Abstract:
Have your family members or friends been taken away by the police for operating an AI relay station? Or are you currently engaged in the API interface business, with a vague sense that something is amiss? This article explains in plain language: reverse scraping, reselling free quotas, and reselling user conversation logs are the three scenarios most likely to lead to legal trouble. You will clearly understand what you may face next—37 days of criminal detention, the possibility of release on bail pending trial, and the one thing you should do right now.
Keywords:
Crime of illegal business operations, Crime of infringing upon citizens' personal information, Crime of refusing to fulfill obligations for information network security management, Release on bail pending trial, AI relay station
Special Declaration:This article is an original work by Attorney Shao Shiwei and represents only the author's individual views. It does not constitute legal consultation or legal advice on specific matters. For article reprints, legal consultations, or professional exchanges, please add: sswls66.
Main Text:
According to news within the AI practitioner community, in May 2026, the operator of an AI relay station publicly issued a statement claiming that he was criminally detained for 37 days for illegally reverse-scraping and reselling low-priced AI interface resources, and is currently released on bail pending trial.

In the past two years, domestic demand for AI applications has exploded. However, due to regional restrictions on overseas large language models, more and more people are operating AI relay stations. Simply put, domestic users want to use these services but cannot access them directly; relay stations help bridge this channel and charge a fee for the service.
Therefore, using this case as a starting point, we can discuss whether the currently booming AI relay station business is still viable, and what risks ordinary individuals might face when operating an AI relay station.
I. Author of this Article: Attorney Shao Shiwei
1
The Highly Profitable Business of AI Relay Stations
According to a report by Xinhua News Agency, China's daily token call volume grew by more than a thousandfold from early 2024 to March 2026. The demand is evident.
However, if domestic users wish to use overseas large language models (such as OpenAI, Anthropic, Google, etc.), they encounter numerous barriers, including network environment restrictions, payment channels, and identity verification.
Where there are barriers, there is business. AI relay stations have emerged to meet this need. On many self-media platforms, it is claimed that AI API relay stations are one of the most profitable projects in 2026, which is not entirely untrue.
An AI relay station can also be understood as an "AI scalper." It packages interfaces from different AI model providers into a unified exit point, connecting users to all models in the background. This saves users the trouble of using tools to bypass internet restrictions or figuring out how to make payments in foreign currencies.
On platforms such as Taobao, Xianyu, and Xiaohongshu, many such posts can be seen, with prices astonishingly low.


This raises the question: With prices pressed so low, how do relay station operators actually make money?
Resellingfree quotas. Platforms like ChatGPT and Claude provide free quotas when new accounts are registered. The account vendors behind relay stations batch-register a large number of accounts to exploit the platforms' free quotas. They then use technical means to reverse-engineer the web interfaces of these accounts into standard APIs and sell them uniformly, with costs close to zero.
Refund Arbitrage。 Batch-register official accounts, recharge funds, and call the APIs. What happens if an account is banned? Apply for a refund. In most cases, the prepaid funds can be recovered. This means they use your money to call the APIs first, and if banned, they recover the cost from the official provider, profiting from both sides.
FalseReporting of Tokens。 Official APIs strictly bill based on the number of tokens. However, the billing system of a relay station is written by the operator themselves. Normally, one Chinese character consumes approximately 1.5 to 2 tokens. Some relay stations increase the multiplier in the backend, causing one Chinese character to be charged as 3 to 4 tokens. Users have no way to verify this.
Model Swapping. You purchase access to Claude Opus 4.7, but the actual model called might be a small open-source model. This is why many users feel that the models used via relay stations seem to have reduced intelligence.

