Anthropic hunts down the Chinese firms working around Claude
The Financial Times reports that Anthropic is actively closing a series of loopholes that allowed Chinese firms like Ant Group, Alibaba's financial
- The Financial Times reports that Anthropic is actively closing a series of loopholes that allowed Chinese firms like Ant Group, Alibaba's financial
- Introduction: an endless race against workarounds
- Loopholes exploited through hidden relays
Facts, quotes, and cited links remain in the body. Interpretations are framed as analysis or opinion according to the format.
Introduction: an endless race against workarounds
Loopholes exploited through hidden relays
The Financial Times reports that Anthropic is actively closing a series of loopholes that allowed Chinese firms like Ant Group, Alibaba's financial affiliate, to access its Claude model despite explicit restrictions. The main mechanism relies on services called transfer stations: relays that accept requests from Chinese users, forward them to Claude's API, then return the answers while masking the true origin of the request in the system logs.
According to people close to the matter cited by the Financial Times, Ant Financial reportedly gave its employees corporate Claude accounts accessible through its intranet, itself linked to its Singapore-based entity. This kind of workaround, technical but effective, illustrates the persistent difficulty of enforcing geographic restrictions in a world of interconnected cloud infrastructure.
A move directly tied to the distillation accusations
This crackdown on workarounds comes directly on the heels of accusations Anthropic leveled at Alibaba, which it calls the largest distillation attack ever known against Claude. According to a letter sent to the U.S. Senate, operators linked to Alibaba's Qwen lab allegedly created nearly 25,000 fraudulent accounts generating more than 28.8 million exchanges with Claude between April 22 and June 5, 2026.
Distillation involves massively querying a more powerful model to train a cheaper model to replicate its capabilities, a practice Anthropic considers illegitimate when it deliberately aims to get around its policy of denying commercial access to China. The company says this campaign specifically targeted Claude's most advanced capabilities: complex software engineering and long-horizon autonomous reasoning.
Three categories of workaround identified
Cloud providers and foreign subsidiaries
Beyond transfer stations, the Financial Times identifies a second category of workaround: Chinese companies routing their API requests through American or European subsidiaries, or through cloud platforms that are technically compliant as Anthropic customers, which then sub-route those requests to end users in China. Microsoft reportedly sold API access through its Azure cloud infrastructure to Chinese entities operating out of Singapore.
A third category involves foreign subsidiaries of Chinese companies formally incorporated in jurisdictions where Claude access is permitted, but whose actual end users are located in mainland China. This kind of complex legal structuring makes detection particularly difficult for Anthropic's compliance teams.
ByteDance and the quiet subscription reimbursements
Chinese giant ByteDance, the owner of TikTok, reportedly set up an expense-reimbursement policy letting its engineers get refunded for individual Claude subscriptions, with those employees then accessing the model through virtual private networks. This method, while breaking neither Chinese nor American law, is a direct violation of Anthropic's terms of service.
These practices reveal an unavoidable truth: even without explicitly breaking a national law, getting around the terms of service of a private American company to access cutting-edge artificial intelligence technology raises an underlying problem that contract enforcement alone struggles to solve.
The regulatory backdrop pushing Anthropic to act
Commitments made to the U.S. government
This loophole-closing effort is part of formal commitments Anthropic made to the U.S. government during negotiations over the ban on its Fable and Mythos models, imposed on June 12, 2026 by the U.S. Department of Commerce. Those restrictions stemmed from fears the models could be used by Chinese military intelligence entities or other countries of concern.
Anthropic had already, as early as September 2025, updated its terms of service to bar access to any company majority-owned, directly or indirectly, by interests based in China, Russia, North Korea, or Iran, regardless of the entity's physical location. That decision already meant giving up revenue estimated in the hundreds of millions of dollars.
A stricter policy than its competitors
According to the reporting, Anthropic maintains verification protocols notably stricter than its direct competitors, including OpenAI, whose systems remain easily accessible through standard VPN setups. To counter the latest evasion techniques, Anthropic reportedly now uses structural indicators within Claude Code, such as computers' localized time zones, to identify users' true geographic location.
This heightened rigor sets Anthropic apart in an industry where the temptation to look the other way on substantial revenue, even revenue generated through workarounds, could easily outweigh longer-term national security considerations.
China's response: ingenuity and denial
Engineers finding new workarounds just as fast
Despite Anthropic's efforts, engineers at Chinese companies reportedly keep finding new workarounds almost as quickly as the company closes old loopholes, according to sources cited by the Financial Times. This perpetual race between restrictions and workarounds illustrates the structural limits of a purely technical approach against such strong market demand.
