China's MSS warns of data leaks via AI relay services for foreign models
Synopsis
Key Takeaways
China's Ministry of State Security (MSS) has issued a formal warning about the security risks posed by AI relay services — intermediary platforms that give Chinese developers access to restricted foreign AI models — citing concerns over data leaks, privacy breaches, and unauthorised cross-border data transfers. The notice, published on the ministry's official WeChat account on Monday, 8 June 2026, comes as demand for such services surges among developers seeking access to US systems including Anthropic's Claude and Microsoft-backed OpenAI's GPT series, neither of which officially supports users in mainland China.
What are AI relay services?
According to the MSS, AI relay services act as aggregators, bundling access to multiple domestic and overseas AI models through a single interface. They have proliferated as a grey-market workaround, offering Chinese developers convenience, lower prices, and access to frontier foreign models that are otherwise unavailable in the country. The ministry described them as intermediaries sitting between local developers and the underlying AI providers.
Why it matters
The MSS warned that some relay platform operators function 'without proper qualification and with weak security controls, increasing the risk of privacy leaks and illicit data trading.' The ministry also noted that certain platforms retain user data on their servers without adequate encryption, creating conditions under which sensitive information could be leaked or sold. The warning reflects growing regulatory anxiety in Beijing over the flow of Chinese user data through unvetted third-party infrastructure to foreign AI systems.
The competitive backdrop
The relay market exists in direct tension with China's broader push to champion domestic AI alternatives such as DeepSeek, Alibaba's models, and other homegrown systems. Despite the availability of competitive domestic options, a segment of Chinese developers continues to seek out OpenAI's and Anthropic's models — widely regarded by benchmarks such as those tracked by Artificial Analysis and Google's Gemini evaluations as among the most capable globally. The relay services industry has flourished precisely because official access channels remain closed.
What the MSS said
The ministry's notice acknowledged that the AI relay market includes both legitimate and unreliable operators. However, it drew particular attention to the subset of platforms operating with inadequate security controls. No specific relay service operators were named in the notice. The MSS did not announce specific enforcement actions or new regulations alongside the warning, though the public notice signals heightened official scrutiny of the sector.
What's next
The warning is likely a precursor to more formal regulatory guidance targeting relay service operators, particularly those handling data that crosses China's borders. Developers currently relying on such platforms to access Claude, the GPT series, or other foreign models face growing compliance uncertainty. How Beijing moves to formalise oversight of this grey market — and whether it targets operators, users, or both — will be the key development to watch in the coming months.