explainx.ai0k
TrendingNewsPathwaysSkills
Pricing
explainx.ai

Upskill in AI — 16 free pathways, live workshops & bootcamps, and 50+ courses from practitioners. Plus the skills, tools, and MCP servers to practice on.

follow us

follow on google

Add explainx.ai as a preferred source

corporate training

support@explainx.ai

get started

Find your pathTake Free Evaluation

community

Join the community

learn

mind: share how you thinkpathways — start freeworkshopsbootcampscoursescompare Explainxcertificationsmock testsexplainx universitycorporate traininglearn skills & mcp

discover

skillsmcp serversexplainx mcptoolsmdx readeragentsllmsdesignsdictionarypeopleagi trackerfelony benchranks

company

aboutvisionmissionteaminstructorsteach on explainxpartnershipscommunityhackathonscareers

content

daily AI newsstate of AI — live resultsblogreleasespromptsgeneratorsresource libraryfor LLMsexplainx.ai kids

solutions

all solutionsdeveloper upskillingmarketing upskillingproduct manager upskillingleadership upskilling

newsletter · weekly

Get AI news, tools, and insights in your inbox.

supportcontactprivacytermsdata rightshow we create contentsubmission guidelines

© 2026 AISOLO Technologies Pvt Ltd

explainx.ai

On this page

  • TL;DR
  • What's actually being alleged
  • Why the specific mechanism matters, and why it's still unclear
  • Why this is relevant well beyond DeepSeek and Moonshot specifically
  • What to actually check in a routing or proxy service
  • The geopolitical layer worth noting without over-reading it
  • Why 35 million is a scale worth taking seriously regardless of outcome
  • Honest limitations
  • Why "which provider actually serves my request" deserves a standard check
  • What this means for builders
  • What to watch for as this investigation develops
  • Related on explainx.ai
← Back to blog

explainx / blog

China Investigates DeepSeek and Moonshot Over 35 Million Requests Sent to Anthropic

DeepSeek, Moonshot AI, Regulation, Data Privacy

Chinese regulators are probing DeepSeek and Moonshot over 35 million requests reportedly routed to Anthropic. What's alleged, and unverified.

Sep 23, 2026·8 min read·Yash Thakker
add explainx.ai
go deep
China Investigates DeepSeek and Moonshot Over 35 Million Requests Sent to Anthropic
Weekly digest3.5k readers

Catch up on AI

Curated AI updates on agents, skills, and MCP — delivered to your inbox. Unsubscribe anytime.

Chinese regulators opened investigations into DeepSeek and Moonshot AI on September 23, 2026, over reports that roughly 35 million user requests were routed to Anthropic's infrastructure — reportedly without clear disclosure to the users making those requests. Whatever the ultimate regulatory finding, the underlying pattern this story surfaces is directly relevant well beyond China or these two specific companies: when a service routes your request to a provider other than the one you chose, without telling you, that's a real problem regardless of which two companies or which country are involved.

TL;DR

table · 2 cols
QuestionAnswer
Who's being investigated?DeepSeek and Moonshot AI, by Chinese regulators
What's alleged?~35 million user requests routed to Anthropic's infrastructure
Was this disclosed to users?Reportedly not clearly
Is this confirmed or still under investigation?Under investigation as of this post
Why does this matter beyond China?It's a concrete case study in undisclosed cross-provider request routing

What's actually being alleged

The core claim under investigation is that a significant volume of user requests — roughly 35 million — intended for DeepSeek or Moonshot's own models were instead routed to, or processed through, Anthropic's infrastructure, reportedly without sufficiently clear disclosure to the users making those requests. That's a meaningfully different, and more serious, allegation than a simple performance or reliability issue — it goes to the core question of who actually processes a user's data when they interact with a given AI service, and whether the company they believe they're using is the one actually handling their query.

