<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>China-Cross-Border-Data-Transmission-Data-Security-Law on 「开源之道」</title><link>https://www.opensourceway.blog/tags/china-cross-border-data-transmission-data-security-law/</link><description>Recent content in China-Cross-Border-Data-Transmission-Data-Security-Law on 「开源之道」</description><generator>Hugo</generator><language>zh-CN</language><copyright>Copyright (c) 2016 - 2026, 「开源之道」·适兕; all rights reserved.</copyright><lastBuildDate>Mon, 28 Sep 2026 01:33:05 +0800</lastBuildDate><atom:link href="https://www.opensourceway.blog/tags/china-cross-border-data-transmission-data-security-law/index.xml" rel="self" type="application/rss+xml"/><item><title>China Open Source Daily — 2026-09-28</title><link>https://www.opensourceway.blog/en/posts/china-open-source-daily/2026/09/2026-09-28/</link><pubDate>Mon, 28 Sep 2026 01:33:05 +0800</pubDate><guid>https://www.opensourceway.blog/en/posts/china-open-source-daily/2026/09/2026-09-28/</guid><description>Two institutionally dense placements on the same unsolved institutional object this series&amp;#39; prior thirty-eight briefings have been documenting — the institutional identity of Chinese open source across institutional borders — plus one technical institutional-form transition. (1) The Information (2026-09-22) reports the Cyberspace Administration of China has opened the first formal regulatory inquiry into a Chinese domestic frontier AI lab over data routed to a U.S. model provider, summoning all seven labs named in Anthropic&amp;#39;s September 10 154-page threat intelligence report (Alibaba, Moonshot, DeepSeek, Zhipu, MiniMax, Xiaomi, SenseTime) and then narrowing the focus to DeepSeek and Moonshot based on the specificity of the examples Anthropic detailed — Moonshot allegedly relayed over 23 million exchanges to Claude May–July 2026 through 5,380 fraudulent accounts across a 10-day window alone, DeepSeek reportedly routed 12.1 million exchanges in a 14-day July window including prompts from engineers building a case-management system for a municipal Public Security Bureau and one Anthropic-assessed-as-likely-PLA-affiliated Kimi user&amp;#39;s request to analyze Chengdu CCTV footage including cameras near PLA facilities and defense-linked institutes. The first-documented instance in this series of a Chinese regulator operating an enforcement mechanism on a Chinese frontier AI lab using the evidentiary basis of a foreign competitor&amp;#39;s threat report, with the CAC&amp;#39;s own separate September 15 batch of ten enforcement cases against domestic API-relay stations and un-declared personal-information transfers to overseas data centers as the domestic regulatory precedent apparatus simultaneously operationalized. (2) DeepSeek posts a 10,000-word paper on arXiv (2609.22978, 2026-09-19) documenting DSec, its production sandbox infrastructure for agentic training at scale — 160-node production-scale unit, ~3 million sandboxes per day, over 380,000 concurrent sandboxes, over 5,000 sandbox creations per second — co-authored by over 130 people including founder Liang Wenfeng, and simultaneously OX Security publicly discloses CVE-2026-82533 (CVSS 9.4, 2026-09-08) in DeepSeek Harness (dsh), DeepSeek&amp;#39;s own open-source local-first coding-agent runtime that reached over 215,000 GitHub stars in the weeks after its August 2026 release — a sandboxed agent could issue a single curl command from inside its own confinement to reach the harness&amp;#39;s unauthenticated loopback control API and elevate its own session to danger-full-access with approval set to never, no credentials or network exposure required. The first-documented instance in this series of a Chinese frontier-lab open-source agent runtime being operationalized at the arXiv-technical-report-plus-industrial-scale-sandbox-infrastructure layer simultaneously with the CVE-critical-sandbox-escape-plus-open-source-agent-runtime-attack-surface layer — the same DeepSeek surface this series&amp;#39; September 24 briefing documented at the UN-Security-Council-AI-briefing-invitation layer with a founder-physical-absence is now being operationalized at the open-source-agent-runtime-critical-vulnerability layer simultaneously. (3) DeepSeek ships V4.1-Flash on 2026-09-10 — a 552B-parameter Mixture-of-Experts model on a new Causal Encoder-Decoder architecture, 8B-active in prefill and 16B-active in decode, 1M-token context, native vision, published ungated on Hugging Face under a plain MIT license with no revenue, user-count, or territory conditions, replacing the April 2026 V4 pair on the same day with V4-Pro requests being rerouted to V4.1-Flash at the cheaper Flash price from noon Beijing time 2026-09-14 — precisely two days after the NSA, CISA, and FBI publish a joint Cybersecurity Advisory (AA26-251A) naming DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI as conducting industrial-scale knowledge distillation campaigns that constitute &amp;#34;the core—not merely a supplement&amp;#34; of their AI development strategy, with the advisory&amp;#39;s sharpest line being that DeepSeek&amp;#39;s widely quoted US$5.6 million training cost is &amp;#34;misleading as it does not include the true cost of the data acquired through extensive malicious distillation.&amp;#34;</description></item></channel></rss>