# Yuyuan Tantian escalated its criticism of Anthropic

> Source: <https://www.geopolitechs.org/p/yuyuan-tantian-escalated-its-criticism>
> Published: 2026-09-19 14:39:44+00:00

Yuyuan Tantian’s criticism of Anthropic has been escalating.

In late August, it published an article titled *“[Anthropic Has Caught America’s Disease](https://www.geopolitechs.org/p/yuyuan-tantian-anthropic-has-caught),”* which mainly questioned whether Anthropic was using “AI safety” as a means to gain greater influence over who gets to define the rules and standards governing AI.

In early September, it followed up with another article, *“[Closed-Source America: Beware of New U.S. Tactics to Contain China’s Open-Source AI Development](https://www.sina.cn/news/detail/5339711961039393.html).”* Focusing on the issue of model “distillation,” the article criticized Anthropic for reframing what it described as a commonly used technical practice as a security and political issue, and for using that narrative to justify efforts to constrain Chinese open-source models.

The latest and most serious criticism came on September 19. An article titled “[13 Changes to User Privacy Policies in Three Years: Anthropic Hands Global User Data to U.S. Intelligence Agencies](https://weibo.com/7040797671/5344849551166217)” examined 13 revisions to Anthropic’s privacy policies since 2023 and characterized the process as unfolding in three stages.

The first stage, according to the article, was the transfer of overseas user data to the United States. It said that, beginning in May 2024, multiple versions of Anthropic’s privacy policies addressed the transfer of user data from jurisdictions including Canada, Brazil, South Korea and the European Union to the United States. It highlighted, in particular, language in Anthropic’s Canadian policy noting that data-protection standards in the United States may differ from, or provide a different level of protection than, those in Canada.

The second stage was an expansion in the range of data Anthropic could collect and use. Yuyuan Tantian claimed that between June 2024 and September 2025, the number of categories of user-data sources available to Anthropic increased from three to six. It also highlighted subsequent changes to Anthropic’s rules governing the use of user data for model training.

The third stage—and the most serious allegation—was that Anthropic had developed increasingly direct links with the U.S. intelligence apparatus.

The article cited three sets of evidence.

First, in February 2026, Anthropic published a report alleging that Chinese companies had engaged in so-called model “distillation,” and said that it was sharing relevant technical indicators with intelligence agencies.

Second, in June, Anthropic submitted materials to the U.S. Senate stating that its analysis of 28.8 million user conversations and 25,000 user accounts had provided information about alleged distillation activities involving Chinese companies.

Third, in July, Anthropic advertised positions for Threat Intelligence Managers. Some of these positions gave preference to candidates with proficiency in Mandarin Chinese or Russian, experience conducting intelligence analysis in government or military environments, and U.S. Top Secret security clearances.

Yuyuan Tantian then linked these developments to a threat-intelligence report Anthropic published on September 10. According to the article, that report analyzed approximately 200 million interactions involving Claude that were suspected of being associated with model distillation.

**Below is an unofficial English translation of the full article:**

A fierce debate is unfolding in Silicon Valley over the speed and safety of AI development.

On September 12, Anthropic CEO Dario Amodei, OpenAI CEO Sam Altman, and xAI founder Elon Musk made a rare show of public agreement late at night in the United States: AI development needs to slow down.

Altman responded to only one of Amodei’s proposals—the introduction of independent third-party evaluators—while Musk simply said, “Dario is right.” Even so, the debate has quickly divided Silicon Valley into two broad camps.

On the other side are figures including Nvidia CEO Jensen Huang and Meta CEO Mark Zuckerberg, who have argued that companies should move “as fast as possible.” Their view is essentially that those who believe the technology is unsafe are free to slow down or stop, but there is no need for everyone to hit the brakes together.

On the surface, this looks like a disagreement over the direction of technological development. In reality, however, the deeper dispute is over who gets to define the standards for AI safety.

The irony is that Amodei, one of the loudest advocates of AI safety, has taken actions that appear to point in the opposite direction.

On September 14, foreign media reported that Nvidia and several other U.S. companies had begun restricting or discontinuing their use of Anthropic’s frontier models.

