NextFin

CCTV Affiliate Targets Anthropic Over Data Policy Ahead of US-China AI Summit

Summarized by NextFin AI
  • Chinese state media accused Anthropic of rewriting privacy rules to hand user data to US intelligence without legal process, ahead of the Trump-Xi summit, turning data sovereignty into a negotiation lever.
  • Anthropic's July 2026 policy update expanded data collection, allowed sharing with law enforcement on a good-faith basis, and permitted cross-border transfers, though it does not mandate intelligence handover.
  • Anthropic is valued at $965 billion after a $19 billion funding round, with investors targeting an October IPO near $2 trillion, making it a high-profile target for regulatory pressure.
  • The dispute reflects a structural split in AI governance, with China building data-sovereignty barriers as US-China model performance gaps narrow to 2.7 percent while investment diverges 23-to-1.

NextFin News - A social-media account affiliated with China Central Television has accused Anthropic PBC of rewriting its privacy rules to hand user data to US intelligence agencies without legal process, an allegation that lands five days before President Donald Trump and President Xi Jinping are due to meet at the White House and puts data sovereignty squarely on the agenda of what was expected to be a narrower AI-safety discussion. The post, published Saturday by Yuyuantantian, is the latest escalation in a months-long campaign against the San Francisco AI lab, but its timing and its specificity suggest it is doing more than raising a privacy complaint: it is setting terms for the negotiation. The central question is whether this marks the opening of a durable split in how the world governs frontier AI, or merely a piece of summit leverage that will be traded away across the table.

The Accusation and the Facts Behind It

The Yuyuantantian post alleges that Anthropic's privacy-policy revisions have increased risks to user data by allowing information to be shared with US intelligence agencies "when the company considers it necessary without legal procedures." It backs the claim with a set of concrete assertions: Anthropic has revised its privacy policy 13 times since 2023; the revisions include provisions to transfer data from users in Canada, Brazil, South Korea and the European Union to the United States; and the company expanded its data sources from three to six between June 2024 and September 2025.

There is a verifiable kernel inside the accusation. Anthropic published an updated privacy policy on June 8, 2026, effective July 8, and the changes are substantive. The update introduced biometric and government-ID age verification, expanded disclosures around data flows in agentic AI sessions, added a description of data collected when users join research studies, and — most contentiously — permitted the company to share user conversation data with law enforcement based on an internal "good faith belief" determination, without necessarily requiring a court order. The company's own summary of the changes states: "We don't sell your data, Claude remains ad-free, and you can control whether your conversations are used to improve Anthropic's AI models." The policy applies only to consumer accounts — Claude Free, Pro and Max — and not to Claude Team, Enterprise or the Developer Platform.

The gap between that policy text and the post's framing is where the dispute lives. A "good faith belief" disclosure standard is a real expansion of corporate discretion, but it is not the same as a blanket intelligence-sharing mandate, and the post does not cite a specific clause compelling handover to intelligence agencies. What the post does instead is place the policy change inside a broader narrative about Anthropic's influence footprint: it points to federal lobbying spending in the first half of 2026 that it says exceeded the company's full-year 2025 total, a $40 million contribution to an organization focused on AI-risk regulation, and an earlier arrangement under which Claude Code was used by the US Department of Defense for intelligence analysis, modeling and simulation, operational planning and cyber operations.

The lobbying math checks out on direction if not on scale. Federal disclosures show Anthropic spent more than $3.5 million on lobbying in the first half of 2026, ahead of the roughly $3.1 million it spent during all of 2025; in the second quarter alone it spent $1.97 million, a 26% increase from the first quarter and its highest quarterly total since it began lobbying in March 2024. The company has also committed $40 million to Public First Action, a nonprofit advocating AI-risk regulation, and CEO Dario Amodei separately donated $1 million to an allied super PAC. Across the sector, 11 major technology, social-media and AI companies and trade associations spent a combined $41 million lobbying Washington from January through June, with Alphabet, Anthropic, Meta, Microsoft, Nvidia and OpenAI retaining 324 lobbyists in the second quarter — roughly one lobbyist for every 1.5 members of Congress.

