China is investigating DeepSeek and Moonshot over routing to Claude, on evidence only Anthropic holds
China's internet regulator is reported to be investigating DeepSeek and Moonshot over user requests relayed to Anthropic's Claude. No regulator finding, no company answer and no confirmed breach is on the public record.
By Parminder Kumar Sharma · · 18 min read

Ten exchanges a second, for a fortnight
Anthropic's September threat report gives one headline figure for DeepSeek: over 12.1 million exchanges observed over 14 days in July 2026. Divide it out and that is about 864,000 exchanges a day, or roughly ten every second, sustained around the clock for a fortnight. That number is now, on today's reporting, sitting in front of a Chinese regulator.
It is also a number that does not establish most of what is being hung on it. It is Anthropic's count of exchanges it attributes to a distillation campaign, measured on Anthropic's own systems. It is not a count of DeepSeek customers whose requests were secretly rerouted. It is not a count of people whose personal information crossed a border. And it is not a finding by anyone with the power to make findings.
On 22 September 2026, twelve days after Anthropic published, The Information reported that China's Cyberspace Administration is investigating DeepSeek and Moonshot AI over user data routed to Claude. The story reached the wires at 11:19 UTC. We could not read it: it sits behind a subscription, and everything in this briefing about its contents comes from outlets that summarised it, which is itself part of the problem this briefing is about.
We covered the underlying allegation against Moonshot on 17 September, in Anthropic says Moonshot served Claude as Kimi. This briefing does not repeat it. It deals with the new thing: a state regulator taking an interest, which laws could bite, and what a UK buyer should do about a risk that does not depend on who is right.
What is reported, and what is confirmed
Two claims are being merged in the coverage. The first is Anthropic's, published in detail on 10 September. The second is that a Chinese regulator has opened an investigation, which rests on one subscription publication citing people it does not name, summarised onwards by wires and aggregators. Neither claim has been tested by anyone who can compel evidence.
We checked the Cyberspace Administration's own published channels on 22 September. Its news and announcements listings carry a livestreaming meeting, an app privacy notice covering 30 apps, an AI safety governance framework and a generative AI filing announcement. Nothing about DeepSeek, Moonshot, Anthropic or Claude.
The reported investigation: what is on the record and what is not, from The Information as summarised by Investing.com, Newsquawk and Infocast, checked against the Cyberspace Administration's own site on 22 September 2026
| Question | Reported | Not established |
|---|---|---|
| Which body | The Cyberspace Administration of China | No notice, case reference or legal basis published by it |
| Who is in scope | All seven labs named in Anthropic's report were summoned, then the focus narrowed to DeepSeek and Moonshot | Whether any process continues for Alibaba, Zhipu, SenseTime, MiniMax or Xiaomi |
| What is being examined | Whether police, military and state-linked corporate data reached a United States model | Which data, whose, in what volume, or over what period |
| Action so far | Officials went to both companies and spoke to executives and staff, per Infocast's summary | Any order, fine, suspension, filing requirement or referral |
| Penalties | Not decided, while severity and intent are weighed | Any timetable, charge or outcome |
| Company response | None found from either company on the routing claim | Any denial, admission or explanation |
| Anthropic's position | No public statement on the investigation found | Whether Anthropic has been contacted by, or is cooperating with, any Chinese authority |
Watch the headline drift, because it will reach your risk register. The Information's own headline says potential data leaks. By the time the story is syndicated, headlines say breaches, and a paragraph later the alleged routing is stated as established fact. The chain runs: one provider's telemetry, one report, one subscription story about an unannounced investigation, then a hundred restatements with the hedges stripped out.
Three different allegations, routinely merged
Anthropic's report describes three distinct behaviours. They carry very different consequences for a customer, and only one of them is what a data regulator would normally care about.
