When you type something private into an AI chatbot, you assume it stays between you and that company. A new investigation in China is testing that assumption in an uncomfortable way, and the details should make anyone who uses AI think twice about where their words actually go.
What China is investigating
China's Cyberspace Administration, the country's powerful internet regulator, has opened an investigation into two of its own AI champions: DeepSeek and Moonshot. Officials visited both companies to question executives and staff. The concern is that these firms quietly routed their users' requests through Anthropic's Claude models, sending data to American servers without the users knowing.
For Beijing, that is a serious problem. If sensitive information from Chinese users ended up on servers in the United States without consent, it could violate China's strict data-security laws. The investigation is still open, and no penalties have been handed down yet.
The report that started it
The probe did not come out of nowhere. On September 10, 2026, Anthropic published a 154-page threat-intelligence report accusing seven Chinese AI labs of what it called "illicit distillation," meaning they routed customer requests through Claude to harvest its answers and use them to train their own models. The seven companies named were Alibaba, Moonshot, DeepSeek, Zhipu, MiniMax, Xiaomi, and SenseTime.
The scale described in the report is striking. Across all seven companies, Anthropic counted roughly 190 million exchanges, with Alibaba alone accounting for 151 million. Moonshot reportedly pushed more than 23 million exchanges through Claude between May and July, and DeepSeek generated 12.1 million in a single 14-day stretch in July. Interestingly, Alibaba had by far the highest volume, yet it is not among the companies currently under investigation.
There is a twist worth noting. Anthropic's complaint was about companies stealing its technology by copying Claude's outputs. Beijing's worry is the exact opposite: that its citizens' data flowed out to a foreign company. The same set of facts is being read as two completely different threats, depending on which side of the border you are standing on.
What it means for your data
You may never use DeepSeek or Moonshot, but the lesson applies to every AI tool you do use. The services you trust with your questions sometimes pass your data to other companies behind the scenes, and you may have no idea it is happening. When the AI you rely on is itself built on top of someone else's AI, your information can travel further than you ever agreed to.
For businesses, this is a direct warning. If your team pastes customer details, financial figures, or private strategy into an AI assistant, you need to know exactly where that data lands and who else can see it. "It stays with the provider" is no longer a safe assumption. The companies that take data privacy seriously, and can prove where information goes, will be the ones enterprises trust with their most sensitive work.
The DeepSeek and Moonshot investigation is still unfolding, and the companies have not been found guilty of anything yet. But it has already made one thing clear: in the AI era, the path your data takes is rarely as simple as you think, and knowing that path is quickly becoming a requirement, not a nicety.