China probes DeepSeek and Moonshot AI over data routing as model-distillation dispute expands from U.S. technology protection to Chinese data sovereignty
Allegations that Chinese AI companies engaged in industrial-scale distillation of advanced U.S. AI models have entered a new phase. The first concrete regulatory move has come not from additional U.S. sanctions, but from China. Chinese internet regulators are reportedly investigating DeepSeek and Moonshot AI over whether user data was routed to Claude, the AI model developed by U.S.-based Anthropic.
The investigation changes the nature of the model-distillation dispute. In the United States, the central concern has been whether Chinese companies extracted reasoning capabilities from advanced U.S. models. In China, a different question is emerging: whether sensitive data belonging to Chinese companies, public institutions and users was sent to a U.S. AI model. The same API is now raising regulatory concerns on both sides — U.S. technology protection in one direction and Chinese data sovereignty in the other.
In a threat intelligence report released on September 10, Anthropic alleged that Chinese companies used proxy services and large networks of accounts to collect Claude outputs. It said it observed more than 151 million exchanges attributable to Alibaba-related distillation activity between May and July, more than 23 million involving Moonshot AI during the same period, and more than 12.1 million involving DeepSeek over 14 days in July. Anthropic also attributed more than 3.4 million exchanges over 17 days in June and July to Zhipu, which operates the Z.AI brand. These figures and attributions are Anthropic’s findings and have not been independently verified or acknowledged by the companies concerned.
From Model Distillation to Data Sovereignty
The most significant change concerns the source of the data allegedly used in the distillation process. According to Anthropic, Moonshot AI forwarded some requests to Claude while users believed they were interacting with Kimi. Anthropic said Moonshot used a proxy network of 5,380 fraudulent accounts and alleged that the information routed through Claude included internal code and credentials from a major Chinese state-owned enterprise as well as data associated with surveillance activity believed to be linked to the People’s Liberation Army.
Similar concerns were raised about DeepSeek. Anthropic said it identified cases in which internal documentation from a Chinese technology company and requests related to the development of a case-management system for a municipal Chinese public security bureau were routed through DeepSeek to Claude. It also alleged that another request exposed live credentials for a Russian government database associated with its Ministry of Defense.
“DeepSeek, Xiaomi, and Moonshot fed conversations between their own models and users into Claude,” Anthropic said in the report. The allegation therefore goes beyond repeatedly submitting synthetic prompts to a U.S. model to collect training material. Anthropic says actual user conversations were also incorporated into the distillation process.
This is central to understanding the Chinese regulator’s response. The Cyberspace Administration of China, or CAC, reportedly summoned companies named in Anthropic’s report for questioning before focusing its investigation on data-routing practices involving DeepSeek and Moonshot AI. Chinese authorities have not yet determined that either company violated the law or announced penalties.
Model distillation itself is a widely used technique in AI development. Training a smaller model on outputs from a larger model is not inherently unlawful. The critical questions in this case are whether false accounts, proxies and third-party services were used to circumvent access restrictions, whether Claude’s non-public reasoning information was deliberately extracted, and whether customer data was transferred across borders without users being informed.
Anthropic said “unauthorized labs have developed increasingly sophisticated methods to circumvent our defenses.” In response, the company said it has introduced additional safeguards, including measures designed to limit access to raw reasoning information and make it more difficult for new API accounts to manipulate system prompts and tools in ways that facilitate extraction.
APIs Become a New U.S.-China AI Frontier
The broader significance of the case is that the focus of AI controls is expanding from semiconductors to model access and data flows.
U.S. technology controls on China have largely focused on physical infrastructure, including advanced Nvidia GPUs and semiconductor manufacturing equipment. But advanced AI capabilities do not necessarily have to cross borders together with GPUs. If large volumes of prompts and responses can be collected through APIs and subsequently used to train other models, model capabilities themselves can be transferred across borders.
The risk also runs in the opposite direction. If Chinese users believe they are interacting with a domestic AI service while their requests are actually being forwarded to a U.S. model, an API can become both a channel through which Chinese companies access U.S. model capabilities and a route through which Chinese data reaches U.S. AI systems.
The central issue therefore extends beyond which company copied which model. A larger policy question is emerging over whether governments will begin treating model access, API calls, proxy services and cross-border user-data transfers as parts of a single AI supply chain subject to regulatory control.
This shift is also intersecting with U.S.-China discussions on AI. U.S. Treasury Secretary Scott Bessent and Chinese Vice Premier He Lifeng discussed AI in New York on September 20, with the United States proposing a mechanism under which the two countries could notify each other of significant AI incidents involving national security. Bessent said it was important for the world’s two leading AI powers to move “from opaque to more transparency.” China confirmed that AI had been discussed but did not publicly provide a detailed response to the U.S. proposal.
U.S. Trade Representative Jamieson Greer said U.S. export controls on advanced AI chips and semiconductor manufacturing equipment were not part of those discussions. This indicates that the emerging bilateral AI dialogue is, for now, developing as a safety and national-security channel separate from negotiations over export controls. There is also no confirmed evidence that model distillation has been formally placed on the agenda for the leaders’ summit.
Whether these two tracks will remain separate is less certain. On one side, Washington and Beijing are exploring a channel for communicating about AI incidents and national-security risks. On the other, tensions between U.S. and Chinese AI companies over model access and data routing are increasing. If model distillation becomes intertwined with the cross-border transfer of sensitive government and corporate data, the dispute could move beyond corporate terms of service into national-security and data-regulation policy.
There is currently no confirmed indication that the United States has placed DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun or Z.AI on the Commerce Department’s Entity List because of these distillation allegations, nor that the Treasury Department has imposed new financial sanctions against them on that basis. No new U.S. government-wide restriction specifically blocking their access to AI models, APIs or cloud services has been confirmed.
Three signals now warrant attention. The first is whether China turns the DeepSeek and Moonshot investigations into tighter rules governing cross-border data transfers or AI services. The second is whether Washington brings model APIs and proxy access into export controls or a separate technology-protection regime. The third is whether model access and distillation formally enter U.S.-China AI talks or discussions at the leaders’ level.
If GPUs represented the first AI frontier, models, APIs and the data passing through them are now emerging as the next boundary. Washington is concerned about advanced U.S. model capabilities reaching Chinese companies, while Beijing has begun examining whether sensitive Chinese data may be reaching U.S. AI systems.
If both issues become regulatory targets, the focus of U.S.-China AI competition will change. Alongside the race to secure GPUs, who can access which models — and which country receives the data passing through them — could become a new basis for technology controls.
That is the second signal emerging from this case.
© Korea IT Times. Unauthorized reproduction or redistribution is prohibited.