Skip to content
Beyond Prompt AI Studio

Governance & guardrails

An AI agent vendor is about to delete customer data - not over GDPR, but an order from Beijing

August 14, 2026 · 11 min read · Beyond Prompt AI Studio

AgentsVendor riskLawData protection

On 11 and 12 August 2026, AI agent vendor Manus confirmed in a blog post titled 'A Note to Our Users' what had been signalled since April: the company is returning to independent operation after China's economic planning body, the NDRC, ordered Meta's $2 billion acquisition - completed in December 2025 - to be unwound. The regulator's reasoning: Manus was founded in China and relocated to Singapore, in part to more easily attract international capital and Western customers - a practice critics call 'Singapore washing'. Beijing's order makes clear that an offshore address doesn't shield a deal from Chinese regulatory authority when the underlying technology and talent originated in China. But for companies using Manus or comparable AI agents, the real story isn't the geopolitics - it's a very concrete consequence: data is being deleted, and Manus's own documentation leaves open exactly who that affects.

Key points at a glance

  • Manus officially confirmed on 11/12 August 2026 that it is separating from Meta, after China's NDRC ordered the December 2025, $2 billion acquisition unwound - on the grounds that Manus's relocation to Singapore did not remove it from Chinese regulatory authority.
  • Data created by certain users since the Meta acquisition (29 December 2025) will be deleted between 23 and 24 August 2026, to meet what Manus itself calls 'regulatory requirements in specific jurisdictions' - the official blog post does not name which jurisdictions.
  • Affected users only have until 7:59 a.m. Singapore time on 23 August to back up their data. Account access is blocked during deletion (23-24 August); restoration only becomes possible from 25 August.
  • The official blog post does not mention business or team accounts once. Whether a business account is affected is, per Manus, only communicated through an individual notification or the Help Center - there is no blanket exemption for business customers.
  • Manus explicitly states the deletion is 'not the result of any security incident' but a deliberate regulatory decision - which sets the case apart from a typical data breach and makes it harder to route through existing incident-response processes.
  • The case exposes a vendor risk that neither GDPR nor the EU AI Act covers: a geopolitical regulatory conflict between two states that the using company itself has no part in can still lead to deletion of its own working data - with roughly ten days' notice.

What happened on 11/12 August

Manus is a China-founded vendor of autonomous AI agents that carry out research tasks and multi-step workflows with comparatively little human steering. Meta completed the acquisition in December 2025, for roughly $2 billion. Back in April 2026, China's economic planning body, the NDRC, ordered the deal unwound, citing regulatory violations related to technology export controls and foreign investment. On 11 and 12 August 2026, Manus confirmed in its own blog post that the separation is now formally underway and the company is returning to independent management.

The regulatory core of the order is notable, and relevant to any company working with Chinese AI startups that are formally headquartered abroad: Manus was founded in China and relocated its headquarters to Singapore in summer 2025 - partly to make it easier to attract international capital and Western customers, and to move outside regulatory reach. The NDRC's order makes clear that an offshore address does not remove Chinese regulatory authority when the underlying technology and personnel originated in China. Observers call this practice 'Singapore washing' - and Beijing's response sends a precedent signal to other Chinese AI companies with a similar structure.

The part that matters for companies: the data deletion

I read Manus's own blog post, 'A Note to Our Users', rather than relying solely on press coverage. It states that data certain users generated since 29 December 2025 (the date of the Meta acquisition) will be deleted to meet 'regulatory requirements in specific jurisdictions'. Which jurisdictions, and by what criterion a user counts as 'affected', the post does not say - users are told to check their individual notification or the Help Center instead.

The timeline is tight and firm: the backup window closes at 7:59 a.m. Singapore time on 23 August 2026. Between 8:00 a.m. on 23 August and 8:00 a.m. on 24 August, account access is fully blocked for affected users while deletion runs. Restoring backed-up data only becomes possible from 25 August. Anyone who misses the backup window loses the affected data irrecoverably - Manus offers no grace period.

Also notable is an explicit clarification in the documentation: the deletion is 'not the result of any security incident', but a deliberate, regulator-forced decision. That's more than a formality. A typical security incident triggers established incident-response processes at most companies - notification duties, forensic review, communication to affected customers within fixed deadlines. A geopolitically forced, voluntarily announced deletion falls outside that framework, even though the consequence for a company's own data is identical.

