Anthropic alleges Kimi and DeepSeek routed requests to Claude
SharpPost examines Anthropic’s allegations, the distinction between relaying and distillation, and the implications for data authorization and sovereign AI.
免费微软自然语音 · 推荐使用 Microsoft Edge
Anthropic alleged in a threat intelligence report published on September 10 that Moonshot, the developer of Kimi, and DeepSeek forwarded some user requests to Claude and used related exchanges to train models. The material included surveillance records and data linked to defense institutions, the company said.
The companies named, including Moonshot and DeepSeek, did not immediately respond to Reuters’ requests for comment. China’s foreign ministry said it was unaware of the report, reiterated that AI should be developed for good, and opposed the distortion of facts and attempts to smear China.
The report said a user assessed as possibly linked to the People’s Liberation Army used what they believed was Kimi to analyze material from hundreds of cameras in Chengdu, including cameras outside military facilities. A DeepSeek-related case involved data from an institution associated with Russia’s defense ministry; user exchanges forwarded to Claude contained still-valid database credentials.
According to The Next Web, Anthropic said Moonshot relayed almost 300,000 customer requests over ten days. Relaying lets Claude answer a request directly; distillation uses a model’s outputs to train another model. User material reaches a third party at the first step, before any training takes place.
Anthropic said it did not know whether Moonshot had notified customers. Where surveillance material identifies individuals, China’s Personal Information Protection Law sets separate requirements for entrusted processing, transfers to other personal information handlers, and transfers abroad. Liability depends on the actual data flow, processing relationships and scope of authorization; permission to answer a query does not by itself establish permission to train on it.
Businesses and governments buying domestic models often also want to retain control over their data. If requests are still sent abroad, the promise of “sovereign AI” may go unfulfilled. Procurement reviews therefore need to examine the servers running the model, access to logs and records of external calls—not just where the supplier is registered.
In a weapons-related case, Anthropic said an operator linked to a Chinese defense manufacturer used Claude to write anti-torpedo fire-control specifications, software and procurement documents. A separate group in Yemen used Claude to help develop rocket-guidance code and carried out an apparently unsuccessful test launch. The company said there was no evidence that the group had fielded an operational weapon.
Anthropic said it had banned the accounts involved in the misuse and updated its safeguards in response.
You read this far. You're not here for noise.
SharpPost delivers one weekly deep dive on geopolitics, finance, and tech — decoded for readers who want signal. No ads, no filler.