Statement on Anthropic’s Report Revealing China's Use of Artificial Intelligence for “Stability Maintenance” and Public Opinion Surveillance
On September 10, @AnthropicAI published "Detecting and Countering Misuse of AI: September 2026", which explicitly identified “Teacher Li Is Not Your Teacher” @whyyoutouzhele as one of the targets of a “stability maintenance” and public opinion surveillance operation.
While reviewing Claude user activity, Anthropic discovered and banned a cluster of accounts it assessed to be linked to local public security and state security authorities in China. The users used Claude to collect information automatically, query government surveillance databases, and generate daily reports for their employers. Our account was included in the surveillance operation disclosed in the report.
Following @OpenAI's disclosure of similar operations targeting dissidents earlier this year, Anthropic has now exposed these surveillance mechanisms from another angle: our news account, which speaks up for people inside China, is being treated as a surveillance target by the state security apparatus.
The report also revealed that Chinese public security and state security authorities label and perceive information about social problems, labor protests, and news coverage as political threats requiring intervention. In another operation that Anthropic assessed to be conducted by a government contractor, users employed Claude to produce automated “public opinion briefings,” processing approximately 15 to more than 30 articles a day. They rated content for “political sensitivity” and reframed labor protests, student activism, minority communities’ demands, and foreign media coverage as threats to “political stability” and “ideological security.” Some documents also recommended government enforcement action.
One of the most direct examples involved a user assessed to have ties to the public security system asking Claude to produce a “stability maintenance” report. The resulting report recommended “control” measures targeting ten Chinese petitioners, including intercepting petitioners before they could lodge official complaints, coercive questioning, and close monitoring of their movements and communications.
Another local state security bureau used Claude to track overseas dissidents and human rights organizations, gathering information such as the assembly point and route of a pro-democracy march in Vancouver and the venues of Uyghur cultural events in Turkey, and write an internal operation manual for other personnel in the bureau.
In a separate operation targeting Uyghurs in Syria, operators analyzed large volumes of group-chat messages to identify exploitable vulnerabilities, including financial hardship and family separation. They paid particular attention to people with relatives still in Xinjiang and conducted covert recruitment outreach to individuals who might have access to local Uyghur armed groups. The report did not confirm whether recruitment succeeded. The operation also involved locating civilians and planning the suppression of Uyghur journalists.
Religious communities were also subjected to surveillance. The report covered Catholics, Tibetan Buddhist communities, Falun Gong practitioners, and the Presbyterian Church in Taiwan, among others. The dossiers collected personal histories, social relationships, and exploitable “points of leverage,” and even included floor plans of religious venues.
Beyond the surveillance operations targeting dissidents, the report also said that some Chinese AI companies exposed users’ sensitive information while conducting unauthorized model distillation. It named seven Chinese AI companies, including @Alibaba_Qwen, @Moonshot, @deepseek_ai, @ZhipuAI @jietang, and @XiaomiMiMo, alleging their involvement in unauthorized model distillation or related data collection. In some of these activities, sensitive data submitted by users was also forwarded to the US company Anthropic.
According to the report, Moonshot forwarded some Kimi users’ requests to Claude, served Claude’s answers back to those users, and saved some of the exchanges for training. The material included surveillance records submitted by a user assessed to be potentially affiliated with the People’s Liberation Army, drawn from hundreds of cameras in Chengdu and used to track a specific individual. It also included internal code and active access credentials submitted by engineers working for Chinese state-owned enterprises.
The report also stated that Xiaomi submitted saved user conversations and coding sessions to Claude to generate training material. The information included users’ names, contact details, and corporate data. Separately, engineers developing a case management system for a municipal Public Security Bureau in China used DeepSeek, and their requests were forwarded to Claude to help develop a tool that uses citizens’ national ID numbers to compare their movements against police records.
These disclosures raise serious questions about user privacy and AI safety standards. The report warned that unauthorized distillation could enhance dangerous cyber or biological capabilities, while Claude’s existing safety standards would not transfer along with them.
In our view, there is an unavoidable issue at the heart of US–China AI competition: the institutional differences between democracy and authoritarianism will profoundly shape how this technology is used, and whether ordinary people can refuse, question, and exercise oversight over that use.
We have repeatedly seen AI being used to make China’s domestic surveillance and “stability maintenance” systems more efficient, with some operations already extend overseas. As these tools mature, the possibility that these methods will be replicated in other countries and adopted by more authoritarian governments is a risk we must confront.
The democratic AI we support should protect people’s expression, privacy, and freedom to make their own choices. It should also allow the public to hold developers accountable. Every company must demonstrate this through its actions. Publicly exposing such abuses and banning accounts involved in them are responsibilities companies should fulfill.
We thank Anthropic for its disclosures and hope they ultimately translate into protection for the people affected. In the face of continuing repression, we remain committed to the principle of open information and will continue working to ensure that more people can see the realities of Chinese society.
Team Teacher Li