The $500 Million Pipeline of American AI Expertise to Beijing
While Washington has spent years building a regulatory fortress around advanced AI chips, a parallel and largely unsupervised trade has flourished: the sale of high-quality training data by Silicon Valley startups to Chinese artificial intelligence labs. Forbes has obtained internal documents and communications showing that at least six marquee US data-labeling companies — among them Surge AI, Mercor, AfterQuery, and Turing — count China’s biggest AI players, including Tencent, Alibaba, ByteDance, and Ant Group, as paying clients.
These are no small deals. According to two industry entrepreneurs briefed by executives at Tencent and ByteDance, the top six Chinese AI labs together spend roughly $500 million a year with American data providers. The data packages they buy — often customized, sometimes “off-the-shelf” — are the same carefully structured, expert-vetted training sets that power frontier models from OpenAI and Anthropic. In essence, Chinese labs are purchasing the hard-won professional knowledge and reasoning architectures that make American AI models so capable, skipping months of trial and error and directly absorbing the output of PhD-level networks vetted by US firms.
The connections sometimes cut uncomfortably close to US national security. Surge AI, whose client list has included the US Army, the US Air Force, and Anthropic, counts Tencent — a company the Pentagon has designated as linked to China’s military — among its data buyers. Mercor, which recently told employees it had secured a US federal government contract, also works with Tencent and ByteDance. Turing’s internal project documents suggest collaboration with ByteDance, the parent of TikTok. When reached for comment, most Chinese firms did not respond, while Mercor declined to comment and Turing defended its work by noting that strong open-source models often come from labs outside the US.
Inside the Invisible Knowledge Supply Chain That Bypasses Chip Controls
The Knowledge Pipeline from Pentagon Contractors to Beijing
The startling reality is that the same data supply chains that undergird US military AI projects and the strongest American commercial models are being explicitly sold to Chinese counterparts. A Tencent procurement executive whose message was reviewed by Forbes stated the company relied on Surge AI for data supply. Internal project documents tie Turing to ByteDance. AfterQuery’s CEO confirmed close collaboration with Ant Group. These are not occasional one-off sales; they represent sustained, high-value commercial relationships that intentionally transfer the structures of expert cognition — task designs, quality rubrics, and grading criteria — developed at the frontier of US AI research.
The consequence is strategic. A former Allen Institute for AI researcher quoted in the investigation bluntly states that after compute, quality data is the most important ingredient. By buying from the same vendors, Chinese labs gain capability parity not by inventing but by imitating the data recipes that made GPT-4 and Claude successful. AI consultant Sean Cai, who studies data supply chains, says the loop is direct: "A large portion of the same US data that enables the progress of US models is also sold to Chinese labs."
Why This Trade Flies Under the Radar
Unlike semiconductor exports, training data has no Wassenaar Arrangement, no BIS entity-list restrictions, and no mandatory government review. The data sets — often packaged as "off-the-shelf" (OTS) products — are sold as digital goods, not munitions. Many are derived from work originally done for OpenAI or Anthropic; vendors repurpose the same expert networks and quality-control algorithms to create data packages that can be resold to multiple buyers, including Chinese labs. This OTS model offers the highest profit margins and makes it easy for a vendor to hand Beijing the same curated knowledge that cost a US lab tens of millions of dollars to develop.
Chinese buyers, one executive who dealt with them told Forbes, openly say they want to buy exactly what the American labs have already purchased. The result is a multi-hundred-million-dollar parallel market that operates entirely outside the chip export controls and has received almost no congressional or public scrutiny. By the time a lab like Moonshot or ByteDance trains its next model, it has already acquired the scaffold of human expertise that defines the state of the art.
The Geopolitical Stakes Are No Longer Abstract
The scale of the dependency is now too large to ignore. Mercor, founded in 2023, is targeting a $20 billion valuation; Surge AI is reportedly worth at least $25 billion; AfterQuery's annual recurring revenue jumped from $100 million to several hundred million in three months. All of them have material, though varying, exposure to Chinese revenue. Even if that exposure is modest — Mercor’s Chinese AI lab revenue reportedly amounted to just 2% of total revenue in Q2 — the strategic value of the transferred knowledge vastly exceeds the dollar amounts invoiced.
Moreover, the Pentagon’s designation of Tencent as a Chinese military company and the known involvement of these US vendors with federal contracts raise acute questions about potential national security vulnerabilities. The founder of a venture firm that has invested in multiple US AI model developers called it an "ethical decision" whether to sell data to Chinese AI companies. But with the US already engaged in a tech decoupling that spent years fencing off advanced chips, the absence of any fence around data — arguably as critical as compute — looks increasingly like a policy vacuum.
What Washington, Investors, and AI Executives Must Do About the Data Gap
For US policymakers: The investigation reveals a regulatory blind spot. Congress should urgently explore whether the sale of high-value AI training data to entities tied to a strategic rival’s military warrants inclusion on the entity list or a new data-export control framework. The Commerce Department’s Bureau of Industry and Security must define when advanced data packages become sensitive enough to trigger national security reviews analogous to those for chips.
For investors in AI data startups: The commingling of US government contracts and Chinese military-linked clients carries a serious reputational and commercial risk. Any future congressional inquiry or executive action could abruptly end a startup’s ability to serve US federal clients. Boards should demand immediate audits of client lists and assess the exposure of their portfolio companies to Chinese AI lab revenue — not just in percentage terms but in terms of the strategic sensitivity of the data sold.
For US AI labs and their vendors: OpenAI, Anthropic, and other frontier labs should review their data-supply contracts to understand whether their proprietary data architectures are being recycled for competitors in China. Contractual clauses that prohibit repurposing of data recipes for non-authorized entities could become a near-term defensive measure. Additionally, labs with sensitive government work must evaluate whether data providers with Chinese ties create unacceptable supply-chain risk.
For Chinese AI labs: In the absence of new US restrictions, this data pipeline will continue to provide a fast track to close the capability gap. Labs that have built procurement offices in the US will likely accelerate buying while the window remains open. The $500 million annual spend signals that Beijing views this as a cost of competing at the frontier — and the return on that spending is measured in months shaved off model development cycles.
Risk & Opportunity Assessment
| Commercial Risk | High | Data-labeling startups with significant Chinese revenue face potential loss of US federal contracts and enterprise customers if the trade is framed as a national security risk. |
| Competitive Risk | High | US frontier labs lose proprietary data advantages as their training recipes are sold to Chinese rivals, accelerating the capability catch-up of models like Kimi K3. |
| Regulatory Risk | High | The investigation exposes a policy vacuum; lawmakers are likely to propose new data-export controls that could radically alter the business models of US data firms overnight. |
| Reputation Risk | Critical | Several startups named in the piece have direct connections to the Pentagon or US Air Force while simultaneously serving Tencent, a company the Pentagon has linked to the Chinese military. |
| Technology Disruption | Medium | While the trade itself does not introduce a new technology, the cross-border transfer of expert data curriculums disrupts the competitive advantage US labs believed they held through data quality. |
| Commercial Opportunity | Transformational | Chinese AI labs’ $500M annual spend represents a transformational revenue stream for US data startups, but one that carries existential regulatory and reputational downsides. |
Comments 0