China Treats AI Query Routing as a Cross-Border Data Transfer Problem: CAC Probes DeepSeek and Moonshot (September 2026)
China's internet regulator has opened a data-security investigation into DeepSeek and Moonshot AI over allegations that the two companies covertly routed Chinese users' queries to Anthropic's Claude — and the framing that matters for compliance teams is that Beijing is treating the routing as a potential cross-border data transfer violation, not merely a model-distillation dispute.
Per The Information (reported September 22, 2026), the Cyberspace Administration of China (CAC) first summoned representatives of all seven Chinese AI developers named in Anthropic's September 10, 154-page report on "illegal distillation" — a list that also included Alibaba, Zhipu, SenseTime, MiniMax and Xiaomi — before focusing on DeepSeek and Moonshot, sending officials to interview executives and employees. Anthropic claims Moonshot redirected more than 23 million user queries to Claude between May and July 2026, and DeepSeek more than 12 million in 14 days in July. Reported examples include queries from an engineer working on municipal public-safety systems processing movement data keyed to national ID numbers, and surveillance data from Chengdu transmitted via Kimi, including near PLA facilities and defense research institutes.
The enforcement theory is the cross-border one:
"For Beijing, a different threat emerges: if Anthropic's allegations are true, sensitive data from Chinese users, government bodies, police, and state enterprises could have been sent to American systems along with the queries. This could potentially violate the country's cross-border data transfer regulations, sources told The Information." — ForkLog, summarizing The Information's report
"The investigation is ongoing. CAC has not yet decided on potential sanctions as authorities assess the extent of possible violations and the companies' intentions." — ForkLog
Hong Kong-listed Chinese AI stocks fell on September 23 on the reports, with Bloomberg confirming CAC had dispatched investigators to both companies. The probe lands just ahead of the Trump-Xi summit, where the two governments were expected to discuss an "AI dialogue" mechanism for notifying each other of AI incidents with national-security implications.
What it means for compliance teams: CAC has demonstrated it will apply China's cross-border data transfer rules (Data Security Law / PIPL export controls) to AI-era data routing — queries, prompts and embedded corporate or government data sent to foreign model providers. Any workflow that pipes China-origin data through offshore AI services is now within demonstrated enforcement scope, alongside the special-campaign penalties documented in China: Nationwide PIPL Special Enforcement Campaign Now Producing Published Precedents — First Fine on Unassessed PI Export (September 2026) (which include a fine for unassessed PI export via a desktop client and a warning for an LLM "API relay station"). The probe's outcome — sanctions, and whether CAC pairs it with new guidance on AI-related data exports — will define the compliance perimeter for AI vendors and their enterprise customers.