What happened on 11/12 August
Manus is a China-founded vendor of autonomous AI agents that carry out research tasks and multi-step workflows with comparatively little human steering. Meta completed the acquisition in December 2025, for roughly $2 billion. Back in April 2026, China's economic planning body, the NDRC, ordered the deal unwound, citing regulatory violations related to technology export controls and foreign investment. On 11 and 12 August 2026, Manus confirmed in its own blog post that the separation is now formally underway and the company is returning to independent management.
The regulatory core of the order is notable, and relevant to any company working with Chinese AI startups that are formally headquartered abroad: Manus was founded in China and relocated its headquarters to Singapore in summer 2025 - partly to make it easier to attract international capital and Western customers, and to move outside regulatory reach. The NDRC's order makes clear that an offshore address does not remove Chinese regulatory authority when the underlying technology and personnel originated in China. Observers call this practice 'Singapore washing' - and Beijing's response sends a precedent signal to other Chinese AI companies with a similar structure.
The part that matters for companies: the data deletion
I read Manus's own blog post, 'A Note to Our Users', rather than relying solely on press coverage. It states that data certain users generated since 29 December 2025 (the date of the Meta acquisition) will be deleted to meet 'regulatory requirements in specific jurisdictions'. Which jurisdictions, and by what criterion a user counts as 'affected', the post does not say - users are told to check their individual notification or the Help Center instead.
The timeline is tight and firm: the backup window closes at 7:59 a.m. Singapore time on 23 August 2026. Between 8:00 a.m. on 23 August and 8:00 a.m. on 24 August, account access is fully blocked for affected users while deletion runs. Restoring backed-up data only becomes possible from 25 August. Anyone who misses the backup window loses the affected data irrecoverably - Manus offers no grace period.
Also notable is an explicit clarification in the documentation: the deletion is 'not the result of any security incident', but a deliberate, regulator-forced decision. That's more than a formality. A typical security incident triggers established incident-response processes at most companies - notification duties, forensic review, communication to affected customers within fixed deadlines. A geopolitically forced, voluntarily announced deletion falls outside that framework, even though the consequence for a company's own data is identical.
The gap missing from coverage so far: business accounts
Press coverage so far has focused on the geopolitics and on individual consumer users. What doesn't appear prominently in any of the reporting I reviewed for this analysis: Manus's own blog post never directly addresses business or team accounts. The post mentions a 'team plan' without naming any separate exemption, escalation path, or dedicated contact for organizations. A company apparently learns its affected status through the same channel as an individual user - an automated notification or a manual check in the Help Center.
For a company using an AI agent like Manus for multi-step research or workflow automation, that's not a minor detail. Unlike classic chat assistants, agent tools often build context and intermediate results over time - completed research, multi-step task histories, stored credentials to connected systems. That's exactly the kind of data that's most expensive to lose and hardest to reconstruct from a single chat export.
Why this isn't a GDPR or EU AI Act case
This series has repeatedly covered labelling duties and governance requirements under the EU AI Act. The Manus case deliberately doesn't belong in that category. The data deletion wasn't ordered by an EU authority and isn't a response to a European regulation - it's the consequence of a regulatory conflict between China and the US that a European company simply using Manus as a tool has no part in whatsoever. GDPR governs how a provider must handle the personal data of European users; it doesn't govern what happens when the provider itself is forced by a foreign regulator to delete its own infrastructure.
That's the real lesson from this case: vendor risk with AI tools isn't only a question of data protection impact assessments and data processing agreements. With vendors headquartered or technologically rooted outside the EU - particularly Chinese AI agent vendors currently courting Western business customers with aggressive pricing and strong benchmark numbers - there's an additional layer of risk that no European compliance checklist covers: the possibility that a foreign regulator intervenes in the vendor's corporate structure on short notice, with consequences for your own data availability, through no fault of your own.
What this means in practice
This case isn't a reason for blanket avoidance of Chinese or other non-European AI vendors - many deliver competitive performance at attractive prices. But it's a very concrete, live example of why vendor risk with AI tools deserves its own review, separate from model quality and price.
- Treat regular backups as a standing practice, not a reaction to an announcement: waiting for a deletion notice before starting an export can leave only days, depending on the vendor - with Manus, specifically until 23 August, 7:59 a.m. SGT.
- For every AI agent vendor in use, check where its corporate headquarters, technological origin, and actual data location sit - an offshore address like Singapore does not, as the Manus case shows, necessarily shield you from the reach of the originating jurisdiction.
- Prepare an exit strategy for business-critical agent workflows before you need it: which intermediate results, credentials, and task histories live only with the vendor, and how quickly could they be exported or moved to another system?
- Review AI agent vendors' contracts and terms of service specifically for clauses on termination, data deletion, and regulator-forced operational changes - not just for narrower data protection and liability clauses.
The case fits a pattern that has come up repeatedly in this series: relying solely on GDPR compliance and EU AI Act requirements when choosing an AI vendor doesn't automatically cover every relevant risk. Geopolitical and regulatory conflicts a company has no part in can still lead to deletion of its own working data - on a timeline it doesn't get to set.