The three allegations in Anthropic's September 2026 report, pages 144 to 151, and where the evidence for each sits
| Allegation | What it does to a customer's data | Where the evidence sits |
|---|---|---|
| Distillation: harvesting a rival's outputs to train a model | Nothing, where the traffic is the lab's own | Anthropic's telemetry, plus advisory AA26-251A, which names DeepSeek and Moonshot for distillation |
| Reasoning extraction: replaying a thinking signature in a new session to recover the full trace | Nothing directly | Anthropic's telemetry and the attacker prompts it quotes |
| Live rerouting: a lab's own customers' requests sent to Claude, and Claude's answers returned as the lab's own | Everything in the prompt reaches a company the customer never chose, in a country the customer never chose | Anthropic's telemetry alone: no regulator finding, no company admission, no indicators published |
The reported investigation is about the third. That is the only one of the three that is a personal information question inside China rather than an intellectual property or contract question between companies. It is also the one with the thinnest public evidence base: the provider on the receiving end is the only party that can see relayed traffic arrive, and it has not published its attribution method for these cases.
What routing through Claude actually means
The report's account of DeepSeek is specific. DeepSeek is said to have checked strings in inbound requests to tag users arriving through coding harnesses such as Claude Code, the Claude Agent SDK or OpenCode, and then relayed selected tagged users' requests to Claude Opus. Moonshot is said to have run its relay through a proxy network of 5,380 accounts Anthropic calls fraudulent, most appearing to be in Singapore and Japan. Anthropic does not offer its services in mainland China, which is why proxies and fraudulent accounts appear in the account at all.
Why coding harnesses? Because they are the one place where a Chinese model service routinely receives traffic already addressed to Claude. DeepSeek publicly documents an Anthropic-compatible endpoint at https://api.deepseek.com/anthropic, and publishes instructions telling developers to point Claude Code at it by overriding the Anthropic base URL environment variable. Its documentation states that models "starting with claude-opus are mapped to deepseek-v4-pro", with Sonnet and Haiku names mapped to a smaller DeepSeek model.
This matters beyond China. Any service that accepts another vendor's API dialect inherits the same property. The request arrives labelled for one provider, the response comes back in that provider's shape, and nothing in the exchange proves which company's hardware produced the tokens.
Where is the breach?
Several versions of this story carry the word breaches. No breach has been confirmed by anyone. There is no notification to a regulator on the public record, no incident report from either company, and no finding.
What the report describes is an unauthorised onward disclosure rather than an intrusion. Its examples are blunt: an engineer building a case management system for a municipal Public Security Bureau, whose tool compares a person's movements against police records using citizens' national identity numbers; an information technology operator working with data from a Russian government agency associated with its defence ministry, whose relayed requests exposed live credentials for a Russian government database; and, in the Moonshot case, an engineer at a large Chinese state-owned enterprise who revealed internal code and live credentials. Anthropic says the customers were likely not aware.
Breach language against the record, using the Personal Information Protection Law definition and Anthropic's report
| Claim in circulation | What the record supports | What it does not support |
|---|---|---|
| Data breaches at DeepSeek and Moonshot | Anthropic says content reached it that the customers did not know was leaving | Any intrusion, theft, or third-party attacker |
| Police and military data was leaked | The report describes police case management work and surveillance data reaching Claude | That any specific citizen record, or any classified material, was exposed |
| Credentials were exposed | The report says live credentials appeared in relayed prompts | Whether they were used, rotated, or ever at risk beyond the receiving provider |
| Chinese users were notified | Nothing | Article 57 of the Personal Information Protection Law requires notice of a leak to the regulator and to individuals; no such notice is public |
There is an uncomfortable symmetry here that neither side will enjoy. The sensitive material is known about because the receiving provider's investigators read what arrived. That is normal trust and safety practice at every provider, and it is exactly the exposure the alleged routing created: content read by a company the user never contracted with.
Which Chinese rules would bite, and what each would need shown
No legal basis has been published, so what follows is our analysis of the instruments that would apply if the routing allegation were established, not a description of the case. The point of laying them out is the last column: each one needs a fact that no published source currently supplies.