The gap missing from coverage so far: business accounts

Press coverage so far has focused on the geopolitics and on individual consumer users. What doesn't appear prominently in any of the reporting I reviewed for this analysis: Manus's own blog post never directly addresses business or team accounts. The post mentions a 'team plan' without naming any separate exemption, escalation path, or dedicated contact for organizations. A company apparently learns its affected status through the same channel as an individual user - an automated notification or a manual check in the Help Center.

For a company using an AI agent like Manus for multi-step research or workflow automation, that's not a minor detail. Unlike classic chat assistants, agent tools often build context and intermediate results over time - completed research, multi-step task histories, stored credentials to connected systems. That's exactly the kind of data that's most expensive to lose and hardest to reconstruct from a single chat export.

Why this isn't a GDPR or EU AI Act case

This series has repeatedly covered labelling duties and governance requirements under the EU AI Act. The Manus case deliberately doesn't belong in that category. The data deletion wasn't ordered by an EU authority and isn't a response to a European regulation - it's the consequence of a regulatory conflict between China and the US that a European company simply using Manus as a tool has no part in whatsoever. GDPR governs how a provider must handle the personal data of European users; it doesn't govern what happens when the provider itself is forced by a foreign regulator to delete its own infrastructure.

That's the real lesson from this case: vendor risk with AI tools isn't only a question of data protection impact assessments and data processing agreements. With vendors headquartered or technologically rooted outside the EU - particularly Chinese AI agent vendors currently courting Western business customers with aggressive pricing and strong benchmark numbers - there's an additional layer of risk that no European compliance checklist covers: the possibility that a foreign regulator intervenes in the vendor's corporate structure on short notice, with consequences for your own data availability, through no fault of your own.

What this means in practice

This case isn't a reason for blanket avoidance of Chinese or other non-European AI vendors - many deliver competitive performance at attractive prices. But it's a very concrete, live example of why vendor risk with AI tools deserves its own review, separate from model quality and price.

  • Treat regular backups as a standing practice, not a reaction to an announcement: waiting for a deletion notice before starting an export can leave only days, depending on the vendor - with Manus, specifically until 23 August, 7:59 a.m. SGT.
  • For every AI agent vendor in use, check where its corporate headquarters, technological origin, and actual data location sit - an offshore address like Singapore does not, as the Manus case shows, necessarily shield you from the reach of the originating jurisdiction.
  • Prepare an exit strategy for business-critical agent workflows before you need it: which intermediate results, credentials, and task histories live only with the vendor, and how quickly could they be exported or moved to another system?
  • Review AI agent vendors' contracts and terms of service specifically for clauses on termination, data deletion, and regulator-forced operational changes - not just for narrower data protection and liability clauses.

The case fits a pattern that has come up repeatedly in this series: relying solely on GDPR compliance and EU AI Act requirements when choosing an AI vendor doesn't automatically cover every relevant risk. Geopolitical and regulatory conflicts a company has no part in can still lead to deletion of its own working data - on a timeline it doesn't get to set.

Frequently asked questions about the Manus case and AI agent vendor risk

Is our company affected by the Manus data deletion if we use the tool?

There's no blanket answer. Manus's own blog post names no clear criteria for business or team accounts and instead points users to individual notifications or the Help Center. Per Manus, affected users are those whose data was created since the Meta acquisition on 29 December 2025 - anyone using Manus should actively check their own account status rather than assume an automatic exemption for business customers.

Is this a GDPR violation or a data breach?

No. Manus explicitly states the deletion is not the result of a security incident, but a deliberate response to an order from China's economic planning body, the NDRC. GDPR governs how a provider handles personal data; it doesn't govern regulator-forced changes to that provider's corporate structure.

What can we actually do right now if we use Manus?

Above all, back up in time. The backup window closes on 23 August 2026 at 7:59 a.m. Singapore time; access is then blocked until 24 August, and restoration only becomes possible from 25 August. Anyone holding business-critical work in Manus should export it as a precaution, regardless of their confirmed affected status.

Does this risk apply only to Manus, or more broadly?

The specific trigger is Manus-specific; the underlying risk is not. Any AI vendor headquartered or technologically rooted outside the EU can be forced by its home jurisdiction's regulator into short-notice changes that affect customer data - regardless of how carefully that vendor implements GDPR for its European users.

Want your AI tool stack reviewed for vendor risk and exit readiness - before a foreign regulator sets the timeline for you?