Beijing Is Investigating Its Own Labs Over What They Sent Claude
Anthropic's distillation report was supposed to be an American IP complaint. China's cyberspace regulator has turned it into a data-export case against DeepSeek and Moonshot.
When Anthropic published its 154-page threat report on September 10, the obvious reading was an American lab accusing Chinese rivals of copying its homework. Twelve days later, the most consequential reaction has come not from Washington but from Beijing.
China's internet regulator, the Cyberspace Administration of China (CAC), is investigating DeepSeek and Moonshot AI over whether they sent sensitive Chinese data to Claude, according to The Information, citing people familiar with the matter. Bloomberg and others have followed the report. The CAC's question is not whether the two labs stole from Anthropic. It is whether they leaked to it.
What the report alleged
Anthropic's report described seven China-based labs running what it called illicit distillation campaigns against Claude: Alibaba, Moonshot, DeepSeek, Zhipu, MiniMax, Xiaomi and SenseTime. Distillation means training a model on a stronger model's outputs. Anthropic called the activity "the largest distillation attack we have ever measured." Coverage of the report puts the combined total at roughly 190 million exchanges between May and July. Alibaba alone accounted for about 151 million.
Two of the seven were accused of something different from bulk extraction.
Anthropic says Moonshot ran more than 23 million exchanges through Claude between May and July, using 5,380 fraudulent accounts. Much of that traffic was not synthetic. According to the report as described in coverage, Moonshot quietly forwarded real Kimi user requests to Claude, including nearly 300,000 in one ten-day window. In one example, a Kimi user's query about surveillance cameras connected to Chinese military facilities was answered by Claude without the user knowing it had left the country.
DeepSeek is alleged to have sent more than 12.1 million exchanges over a 14-day period in July, relaying user requests without consent. The most pointed detail: Anthropic says DeepSeek forwarded requests from engineers working on a police surveillance system.
Anthropic wrote that the prompts included "sensitive information, including from individual users, major multinational companies, and state-affiliated actors." It said they contained names, email addresses and company data belonging to hundreds of end users, in at least a dozen languages.
Why the CAC narrowed to two
According to Decrypt's account of The Information's reporting, the CAC first summoned all seven companies, then narrowed its focus to DeepSeek and Moonshot. Officials have reportedly visited both companies' offices to interview executives and staff. They want to know what categories of data went out, whether users were told their queries could leave Chinese systems, and whether police, military or state-linked corporate data reached U.S. servers.
The narrowing makes sense once you separate the two kinds of alleged behavior.
Generating prompts, sending them to Claude and keeping the answers is an IP and terms-of-service problem, and the aggrieved party is Anthropic. Beijing has no particular reason to punish a domestic lab for it. Quietly routing a Chinese user's live request to an American model is a different act. Under China's rules on cross-border data transfers, that looks like an unauthorized export of personal and possibly state-sensitive data. The alleged victims are Chinese users and Chinese institutions.
Put simply, the only part of the story Beijing cares about is the part where China's data went to the U.S., not the part where the U.S. lab lost value.
Why it matters
The distillation debate just gained a second enforcer. Until now, the only practical defenses against distillation were the ones labs could build themselves: account bans, identity checks and, in Anthropic's case, summarizing or encrypting internal reasoning so it is harder to harvest. Those raise the cost, but proxy networks and stolen API keys keep finding a way in. A Chinese regulator treating covert routing to a foreign model as a data-security violation creates a deterrent inside the jurisdiction where the activity happens. That is something no American terms of service can do.
The lab's user becomes the evidence. The allegation against Moonshot and DeepSeek rests on users who believed they were talking to a domestic system. That changes the trust question for every Chinese assistant. If a Kimi or DeepSeek answer might have come from Claude, then the model card, the privacy policy and the national-security review all described a product that was not actually running. Regulators do not tolerate that gap in any market. They tolerate it least in China, where data localization is a political principle.
The timing is bad for both companies. According to Decrypt, Moonshot filed confidentially for a Hong Kong IPO on September 3, a week before the report landed. A live CAC data-security investigation is exactly the kind of risk factor that prospectus lawyers have to disclose and investors have to price. DeepSeek, meanwhile, is reportedly set to brief the UN Security Council on AI risk this week. It is an awkward week to be under investigation by your own government for how you handle sensitive data.
It lands on the eve of the Trump–Xi summit, where AI is reportedly on the agenda. Anthropic's report gives Washington a documented example of Chinese labs leaning on American models. The CAC probe gives Beijing a way to show it is policing that behavior on its own terms, as a sovereignty matter rather than a concession.
What to watch
The Information's reporting is sourced to people familiar with the matter. As of publication, neither DeepSeek, Moonshot nor the CAC had publicly detailed the probe. Anthropic's figures are its own attribution and have not been independently audited. Three things will show how serious this gets.
The first is whether the CAC publishes findings or penalties. Past data-security cases have ended in app removals and mandated rectification, not just fines. The second is whether Moonshot's IPO timetable slips. The third is whether the remaining five labs get pulled back in if new evidence of user-data routing appears.
The larger shift has already happened. Frontier distillation used to be a story about one lab's losses. It is now a story about where a user's words actually go, and both governments have a stake in that answer.