Chinese instruments that would be in scope, read at source on cac.gov.cn. The third column is pk-sharma.com analysis
| Rule | What it requires | What would have to be established |
|---|---|---|
| Personal Information Protection Law, Article 38 | One of three routes before personal information goes abroad: a state security assessment, certification by an approved body, or the standard contract with the overseas recipient | That personal information left China and that no route was completed |
| Personal Information Protection Law, Article 39 | Tell the individual the overseas recipient's name and contact details, purpose, method and categories, and obtain separate consent | That users were not told and did not separately consent |
| Provisions on cross-border data flows, Articles 7 and 8 | Assessment at 1,000,000 people, or 10,000 people's sensitive personal information; standard contract or certification from 100,000 people | The number of distinct people, which no published figure gives |
| Interim Measures for Generative AI Services, Article 11 | Providers must not unlawfully provide users' input information and usage records to others | That prompts and logs went to a third party without a lawful basis |
| Data Security Law, Articles 31 and 46 | Important data may only leave under the measures set for it, with fines to 10,000,000 yuan in serious cases | That relayed content is important data, a category set by catalogues, not by how sensitive it feels |
| Personal Information Protection Law, Article 66 | Up to 50,000,000 yuan or 5 per cent of the previous year's turnover in serious cases, with suspension and licence powers | A serious infringement, found by the competent department |
Now do the arithmetic that the coverage skips. The thresholds above count people. Anthropic's figures count exchanges. One developer inside a coding harness can generate hundreds of requests in a day, so 12.1 million exchanges is consistent with a few thousand people or with several million. The only person-scale figure in the report is small: across DeepSeek, Xiaomi and Moonshot, sessions relayed from third-party routers contained the data of "hundreds of end users in at least a dozen languages". Hundreds is three orders of magnitude below the 100,000 person threshold at which the lightest export route is required, and the report does not break that figure down by lab or by country.
Our inference, not a claim in any source: the volume that determines the Chinese thresholds is not in the public record at all, which means nobody outside the companies and the regulator can say which gate should have been passed.
One more feature of the alleged route cuts against the labs. On Anthropic's account the traffic reached Claude through accounts that appeared to be in Singapore and Japan. If personal information collected in China took that path, the hop is not a mitigation. It is an additional export.
The endpoint carries Anthropic's name, and that settles nothing
This story is a catalogue of comforting labels that are not controls.
A model name in an API call is a label. An endpoint path that contains a provider's name is a label. A router's data policy tag is a label: OpenRouter, one of the aggregators whose users Anthropic says appear in the relayed traffic, says plainly that its tags are "not a definitive source of third party data policies, but represents our best knowledge". A storage location is a label too, and the wrong one: DeepSeek's privacy policy, last updated 10 February 2026, says it collects, processes and stores personal data in the People's Republic of China, and lists sharing with categories of service providers, including third-party search and analytics services. A category list is not a sub-processor list, and a storage clause says nothing about where inference happens.
China's own regulator already treats relays as a regulated activity, though on different grounds. On 15 September, five days after Anthropic published, the Cyberspace Administration released ten enforcement cases. One concerned a Jiangsu company running two websites as an API relay station calling several large model interfaces to provide chat and question answering without the required security assessment: warning, rectification order and action against those responsible. Another fined a Shanghai company for sending users' personal information to overseas data centres without declaring an export security assessment.
Neither case is connected to DeepSeek or Moonshot, and neither is about telling customers which model answered them. They show the machinery that exists, and the grounds it currently runs on: filings and content safety, not routing transparency.
Method, motive, and the traffic going the other way
Three things are true at once, and a briefing that drops any of them is doing advocacy.
First, Anthropic has a direct commercial interest. DeepSeek and Moonshot compete with it in agentic coding, the market Claude sells into. Second, Anthropic is nonetheless the only party positioned to see relayed traffic arrive, and its report is specific about mechanism in a way that inventions usually are not. Third, the report still does not publish the attribution method for these cases, and its companion indicator file carries nothing for the distillation section, so nobody outside the company can test it.
The traffic in the other direction has its own file. On 8 July 2026, China's National Vulnerability Database, run under the Ministry of Industry and Information Technology, said Claude Code contained "security backdoor risks, posing a severe threat" in versions 2.1.91 to 2.1.196, alleging transmission of user location and identity data to Anthropic's servers without consent. Anthropic rejected the characterisation. One of its engineers described the mechanism publicly as an experiment "meant to prevent account abuse from unauthorized resellers and protect against distillation", and the company described checks on time zone and on routing from unsupported regions or from labs suspected of distillation.