The financial stakes make the target intelligible. Anthropic is valued at $965 billion after a $19 billion funding round in May 2026, and investors are targeting a public listing in October at a valuation near $2 trillion, which would make it the largest initial public offering in history. Amazon, its largest backer, held a stake worth an estimated $190.4 billion at the end of June 2026 — about 7.4% of Amazon's market capitalization — and secondary-market marks have climbed since. A company of that size, on the eve of a potential public listing, is an exposed target for any actor trying to shape the rules of the industry.

The Kernel of Truth Inside the Accusation

The mechanism here matters more than the headline. The July policy did three things that a foreign regulator could plausibly treat as risk factors. First, it widened the categories of personal data Anthropic may collect directly from users, including government-issued identity documents and biometric images for age verification. Second, it expanded the circumstances under which conversation data can flow to third parties and, on the company's own good-faith determination, to law enforcement. Third, it acknowledged that consumer data may be transferred to servers in the United States or other countries outside the user's home jurisdiction, relying on adequacy decisions, standard contractual clauses or derogations.

For a Chinese regulator, that third point is the vulnerability. China has spent years building a data-sovereignty regime — the Data Security Law, the Personal Information Protection Law, cross-border transfer assessments — on the premise that sensitive data generated inside China should not exit without review. A US AI lab that routes conversation data, code repositories and agentic task logs to American servers under a self-certified legal basis is the exact scenario those rules were designed to block. The allegation of intelligence access is the sharpest possible framing of that concern, whether or not a specific clause supports it.

This is not the first time the concern has surfaced. On July 8, the same day the new policy took effect, China's National Vulnerability Database, a cybersecurity platform affiliated with the Ministry of Industry and Information Technology, warned that Claude Code contained "security backdoor risks" that could transmit users' locations and identity-related identifiers back to Anthropic's servers without consent. It advised institutions to uninstall or upgrade immediately. Within two days, Alibaba told employees the tool would be banned from July 10. Anthropic's Claude Code engineer Thariq Shihipar responded on X:

"This is an experiment we launched in March that was meant to prevent account abuse from unauthorized resellers and protect against distillation... This should be fully rolled back in tomorrow's release."

That exchange captures the pattern: a Chinese regulator identifies a data-exfiltration risk, a major Chinese tech company moves to ban the tool, and Anthropic characterizes the behavior as an anti-abuse experiment already being removed. The privacy post follows the same script at a higher level of abstraction — from a single coding tool to the entire consumer data regime.

Why Anthropic, and Why Now

Timing is the second mechanism. The post arrives ahead of a planned Trump-Xi meeting on September 24, where AI governance is expected to be on the agenda. Yuyuantantian closes by citing Stanford University's 2026 AI Index report: the performance gap between the top US and Chinese models has narrowed to about 2.7 percent, down from between 17.5 and 31.6 percentage points in May 2023, and Chinese models' open-source, low-cost character is eroding barriers built on performance alone. Front-end model controls, the post argues, will be a central topic when the two countries discuss AI cooperation — and "who defines the safety boundary" is the question that must be answered first. The post reportedly lays out two conditions Washington must meet before substantive US-China AI safety talks can proceed.

Anthropic is an unusually convenient focal point for that argument. Amodei recently published an essay warning that a "Chinese lead in AI would pose grave danger for the United States and the world" and calling for continued restrictions on sales of cutting-edge AI chips and chipmaking equipment to China. China's Ministry of Foreign Affairs responded that all parties should work together on AI, while the state-run Global Times dismissed the essay as "packed with containment provisions targeting China" and "a 'Cold War playbook' for the AI sector." Days earlier, the FBI, the National Security Agency and the Cybersecurity and Infrastructure Security Agency issued a joint advisory saying Chinese AI developers had engaged in "aggressive, malicious" efforts to extract, or "distill," capabilities from advanced US models including Anthropic's Claude. China's Commerce Ministry called the claims groundless and said the US was pursuing an "AI monopoly."

Anthropic has its own counter-narrative. In a September 2026 threat-intelligence report, the company said it had disrupted multiple operations in which state-aligned actors, state-linked contractors and commercial spyware vendors used Claude to build and run surveillance operations, including actors from China, Iran and West Africa. It described one user it assessed as likely PLA-affiliated using what he believed was Moonshot's Kimi model to load CCTV archive data on a targeted individual in Chengdu, including video from hundreds of cameras. The point Anthropic wants on the record is symmetrical: data flows cut both ways, and the surveillance risk is not one-directional.