Why the specific mechanism matters, and why it's still unclear

Available source coverage doesn't specify the technical or business mechanism behind this routing, and that gap matters for how seriously to weigh different possible explanations. A few genuinely different scenarios could produce a similar surface-level pattern: a capacity-driven fallback system routing overflow traffic to a different backend during high demand, an infrastructure partnership or reseller arrangement that wasn't adequately disclosed to end users, or a misconfiguration in request-handling logic that unintentionally sent traffic to the wrong destination. Each of those has a meaningfully different severity and intent behind it — a disclosed fallback arrangement handled poorly is a different kind of failure than deliberately undisclosed data routing — and without more detail from the regulatory investigation itself, it's not possible to say with confidence which applies here.

Why this is relevant well beyond DeepSeek and Moonshot specifically

The broader pattern this story illustrates is worth internalizing independent of how this specific investigation resolves: any service that sits between a user and an AI model — a router, a proxy, an API aggregator, a fallback system — creates a point where a user's actual data destination can diverge from what they believe it is, unless that routing is clearly and specifically disclosed. This isn't a China-specific or DeepSeek-specific risk; it applies equally to any multi-provider router or proxy service operating anywhere, and the growing popularity of exactly this kind of routing infrastructure — explainx.ai has covered several router and proxy services this year specifically for their cost and reliability benefits — means this is a genuinely widespread pattern worth scrutinizing, not an isolated incident.

What to actually check in a routing or proxy service

For anyone using a model router, proxy, or fallback service — rather than calling a single provider's API directly — the practical takeaway from this story is a specific question worth asking directly of any such service: does it clearly disclose, for every request, which underlying provider actually processed it, or is that information opaque or only available after the fact, if at all? A service that can't answer that question clearly and specifically is asking users to trust it with exactly the kind of undisclosed-routing risk this investigation is centered on, regardless of how reputable the service otherwise appears.

The geopolitical layer worth noting without over-reading it

There's an obvious geopolitical dimension to a Chinese regulatory investigation into Chinese AI companies allegedly routing user data to a US-based AI lab specifically, and it's worth naming that context directly without over-interpreting it. Cross-border data flows between Chinese and US technology companies sit within a broader, well-documented pattern of heightened regulatory scrutiny in both directions this year, and a Chinese regulator investigating exactly this kind of data movement is consistent with that broader environment regardless of whatever the underlying technical facts of this specific case turn out to be. That context is useful for understanding why this investigation is happening now and receiving significant attention, but it shouldn't be read as evidence one way or the other about whether the underlying technical allegation (undisclosed routing to Anthropic) is actually true — the geopolitical backdrop explains the investigation's prominence, not its merits.

Why 35 million is a scale worth taking seriously regardless of outcome

Even setting aside the eventual regulatory finding, the scale alleged here — 35 million requests — is large enough that even a partial confirmation would represent a genuinely significant data-handling failure, not a minor technical glitch affecting a handful of edge-case users. For context, a leak or undisclosed routing incident at that volume would place among the larger reported AI-data-handling incidents of the year regardless of which specific companies are involved, which is part of why this warrants coverage independent of how the underlying geopolitical dynamics eventually shake out. Scale alone doesn't confirm severity of harm — it matters what data was actually included in those requests, and whether it contained sensitive personal information — but it does establish that this isn't a story to dismiss as a minor procedural matter regardless of its outcome.

Honest limitations

  • This is a regulatory investigation, not a finalized, adjudicated finding — the specific facts alleged (the 35 million figure, the routing-to-Anthropic claim) come from reporting on the investigation's scope, not a confirmed regulatory conclusion as of this post.
  • The technical mechanism behind the alleged routing was not detailed in the source coverage available for this post, meaning the actual severity and intent behind the incident remains genuinely unclear.
  • Neither DeepSeek, Moonshot, nor Anthropic's own detailed response or statement was available in the source coverage used for this post — this summary reflects reported investigation activity, not any of the involved companies' own account of events.
  • This post does not take a position on the ultimate merits of the regulatory investigation — it summarizes what's alleged and what's unverified, not a conclusion about wrongdoing.