We are not asserting a link between that mechanism and the current allegations, and no source we read draws one. The observation is narrower and worth holding: the same class of client-side signal that one government called a backdoor is the class of signal that produces the evidence the other government is now reportedly examining. Both states treat a data flow into the other's AI stack as a security matter, and both are right to.
The timing is political on both sides. The reported investigation surfaced two days before Donald Trump and Xi Jinping are due to meet, with officials discussing an AI dialogue that could include notifying each other of significant AI incidents. A Chinese regulator visibly disciplining its own champions over data leaving the country is a card in that room. So is a United States report published two days after a joint intelligence advisory. Weigh the checkable claims on their merits and discount the choreography.
What a UK organisation should take from a Chinese regulator's probe
Nothing here turns on whether Beijing acts. Two exposures apply to UK organisations now, and they point in different directions.
The first is the data path. Anthropic says many relayed exchanges came from users of third-party model routing services "commonly used by users in the United States and Europe", and that those sessions contained names, email addresses, company data and other sensitive data of hundreds of end users in at least a dozen languages. There is no UK breakdown, and no source we read gives one. If your staff reach models through a router or an aggregator, your prompts are in the population the report describes, whether or not the routing allegation stands up.
The second is continuity, and it is the one most UK risk registers miss. The realistic near-term disruption to a Chinese model service is not a United States export control. It is its own regulator. Article 21 of the Interim Measures lets authorities order a provider to suspend services where it will not rectify or where the case is serious. A supplier that vanishes for a fortnight is an availability incident you own.
Supplier assurance for any third-party AI service, including routers and aggregators. pk-sharma.com analysis, with the NCSC secure AI design guidelines as the baseline
| Question to put in writing | An answer that is not an answer | What good looks like |
|---|---|---|
| Which company's model, on whose infrastructure, served this specific request? | We use our own proprietary technology | Response metadata naming model, version and serving region, retained in logs you can query |
| Who else may receive our prompts? | A category list such as service providers or information technology providers | Named upstream providers per product and per endpoint, with notice of changes and a right to object |
| Where are prompts processed, as distinct from stored? | Data is stored in country X | A processing location commitment that also covers fallback and overflow capacity |
| What happens if your own regulator restricts you? | Silence, or a force majeure clause | Notification duty, a stated continuity plan, and an exit you have actually tested |
The NCSC's guidelines for secure AI system development, published in November 2023, already put this in scope: working with an external model provider "includes a due diligence evaluation of that provider's own security posture", and where an external API is used you should apply "appropriate controls to data that can be sent to services outside of your organisation's control". The contract terms that close these gaps, including named sub-processors and per-request attestation, are set out in our 17 September briefing and are not repeated here.
What to do, in order
Take this with you
Actions worth doing this week
- Inventory every route by which staff or systems reach a third-party model: direct APIs, routers and aggregators, coding harnesses, IDE plugins and browser extensions.
- Search developer and build configuration for overridden base URLs, such as an Anthropic or OpenAI endpoint variable pointing at another company's service, and record who approved each one.
- For every model service headquartered outside the UK and EU, record what its published terms actually say about onward disclosure, processing location and training use. Treat a category list of service providers as a gap, not an answer.
- Where a router is in use, enable and retain its per-generation records so you can show which upstream endpoint served each call, and sample them monthly.
- Stop credentials, secrets and regulated personal data reaching any model endpoint without a signed data processing agreement, and scan prompts for secrets where your tooling allows it.
- Put the four supplier questions above to every AI vendor in writing, and keep the answers with the contract rather than in an inbox.
- Add regulatory continuity for Chinese model vendors to the supplier risk register, with a named alternative model and a tested switch, not an aspiration.
- Record the Cyberspace Administration investigation as reported and unconfirmed, with a review date, and do not restate one provider's telemetry as a finding in your own risk papers.
