- Anthropic alleges that DeepSeek and Moonshot AI routed sensitive Chinese data to its Claude model without user consent, prompting a Chinese government probe.
- The companies allegedly used over 35 million exchanges to train their own models via 'illicit distillation,' according to Anthropic's threat-intelligence report.
- The probe adds to escalating U.S.-China tensions over AI, data sovereignty, and national security.
China Launches Probe into AI Startups
Chinese authorities are investigating whether AI startups DeepSeek and Moonshot AI allowed sensitive data from Chinese users to reach Anthropic’s Claude model without proper disclosure. The probe follows allegations from Anthropic, which claimed in a September threat-intelligence report that it disrupted "illicit distillation" operations—using a competitor model’s outputs as training material—between December 2025 and August 2026. The report named seven China-based labs, including DeepSeek and Moonshot.
According to people familiar with the matter, the investigation is focused on potential violations of China’s data security and cross-border data transfer rules. A formal probe has not been publicly confirmed by Chinese regulators, and China’s Foreign Ministry has denied Anthropic’s characterization, accusing the U.S. company of distorting facts. "China supports AI for good," a ministry spokesperson said, rejecting the allegations as politically motivated.
Anthropic’s Allegations Detail Massive Data Routing
Anthropic alleges that Moonshot, which operates the Kimi assistant, silently forwarded customer requests to Claude and returned Claude’s responses as its own. The company attributes more than 23 million exchanges to Moonshot from May through July, including nearly 300,000 purported customer requests over a 10-day period through 5,380 fraudulent accounts. Similarly, DeepSeek allegedly routed more than 12.1 million exchanges to Claude over 14 days in July. Anthropic says some diverted prompts included corporate material, identities, and data tied to state-linked users—raising concerns beyond model-copying to potential unconsented cross-border data transfer.
The financial stakes are high. DeepSeek, founded by Liang Wenfeng, has an estimated annual recurring revenue of about $500 million and a valuation-to-revenue multiple of roughly 163x, per Rhodium. Moonshot, led by CEO Yang Zhilin, is estimated at $1 billion ARR with a multiple of around 50x. Both companies have been invited to make statements at a UN Security Council discussion on AI risks this week, though DeepSeek’s founder is not expected to attend, according to Reuters sources.
Regulatory and Market Implications
The probe underscores China’s tightening scrutiny of AI data governance. The country’s generative-AI rules, effective since August 2023, require security assessments for services with significant public-opinion functions, and labeling requirements for AI-generated content were adopted in 2025. If authorities conclude that prompts crossed borders without legal basis, DeepSeek and Moonshot could face audits, data-localization obligations, and reputational damage.
For enterprise users, the controversy may prompt a reassessment of whether prompts, source code, or proprietary material remain within declared processing chains. "Companies need to treat model-routing intermediaries as critical vendors," said an industry analyst, speaking on condition of anonymity. "A contract with one AI brand may not reveal every model that handles a request."
Anthropic, led by CEO Dario Amodei, estimates its own revenue at roughly $65 billion on an ARR basis, far exceeding Chinese counterparts. Rhodium estimates Chinese AI models generate only about 10% of the revenue of OpenAI and Anthropic, despite rapid adoption. The incident could accelerate fragmentation of the global AI ecosystem, with Chinese firms relying more on domestic infrastructure and U.S. firms tightening access to high-risk jurisdictions.
Diplomatic and Industry Fallout
The timing is delicate. U.S. and Chinese officials have agreed to further AI-safety talks ahead of expected Trump–Xi discussions, and the UN Security Council is increasingly focused on AI risks. Anthropic’s report follows earlier claims that Chinese labs made large volumes of Claude requests using account networks. The company says it has banned associated misuse and strengthened monitoring.
Moonshot declined to comment on the probe or on reports that it has confidentially filed for a Hong Kong IPO. DeepSeek did not respond to requests for comment. Chinese regulators, including the Cyberspace Administration of China, have not publicly announced an investigation.
Correction: An earlier version of this article misstated the estimated ARR for Anthropic. It is approximately $65 billion, not $65 million.