's credits.md.