Data Resale. Complete user conversation logs, especially high-quality training data such as code, reasoning processes, and engineering decisions in programming scenarios, are packaged and sold to model providers. Why are relay stations cheap? In reality, they profit by selling data.
However, the greater the traffic, the greater the accompanying risks.
2
Why AreAI Relay Station Operators Arrested??
We have previously outlined the profit models of AI relay stations. As operators, they may be aware of the risks associated with such gray-market projects. However, after operating for some time and making profits, and seeing that peers have not faced issues, they gradually lower their guard.
From a legal perspective, the criminal risks of AI relay stations are mainly concentrated in three areas.
First, the businessmodel itself is suspected of being illegal.
The computing resources of AI relay stations are not procured through formal channels by purchasing API interfaces. Instead, they involve batch-registering accounts to exploit free quotas or using technical means to reverse-engineer interface permissions. This falls outside the scope of normal commercial agency.
Providing information relay and data processing services is, in nature, a value-added telecommunications business. According to the Regulations of the People's Republic of China on Telecommunications, operating such businesses requires obtaining the corresponding administrative license. Operating without permission carries the risk of violating the Crime of illegal business operations.
Furthermore, overseas large language model providers impose access restrictions on users in China. Relay stations help users bypass these restrictions through proxy IPs and fabricated identity information, effectively assisting in evading the access conditions set by service providers. If this behavior is deemed to disrupt market order, it may also fall within the scope of the Crime of illegal business operations.
Second, Lack of Data Security Obligations。
AI relay stations process a large volume of interaction data between users and models daily. Prompts, code snippets, and business documents sent by users are transmitted and processed through the relay station's servers. As the actual handler of the data, the relay station bears corresponding security management responsibilities under the law.
However, in reality, the vast majority of relay stations have not established any data security management systems—data storage locations, access control permissions, and security protection measures are all nonexistent. In the event of a data breach, whether caused by external attacks or internal management failures, the relay station, as a network service provider, may face criminal prosecution for the Crime of refusing to fulfill obligations for information network security management. This crime specifically targets the situation of "having statutory obligations but failing to fulfill them."
Third, Illegal Collection and Sale of User Data.
Some relay stations package and sell user conversation logs to third parties, which is not an isolated phenomenon in the industry. However, the legal risks associated with this behavior are generally underestimated.
Conversations between users and AI models often contain personal information, trade secrets, and other sensitive data. When collecting this data, relay stations rarely obtain explicit consent from users, nor do they fulfill the obligation to inform users about the purpose and flow of the data. Collecting and providing such information to third parties without consent, if the circumstances are serious, constitutes the Crime of infringing upon citizens' personal information.
The threshold for criminal liability for this offense is not high. According to relevant judicial interpretations, illegally obtaining, selling, or providing fifty or more items of location trajectory information, communication content, credit information, or property information, or five hundred or more items of other personal information that may affect personal or property safety, such as accommodation information, communication records, health and physiological information, or transaction information, meets the standard for prosecution. Given the daily data processing volume of relay stations, reaching this threshold is not difficult.
3
Concluding Remarks
Regarding the issue of AI relay stations, Attorney Shao does not wish to limit the discussion to whether operators will be prosecuted. This event actually reflects the inevitable challenges that the AI industry must face during its rapid development phase.
For users, relay stations lower the barrier to entry, but they also expose users' sensitive data to an intermediary link that lacks qualifications and security guarantees. If problems arise, users may not even find a party against whom to assert their rights.
For providers, the existence of relay stations drains their technical investments and business models. Free quotas are exploited in bulk, paid interfaces are reverse-engineered and stolen, and pricing systems are undermined. Providers are forced to shift significant resources from product research and development to risk control countermeasures, and these costs are ultimately passed on to normal paying users. A deeper harm lies in the fact that when relay stations dump computing power at low prices, the market's perception of the value of AI services is being distorted—users gradually come to believe that these capabilities should be nearly free. This harms the sustainable development of the entire industry.
As a lawyer specializing in the new economy, Attorney Shao has been closely monitoring the development of the AI industry and has served many practitioners in this field. How far an industry can go depends not on how fast it runs, but on whether it can establish basic commercial order and a foundation of trust. The AI industry is at a critical stage of transitioning from wild growth to standardized operation. The choices of every practitioner are shaping the future ecosystem of this industry.
A healthy AI industry requires providers to continue investing in technological research and development, requires users' data rights to be effectively protected, and requires practitioners to participate in market competition in a compliant and responsible manner. These are the prerequisites for the long-term survival of the industry. Attorney Shao hopes to see more practitioners choose to do the difficult but right things, thereby laying a more solid foundation for this industry.

Recommended Reading
Analysis of AI Agent Computing Power Arbitrage Models and Their Legal Risks