Why "which provider actually serves my request" deserves a standard check

The underlying question this story raises — do you actually know which company's infrastructure processes your data when you interact with an AI product — is worth treating as a standard due-diligence item for any AI service, the same way checking a service's data-retention policy or terms of service already is for privacy-conscious teams. For consumer users, that check is often genuinely difficult to do independently; you largely have to trust a provider's own disclosures. For teams building products or internal tooling on top of any AI provider, model router, or API aggregator, it's more tractable: monitoring outbound network traffic from your own infrastructure, reviewing a router's documented routing logic in detail rather than trusting a marketing summary, and preferring providers who offer verifiable, auditable routing transparency over those who simply assert trustworthiness are all concrete, actionable steps that don't depend on waiting for a regulatory investigation to surface a problem after the fact.

What this means for builders

If you're using any multi-provider router, proxy, or fallback service in production, this is a good prompt to directly verify — not assume — exactly which provider is processing each of your requests, particularly for any workload involving sensitive or proprietary data. Look for services that provide per-request transparency about actual routing destination, and treat vague or unverifiable claims about "which provider handles your traffic" as a real due-diligence gap worth resolving before routing sensitive data through any intermediary service, regardless of that service's country of origin or general reputation.

What to watch for as this investigation develops

The most informative next development to watch for is whether Chinese regulators publish a detailed technical finding once the investigation concludes, rather than only an outcome (fine, sanction, no action) without accompanying explanation. A detailed technical finding would resolve the open questions this post has flagged throughout — the actual routing mechanism, the scope of data involved, and whether the behavior was intentional, a poorly-handled partnership arrangement, or a genuine misconfiguration — in a way that reporting on the investigation's mere existence cannot. Until that detail becomes available, this remains a story worth tracking rather than a resolved one.

Related on explainx.ai

  • Grok 4.7 vs Claude Opus 5.5 vs GPT-6 Sol: The Only Numbers That Overlap
  • What Is Indirect Prompt Injection?
  • Aikido Releases Altar 1, an Open-Weight Security Model Built on GLM 5.3

Primary source: Industry news aggregation, September 23, 2026, covering the reported Chinese regulatory investigation into DeepSeek and Moonshot AI.


This post reflects publicly reported information about an ongoing regulatory investigation as of September 23, 2026. Facts alleged in this post are unconfirmed pending the investigation's conclusion.

Spotted something out of date? Let us know.
Yash Thakker

Written by

Yash Thakker

Yash is an AI expert with over 300K learners. Join his workshops →

View Yash Thakker in People in AI →

Related posts

Sep 11, 2026

Moonshot and DeepSeek Secretly Served Claude Instead of Their Own Models

Anthropic's September 10, 2026 threat intelligence report disclosed that Moonshot AI and DeepSeek silently rerouted user requests to Claude and displayed its responses as their own models' output — while Alibaba ran the largest distillation attack Anthropic has ever measured, at 151 million exchanges.

Sep 7, 2026

China's AI Token Economy: Credit Cards, Bank Loans, and a Reported 500 Trillion Tokens a Day

One commentator's viral X essay strings together three claims about China's AI ecosystem: a Moonshot AI credit card that pays rewards in token credits instead of cash, Chinese banks reportedly sizing loans partly on AI token consumption, and an aggregate figure of roughly 500 trillion tokens processed daily nationwide. None of it is a primary announcement — here's what the scale claim actually means, why the credit-card angle is a real business-model innovation, and why the loan-sizing claim is the one worth watching regardless of geography.

Jun 29, 2026

Top Chinese AI Companies and Startups in 2026: The Complete Landscape Guide

China's AI industry has consolidated around ten serious providers plus the Six Tigers startup cohort. This guide maps every major lab — what they ship, who they serve, how they price, and which models developers actually use in production.