Politics🌐 Available in EnglishSeptember 16, 2026

Are Chinese Firms Handing the United States Data?

Are Chinese Firms Handing the United States Data?
Foreign Policy
Foreign Policy
Foreign Policy
Original Source

Anthropic revealed that leading Chinese AI firms are routing hundreds of thousands of user requests through its models to extract their capabilities, inadvertently leaking sensitive military, engineering, and security data to the U.S. More critically, Chinese user data itself—revealing technological intentions and capabilities—is flowing to America, potentially exposing China's industrial weaknesses and military capabilities.

China-U.S. AI Competition Exposes Data Loophole

!Foreign Policy

Foreign Policy

Get analysis and alerts more quickly in the mobile app.

Install

Back to Foreign Policy Magazine home page

* Latest
* Regions
+ Asia & the Pacific
+ China
+ Middle East & Africa
+ Americas
+ Europe
* Newsletters
Editors’ Picks
Evening roundup with our editors’ favorite stories of the day
!World Brief Icon
World Brief
Your guide to the most important world stories of the day
!China Brief Icon
China Brief
The latest news, analysis, and data from the country each week
Situation Report
Weekly update on what’s driving U.S. national security policy
FP Weekend
A curation of our best book reviews, deep dives, and other reads
!Africa Brief Icon
Africa Brief
Essential analysis of the stories shaping geopolitics on the continent
!South Asia Brief Icon
South Asia Brief
Weekly update on developments in India and its neighbors
The Reading List
Curated guides on geopolitics and current affairs
FP Bookshelf
A monthly guide to FP’s book reviews, excerpts, and reading recommendations
!Latin America Brief Icon
Latin America Brief
One-stop digest of politics, economics, and culture
!Southeast Asia Brief Icon
Southeast Asia Brief
A weekly dispatch with news from the region’s 11 countries
The New Geopolitics
A five-part masterclass in IR theory with Harvard Professor Stephen M. Walt
View All Newsletters

* FP Live

* Latest
* Trending:
* 25 years after 9/11
* Germany elections

Search this website

* Preferences
* My FP Feed
* Saved Articles
* Newsletters
* Magazine Archive
* Subscription Settings
* FAQs
* Log Out

Sign In

Sign In

Partner with FP at UNGA81 Partner with FP at UNGA81

Subscribe SubscribePartner with FP at UNGA81 Partner with FP at UNGA81

Analysis:

Are Chinese Firms Handing the United States Data?

*
*
* Facebook
* Bluesky
* X
* LinkedIn
* WhatsApp
* Reddit

Save

1. Create an FP account to save articles to read later.
Sign Up
ALREADY AN FP SUBSCRIBER? LOGIN

PDF

1. **Downloadable PDFs** are a benefit of an FP subscription.
Subscribe Now
ALREADY AN FP SUBSCRIBER? LOGIN

Gift

*
*
* WhatsApp

1. Gifting articles is a subscriber benefit.
Subscribe Now
ALREADY AN FP SUBSCRIBER? LOGIN

2. This article is an Insider exclusive.
Contact us at [email protected] to learn about upgrade options, unlocking the ability to gift this article.

Analysis

Are Chinese Firms Handing the United States Data?

AI competition may be an unwitting weakness for Beijing.

By **Deng Yuwen**, a Chinese writer and scholar.

!An outside view of an Apple data center in Guiyang, in China's southwestern Guizhou province, on July 24.

*An outside view of an Apple data center in Guiyang, in China's southwestern Guizhou province, on July 24.*

An outside view of an Apple data center in Guiyang, in China's southwestern Guizhou province, on July 24. Jade Gao/AFP via Getty Images

*
*

September 15, 2026, 1:46 PM

A recent report by the U.S. artificial intelligence company Anthropic accused several leading Chinese AI firms, including Moonshot AI and DeepSeek, of distilling Claude’s capabilities on a large scale. Anthropic said some of these companies went beyond using Claude to generate training data and, without users’ knowledge, in one instance routed at least 300,000 requests from real users through the model over a 10-day period.

The data reportedly sent to Claude included surveillance material submitted by a user Anthropic suspected of being affiliated with the People’s Liberation Army; internal code and valid credentials from engineers at major Chinese state-owned enterprises; information from police case management systems; and details of internal AI projects at Chinese technology companies.

A recent report by the U.S. artificial intelligence company Anthropic accused several leading Chinese AI firms, including Moonshot AI and DeepSeek, of distilling Claude’s capabilities on a large scale. Anthropic said some of these companies went beyond using Claude to generate training data and, without users’ knowledge, in one instance routed at least 300,000 requests from real users through the model over a 10-day period.

The data reportedly sent to Claude included surveillance material submitted by a user Anthropic suspected of being affiliated with the People’s Liberation Army; internal code and valid credentials from engineers at major Chinese state-owned enterprises; information from police case management systems; and details of internal AI projects at Chinese technology companies.

The leakage of sensitive information will of course alarm Beijing. But compared with one or two pieces of sensitive material reaching the United States, the bigger worry may be that, in the process of distilling the capabilities of the most advanced U.S. models, Chinese AI companies may also be sending large quantities of real Chinese user data to the United States.

AI competition is not just about compute but about data. Today, data available on the open internet is increasingly easy to obtain. What is truly scarce is the high-quality data generated by real tasks: why users turn to AI, what problems they are trying to solve, what background materials they provide, how far they have progressed in writing code, what technical obstacles companies encounter, and what they want AI to help them accomplish. Such data can be far more valuable than the ordinary detritus of the web.

On its own, such data may not mean much or be worth much. But once hundreds of thousands, millions, or even tens of millions of such pieces of data are aggregated, their nature changes completely. A Chinese programmer asking why a piece of code failed has little or no intelligence value. But if thousands of Chinese engineers repeatedly encounter and ask about similar problems, the aggregate may expose a common bottleneck in a Chinese technological system.

Likewise, an employee asking how to improve a particular piece of equipment or software would hardly be a concern—or a secret. But if large numbers of engineers from industries such as semiconductors, robotics, aerospace, telecommunications, electricity, and automobiles are continually talking about their work to AI models, over time those interactions could allow others to form a dynamic map of China’s industrial and technological capabilities.

This data is more telling than conventional searches. Those queries generally reveal what a person wants to know, but AI often reveals what a person is actually doing. Users voluntarily provide work context, upload code, documents, and project descriptions; explain what they have already tried; identify the problems they have encountered; and describe what they intend to do next.

This is a very particular kind of data. It might be called intent data. It tells outsiders not only what China possesses but what China is doing.

In peacetime, such data primarily has commercial and technological value. But as tensions between the two superpowers grow, so too will the value of such a data mine.

Imagine a scenario where war seems to be on the horizon. U.S. intelligence agencies would need to know not only how many missiles and warships China possesses but also whether its military-industrial system is accelerating production; where bottlenecks are emerging; which civilian companies are beginning to enter wartime production; what weaknesses exist in semiconductors, drones, communications, electricity and transportation; and which research institutions are suddenly concentrating on particular problems. Large volumes of AI interactions could provide precisely this kind of information.

When the institutions, names, equipment, software, suppliers and technical failures mentioned in AI conversations are combined with satellite imagery, customs records, procurement data, patents, academic papers, corporate information, network data, and other intelligence already available to the United States, an apparently ordinary user query can bec

🔗 Share Article

Tags:#الذكاء الاصطناعي#التجسس#الصين#الولايات المتحدة#الأمن السيبراني#المنافسة التكنولوجية

For Context

Related reads from the same topic or latest developments