The question that exposes the gap
The Chinese users in this story, if the allegation is right, had no way to know that their prompts were being answered in another jurisdiction by a company they had never heard of, and no way to find out afterwards. Neither, in most organisations, would yours.
So the question to put to your own team, before you put anything to a supplier: if a regulator asked you today to show, for one specific prompt one of your staff sent last month, which company's model answered it and in which country, what would you produce?
Key facts
Sources
- PrimaryDetecting and countering misuse of AI: September 2026, 154 pages. Read for cases GTG-16001 (DeepSeek) and GTG-16002 (Moonshot), pages 144 to 151, and for every figure attributed to Anthropic hereAnthropicaccessed 2026-09-22
- PrimaryWeb version of the September 2026 threat report, used to confirm the report text and publication dateAnthropicaccessed 2026-09-22
- PrimaryTen enforcement cases published on 15 September 2026, including an unlawful personal information export case and an API relay station case, read in full for the laws citedCyberspace Administration of Chinaaccessed 2026-09-22
- PrimaryData export security policy questions and answers, September 2026, read for the certification and assessment thresholds and the bar on splitting volumesCyberspace Administration of Chinaaccessed 2026-09-22
- PrimaryText of the Personal Information Protection Law, read for Articles 23, 28, 38, 39, 40, 57 and 66Cyberspace Administration of Chinaaccessed 2026-09-22
- PrimaryProvisions on promoting and regulating cross-border data flows, read for the Article 7 and Article 8 volume thresholds and the Article 5 exemptionsCyberspace Administration of Chinaaccessed 2026-09-22
- PrimaryInterim Measures for the Management of Generative AI Services, read for Article 11 on users' input information and Article 21 on suspension of servicesCyberspace Administration of Chinaaccessed 2026-09-22
- PrimaryText of the Data Security Law, read for Articles 21, 31, 45 and 46 on important data and penaltiesCyberspace Administration of Chinaaccessed 2026-09-22
- PrimaryDeepSeek documentation for its Anthropic-compatible endpoint, read for the base URL and the model name mappingDeepSeekaccessed 2026-09-22
- PrimaryDeepSeek instructions for pointing Claude Code at its endpoint by overriding the Anthropic base URLDeepSeekaccessed 2026-09-22
- PrimaryDeepSeek privacy policy, last updated 10 February 2026, read for the controller, storage location and service provider wordingDeepSeekaccessed 2026-09-22
- PrimaryProvider routing documentation, read for the data policy filter wording and the generation stats endpointOpenRouteraccessed 2026-09-22
- PrimaryJoint advisory AA26-251A of 8 September 2026 on China-based distillation campaigns, read for which companies it names and what it does not allegeCISA, NSA and FBIaccessed 2026-09-22
- PrimarySpokesperson's response of 9 September 2026 to the United States distillation advisoryMinistry of Commerce of the People's Republic of Chinaaccessed 2026-09-22
- PrimaryGuidelines for secure AI system development, secure design section, read for the supply chain and external API wordingNCSCaccessed 2026-09-22
- Reported byOriginal report of the investigation by Qianer Liu and Jing Yang. Headline and bylines only: the article is behind a subscription and we could not read itThe Informationaccessed 2026-09-22
- Reported bySummary of The Information's report, used for the list of seven companies summoned and the police surveillance detailInvesting.comaccessed 2026-09-22
- Reported byTimestamped headline, used to fix when the report reached the wires on 22 September 2026Newsquawkaccessed 2026-09-22
- Reported byChinese language summary of The Information's report, used for officials visiting the two companies and for no penalty decision having been takenInfocast via Yahoo Hong Kongaccessed 2026-09-22
- Reported bySummary used for the timing against the Trump and Xi meeting and the proposed AI incident notification mechanismStocktwits via Yahoo Financeaccessed 2026-09-22
- Reported byCoverage of 11 September 2026, used for the absence of any company response and for Beijing's position on the United States advisorySouth China Morning Postaccessed 2026-09-22
- Reported byReport of 8 July 2026 on China's National Vulnerability Database warning about Claude Code, used for the quoted warning and Anthropic's explanationCBS News and AFPaccessed 2026-09-22