The Second-Order Battle: Who Defines the Safety Boundary

The first-order story is a privacy allegation against one company. The second-order story is a fight over who gets to write the rules for frontier AI, and the weapon being used is data sovereignty as a non-tariff barrier. If China can establish that US-hosted AI services are structurally unsafe for Chinese users — through vulnerability databases, enterprise bans and state-media framing — it can justify keeping Chinese data, Chinese developers and Chinese demand inside domestic alternatives without ever imposing a formal trade restriction. That is a far more durable instrument than a tariff, because it is framed as consumer protection rather than protectionism.

The capability data explains why the fight is happening now. The Stanford AI Index finds the top-model performance gap at 2.7 percent as of March 2026, with US and Chinese models trading the top spot multiple times since early 2025. Anthropic's Claude Opus 4.6 leads the global leaderboard with an Arena score of 1,503, while ByteDance's Dola-Seed-2.0-Preview sits at 1,464. Yet the investment gap remains lopsided: US private AI investment totaled $285.9 billion against China's $12.4 billion, a 23-to-1 ratio. China leads in AI patents, at 69.7% of global filings, publications at 23.2% of global output, and industrial robot installations at nine times the US rate. In other words, performance has converged while capital has not — which is precisely why rules, not benchmarks, are becoming the battlefield. If you cannot win on money, you try to win on access.

The transmission to markets runs through the parent company and the index. Amazon's exposure to Anthropic has grown from 3.4% of its market value at the end of March 2026 to 7.4% by the end of June, and a $2 trillion listing would push that share materially higher. Any sustained regulatory action that delays Anthropic's planned public listing, forces data-localization architecture, or triggers enterprise customer churn in Asia would hit Amazon's mark-to-market before it hits Anthropic's revenue. Broader AI equities are already twitchy: global shares fell earlier in September after Amodei called for a slowdown in AI development, and SoftBank, a major OpenAI backer, declined with the rest of the complex. A data-sovereignty escalation adds a second channel of pressure — not demand, but permission.

The asymmetry is captured in a single line from Lizzi C. Lee, a fellow at the Asia Society Policy Institute's Center for China Analysis:

"Both China and the U.S. want to make sure the other side cannot establish a tech chokepoint over them."

Cyclical or Structural: This Is the Opening of a Regime, Not a Summit Tactic

The critical judgment is whether this is a cyclical negotiating ploy that fades after the summit or a structural shift that will not revert on its own. The evidence points to structural. A cyclical claim would require a short-term driver with a demonstrated mean-reversion pattern — a negotiating lever pulled before a meeting and released after a concession. What we actually see is a sequence of rule-based actions that accumulate regardless of the summit's outcome: a privacy policy that expands data transfer and good-faith disclosure, a national vulnerability database warning that remains on a government site, an enterprise ban at a major tech company that has not been reversed, and a state-media narrative that ties all of it to a condition for future talks.

The history that used to apply no longer does. Cross-border data flows worked for cloud computing because the data was largely transactional and the regulatory frameworks — adequacy decisions, standard contractual clauses — were negotiated in a period of relative tech detente. Frontier AI data is different: it includes code, reasoning traces, agentic task logs and, increasingly, biometric identity material. Once a regulator classifies that category as a national-security asset rather than a commercial input, the default flips from "flow unless restricted" to "stay unless approved," and that flip does not self-correct.

Both forces are present, and they should be kept separate. The short-term cyclical leg is the summit leverage — the specific post, the specific conditions, the specific timing — and that leg can be traded. The long-term structural leg is the data-sovereignty framework being built underneath it, and that leg persists whether or not the two presidents shake hands.

The strongest counter-thesis is that China cannot afford a clean break. It still depends on US-designed chips and on the capital markets where Anthropic plans to list; Alibaba and other Chinese labs benefit from access to frontier models for research and benchmarking; and a 23-to-1 investment gap means the US retains the capacity to outspend any regulatory barrier. On that view, the Yuyuantantian post is theater calibrated to extract concessions on chip policy, not a genuine decoupling move, and it will be quietly walked back once the summit produces its photo opportunity.

