Leaks and Backdoors: China Warns of Security Risks in Relay Services for Foreign AI Models
China’s security ministry warned that relay services for foreign AI models can leak data and enable illicit trading. It said some platforms lack proper qualification and security controls.
Intelligence analysis by GPT-5.4 Mini

Beijing is flagging a grey market that gives Chinese developers access to restricted foreign AI models through intermediary relay platforms. The warning focuses on privacy leaks, weak security, and possible cross-border data transfers.
China’s security agency is warning that some middleman websites for foreign AI tools can be like a shaky bridge: they may make access easier, but they can also let private information leak or be sold.
Analysis
China’s Ministry of State Security said so-called artificial intelligence relay services can create serious security risks when they sit between local users and overseas model providers. According to the ministry’s notice on WeChat, these platforms aggregate access to domestic and foreign models through a single interface, which makes them convenient and often cheaper than direct access.
The warning is aimed at a market that has grown because some leading US systems, including Anthropic’s Claude and OpenAI’s GPT series, are not officially available to users in mainland China. Even as Chinese AI start-ups improve their own systems, the article says many developers still turn to foreign models for stronger coding performance.
The ministry said the market includes both legitimate and unreliable operators. Its main concern is that some platforms operate without proper qualification and with weak security controls, which can increase the risk of privacy leaks and illicit data trading. It also warned that some relay services may store user data on their own servers without adequate encryption, creating a path for sensitive information to be leaked or sold.
The article points to a familiar policy dilemma: developers want access to the best tools, but intermediaries that unlock those tools can become a security weak point. In this case, the Chinese government is framing those weak points as a national security issue as well as a privacy problem.
Key points
- China’s Ministry of State Security warned about security risks in AI relay services that provide access to foreign models.
- The ministry said some operators lack proper qualification and weak security controls can lead to privacy leaks and illicit data trading.
- Relay services are used because they can provide cheaper access to models that are not officially available in mainland China.
- The article says Chinese developers still seek US models such as Claude and GPT for stronger coding capabilities.
- The ministry said some platforms may store user data without adequate encryption, raising leak and resale risks.
If the warning pushes relay operators to improve qualification, encryption, and data handling, developers could still use these services with fewer privacy risks. Clearer rules could also make the market safer for legitimate platforms.
If weak operators keep growing, sensitive developer data could be exposed, stored insecurely, or traded without permission. The crackdown risk may also make access to foreign AI models harder for Chinese developers who rely on them for coding and other tasks.