One factor prompting American companies to move away from American AI models was Anthropic’s unilateral change to its data-retention rules: user interaction data must now be retained for 30 days for safety reviews, with users given no option to opt out.

This was not the first time Anthropic had changed its policies governing user data.

Tan Zhu reviewed all 13 revisions made since Anthropic released the first version of its Privacy Policy in 2023 and compared them with ISO/IEC 27701, the international standard for privacy information management. The review found that the risks surrounding the security and privacy of Anthropic users’ data have continued to increase.

Most major AI companies in China and abroad state in their privacy policies that they will comply with lawful requests for data from law-enforcement authorities. Anthropic goes further. Its Privacy Policy provides that, when the company itself considers it necessary, it may share user data with U.S. intelligence agencies without first going through a legal process. In other words, both the decision and the standard for making it are defined by the company itself.

Why has Anthropic taken this approach? Looking at the substance and timing of each revision to its privacy policies reveals three steps through which Anthropic has increasingly positioned itself as an “intelligence hub.”

**First, transferring overseas user data to the United States.**

Beginning in May 2024, five versions of Anthropic’s privacy policies referred to mechanisms—such as establishing subsidiaries or adopting supplementary provisions—for transferring relevant user data from places including Canada, Brazil, South Korea, and the European Union to the United States in accordance with specified terms.

Its current policy for Canadian users even explicitly states that data-protection standards in the United States may be less stringent. In effect, once users’ data reaches the United States, it may no longer enjoy the same protections provided by the standards of the country in which those users are located.

**Second, expanding the sources from which user data can be obtained.**

Between June 2024 and September 2025 alone, the number of categories of user-data sources accessible to Anthropic increased from three to six. These include user conversations, data generated by users themselves, and, more recently, user identity data.

Once collected, these data can potentially be used to train Anthropic’s AI models. The larger the volume and the wider the range of data, the greater the potential capability of the models trained on them.

Anthropic accordingly revised its rules governing the use of data for model training. Its position shifted from not using such data by default in 2024 to using it by default in September 2025. Even when users decline to provide their data, Anthropic may still flag certain interactions on “safety” grounds and use them for model training.

**Third, providing intelligence to U.S. intelligence agencies in exchange for benefits.**

On February 23, 2026, Anthropic published a report claiming that Chinese companies had engaged in so-called “distillation” activities. The report stated that Anthropic was “sharing technical indicators with relevant intelligence agencies.”

Anthropic subsequently continued to provide additional information. On June 10, 2026, it submitted a letter to the U.S. Senate stating that, by analyzing 28.8 million user conversations and 25,000 user accounts, it had obtained new intelligence regarding the alleged involvement of Chinese companies in so-called “distillation.”

Becoming an intelligence hub requires more than data. It also requires people.

In July 2026, Anthropic posted three openings for “Threat Intelligence Manager” positions on its website. Two of the roles gave preference to candidates who were fluent in languages such as Mandarin Chinese or Russian, had experience conducting intelligence analysis in government or military environments, and held U.S. Top Secret security clearances. The roles involved investigating user interaction data for evidence of foreign-government-backed influence operations or model “distillation.”

Then, on September 10, Anthropic published a threat-intelligence report whose subject matter closely mirrored the responsibilities described in those July job postings. The report analyzed approximately 200 million interactions between users and the Claude model that were suspected of being associated with so-called “distillation.”

Two days later, on September 12, Anthropic CEO Dario Amodei cited that report while proposing three measures to “slow down” the development of AI.

The pattern is clear: first collect data from around the world and use it to define what constitutes a “threat”; then recruit trusted personnel to analyze that data; and finally turn a company-defined safety standard into an American standard. Once that American standard is extended globally, the “risks of AI development” described by Amodei can, by definition, be brought under control.

Seen in this light, the “technical consensus” reached by the three AI leaders is ultimately rooted in problems within the U.S. AI industry itself. What they want to slow down is the speed at which others can catch up. What they want to accelerate, meanwhile, is their own collection of data, extraction of intelligence, and ability to define the rules—and even the meaning of safety itself.