The counter-thesis is plausible but underestimates the mechanism. China has spent years building domestic substitutes — Huawei's Ascend stack, homegrown model labs, the NVDB as a standing review body — precisely so it can absorb the cost of restricted access. The Alibaba ban on Claude Code was not reversed after Anthropic said the tracking would be rolled back; it became the baseline. And the investment gap cuts both ways: if performance has converged to 2.7% while spending diverges 23-to-1, then restricting access to US models is less costly than it would have been three years ago. The counter-thesis also assumes the goal is decoupling; it may instead be leverage asymmetry — China does not need to leave the system, only to make its exit credible enough to shape the rules inside it.

The falsifying signal is specific: if the September 24 summit produces a joint AI data-governance framework that includes mutual recognition of safety audits and data-transfer safeguards, and if China removes the NVDB's Claude Code warning and lifts the enterprise restrictions within 60 days of the meeting, then the fragmentation thesis is wrong and this was summit theater after all. If neither happens, the post should be read as the first public term sheet of a split regime.

What Comes Next

The near-term beneficiaries of this dynamic are domestic AI providers in both blocs. In China, Huawei, Alibaba Cloud, ByteDance and other homegrown model vendors gain a regulatory tailwind as enterprise customers are steered toward locally hosted alternatives. In the United States, the same logic favors providers that can offer data-residency guarantees and on-premise deployments to government and regulated-industry customers. The exposed parties are the pure-play frontier labs whose business models assume frictionless global data flows and a single public listing venue: Anthropic most directly, but also any AI company with significant Asian enterprise exposure or a 2026 IPO timetable that assumes regulatory calm.

Three time horizons matter. In the short term — the days around the summit — expect volatility driven by headlines, with AI equities reacting to any hint of escalation or compromise. In the medium term — six to eighteen months — the binding constraint shifts from chips to data: companies that have not architected for data localization will find entire customer segments closed to them. In the long term, the question is whether the world ends up with two interoperable AI governance regimes or two walled gardens; the 2.7% performance convergence suggests the latter is increasingly viable, because a closed ecosystem no longer needs to be the best to be self-sustaining, only good enough.

Scenarios: the base case is no formal agreement and no formal rupture — a communique vague enough for both sides to claim victory while the NVDB warning and enterprise bans remain in place, slowly hardening into precedent. The upside case for markets is a limited framework on safety testing and evaluator access, paired with a Chinese commitment to keep consumer AI services open, which would ease listing and valuation pressure on Anthropic and its backers. The downside case is a reciprocal escalation: the US restricts cloud access to Chinese entities more broadly, China expands its vulnerability database to other US AI products, and data-localization mandates spread to additional jurisdictions, turning AI into the most fragmented technology market since telecoms.

What to watch: the summit communique's language on AI governance; whether the NVDB warning is still published 60 days after the meeting; Anthropic's IPO filing language on international data-transfer risk factors; and Amazon's next quarterly disclosure of its Anthropic stake value. Each of these is an observable read on whether the regime is hardening or softening.

The real story is not whether Anthropic's privacy policy is risky — most large AI labs face the same question. It is that data sovereignty has become the opening bid in the negotiation over who governs frontier AI, and the company caught in the middle is worth more on paper than the entire AI sector was five years ago. Markets price valuations; regimes price access. This one is starting to price both.

Explore more exclusive insights at nextfin.ai.

Insights

What is Anthropic new data policy?

Why does CCTV target Anthropic now?

How does US intelligence access data?

What is China data sovereignty law?

Did Anthropic revise privacy rules?

How close are US and China AI models?

What is Anthropic IPO valuation aim?

Why did Alibaba ban Claude Code?

What risks does biometric data pose?

How does data sovereignty affect AI?

Will US-China AI summit reach deal?

What is the AI investment gap ratio?

Who defines frontier AI safety rules?

Does Anthropic share data with spies?

How does Amazon stake impact Anthropic?

How do cross-border data rules work?

Is AI market splitting into two blocs?

Why restrict US AI chips to China?

What happens if summit fails on AI?

How does data localization hurt labs?

Search
NextFinNextFin
NextFin.Al
No Noise, only Signal.
Open App