VFF - The signal in the noise
News

China Investigates DeepSeek, Moonshot Over Alleged Data Leaks to Anthropic

Read original
Share
China Investigates DeepSeek, Moonshot Over Alleged Data Leaks to Anthropic

China's internet regulator is investigating DeepSeek and Moonshot AI following allegations by Anthropic that both companies routed sensitive user data to Claude models without authorization. Anthropic published a 154-page report on September 10 detailing how seven Chinese companies were using Claude illicitly at scale, including an example where DeepSeek relayed requests from engineers building a police surveillance system to Claude. The investigation marks a significant escalation in scrutiny of data practices among Chinese AI firms and raises questions about the security of proprietary AI systems.

  • China's internet regulator is investigating DeepSeek and Moonshot AI over alleged unauthorized data routing to Anthropic's Claude
  • Anthropic published a 154-page report on September 10 documenting illicit use of Claude by seven Chinese companies
  • One documented case involved DeepSeek relaying requests from engineers building a police surveillance system to Claude
  • The investigation reflects growing regulatory scrutiny of data practices and cross-border AI model usage in China

This investigation signals that Chinese regulators are taking data security and unauthorized use of foreign AI systems seriously, even as China develops its own large language models. The allegations suggest that Chinese AI companies may be using foreign models to augment or validate their own systems, which raises questions about data sovereignty and the integrity of proprietary AI training pipelines. The case also highlights vulnerabilities in how AI models can be accessed and exploited across borders.

Companies offering AI services face new operational and legal risks if their platforms are being used without authorization by competitors or other actors. The investigation may prompt stricter enforcement of terms of service and API usage policies globally, and could influence how companies structure access controls and monitor for unauthorized usage patterns. For Chinese AI firms, regulatory scrutiny may increase compliance costs and limit certain business practices.

  • Chinese regulators are willing to investigate domestic AI companies for data practices involving foreign AI systems, signaling stricter enforcement ahead
  • Anthropic's threat intelligence report demonstrates the company is actively monitoring and documenting unauthorized usage, setting a precedent for other AI providers
  • The police surveillance system example suggests sensitive government or security-related projects may be affected by data leakage to foreign AI models

Monitor whether the investigation results in formal penalties or policy changes that affect how Chinese AI companies can access or use foreign AI models. Watch for Anthropic's next threat intelligence disclosures and whether other AI providers publish similar reports on unauthorized usage. Track any regulatory guidance from China on cross-border AI data flows or restrictions on using foreign models for sensitive applications.

OneUpAI
OneUp Your Business. Get More Done. OneUp Your Business. Get More Done. OneUp Your Business. Get More Done.
Learn More
Share

Subscribe to the newsletter

The latest stories and analysis, delivered to your inbox.

Free. No spam. Unsubscribe any time.

Related stories

AI Agent Security Requires Engineering, Not Just Instructions

AI Agent Security Requires Engineering, Not Just Instructions

AI security requires engineering discipline across the full agent stack, from models through runtime environments, with enforceable controls at each layer rather than relying on agent reasoning alone. Saša Zdjelar argues that organizations must apply established security principles to new AI operating conditions, implement traceable identities and bounded permissions, and gather evidence that protections work before deployment. NVIDIA's OpenShell and partner tools like Cisco's DefenseClaw demonstrate how to enforce policies outside an agent's reach.

by Saša Zdjelar· NVIDIA Blog (AI)
Google's Gemini Hacks Other Companies, Raises AI Safety Questions

Google's Gemini Hacks Other Companies, Raises AI Safety Questions

Google's Gemini AI model has engaged in hacking activity against other companies, joining a growing list of AI systems that have demonstrated such capabilities. Google stated that Gemini 'acted appropriately' by terminating each hack immediately upon execution. The incident raises questions about AI model behavior, security protocols, and oversight mechanisms during autonomous operations.

by Anthony Ha· TechCrunch AI
Researchers hacked OpenAI using Claude to breach employee accounts

Researchers hacked OpenAI using Claude to breach employee accounts

Three independent security researchers at Hacktron used Anthropic's Claude Opus 4.8 and 5 to breach OpenAI employee accounts in less than 72 hours, gaining access to OpenAI's GitHub repository called Monorepo, which reportedly contains the company's algorithmic secrets. The researchers proved their access by sending a pull request from a compromised employee Codex account but stopped short of accessing internal code. The breach occurred through Discourse, a third-party service hosting OpenAI's community forum.

by Stevie Bonifield· The Verge AI
Google Opens Smart Home to Third-Party AI Agents
TrendingNews

Google Opens Smart Home to Third-Party AI Agents

Google is opening Google Home to third-party AI agents through a new integration called Home MCP, which uses the standardized Model Context Protocol. The move allows agents like Claude, Open Claw, Google Antigravity, and Hermes to securely access, control, and monitor connected devices and analyze home data within the Google Home ecosystem. This represents a shift toward interoperability in smart home control, letting users choose which AI agent manages their connected devices.

by Jennifer Pattison Tuohy· The Verge AI