On Chinese social media, some commentators have even suggested, with a touch of irony, that one could simply buy a Claude account directly on e-commerce platforms like Taobao, showing just how normalized these workarounds have become in certain Chinese tech circles.
Alibaba firmly denies the distillation accusations
For its part, Alibaba has firmly denied the distillation accusations leveled by Anthropic, stating it does not use the outputs of proprietary artificial intelligence models to train its own systems and insisting its AI development complies with applicable intellectual property laws. At this stage, Anthropic's allegations remain independently unverified.
A Chinese expert cited by state media, meanwhile, described these accusations as a reflection of technological hegemonic anxiety aimed at slowing China's AI progress, adding that Anthropic was allegedly using litigation to protect its monopoly rather than fostering open, collaborative innovation.
What this tech battle reveals about U.S.-China rivalry
A precedent that goes beyond the Claude case alone
This case isn't isolated: back in February 2026, Anthropic had already accused Chinese labs DeepSeek, Moonshot AI, and MiniMax of running similar campaigns, generating more than 19 million fraudulent exchanges with Claude between them. This repetition of workaround attempts, by different actors but with similar methods, points to a structural pattern rather than a series of isolated incidents.
This accumulation of precedents strengthens Anthropic's argument that access to frontier artificial intelligence models should be treated with the same rigor as technologies subject to export controls, a position that could shape future regulation across the entire sector if it gains traction in Washington.
The West facing the urgency of preserving its technological edge
This battle to close technical loopholes illustrates a much larger stake: the West's ability to preserve its lead in the artificial intelligence race against a China determined to close the gap, through legitimate research but also, it seems, through more questionable workarounds of the commercial restrictions imposed by American companies.
Every loophole Anthropic closes is a tactical win, but the real battle will be decided by the entire American AI industry's ability to maintain collective, coordinated vigilance, rather than leaving each company to manage its own security gaps in isolation against unrelenting Chinese competitive pressure.
The role of global cloud supply chains
An interconnection that complicates any geographic restriction
The complexity of global cloud supply chains makes Anthropic's task especially difficult: a company can technically comply with the terms of service in the country where it's officially registered while quietly sub-routing its requests to users located in restricted jurisdictions like China. This technical architecture makes detection far more complex than simple IP address blocking.
Even major cloud providers like Microsoft sometimes find themselves, perhaps unintentionally, in a gray zone where their official customers comply with the surface-level contractual terms while enabling, downstream, access for end users who normally shouldn't be entitled to it under Anthropic's policy.
The shared responsibility of technology intermediaries
This situation raises a question of shared responsibility: to what extent should infrastructure providers like Microsoft Azure be required to actively verify the ultimate identity of their customers' users, rather than settling for first-tier contractual compliance with their direct partners?
Without closer coordination between Anthropic and the entire ecosystem of cloud infrastructure providers involved, every loophole closed risks simply pushing the problem to another link in the technology chain, without ever resolving the structural problem at its root.
Implications for other American AI labs
OpenAI and Google facing the same structural challenge
While Anthropic stands out for the rigor of its verification protocols, nothing suggests its direct competitors, OpenAI and Google, aren't facing exactly the same kind of Chinese workarounds, simply with less public transparency about the scale of the problem. The absence of public disclosure doesn't necessarily mean the absence of the threat itself.
This information asymmetry among American artificial intelligence labs complicates regulators' ability to assess the true scale of the problem across the whole industry, rather than case by case based solely on which company chooses to speak publicly about its own security incidents.
Toward coordinated information-sharing among rival labs
Anthropic, OpenAI, and Google have reportedly already begun collaborating to share information on distillation attempts that violate their respective terms of service, an unprecedented move toward cooperation among direct competitors against a common external threat. This cooperation, while still in its early stages, could evolve into a more formal industry standard for shared detection.
This kind of inter-lab cooperation, if it solidifies, could become a model for the entire American tech sector confronting similar attempts at unauthorized extraction of proprietary capabilities by determined foreign actors.
What Washington could do to reinforce this effort
Toward a more binding regulatory framework
Several U.S. lawmakers, including members of the Senate Banking Committee who received Anthropic's letter, are now considering additional sanctions against Chinese companies identified as having illegally extracted American artificial intelligence capabilities. A more binding regulatory framework could impose stronger verification obligations directly on cloud infrastructure providers.
Such a framework would turn access to frontier artificial intelligence models into a regime comparable to export controls on advanced semiconductors, with traceability and identity verification obligations far stricter than the simple contractual compliance currently in place.
The urgency of acting before the lead erodes
Every month of delay in establishing a more robust regulatory framework is another opportunity for determined Chinese actors to extract, through distillation or direct workarounds, capabilities that American labs spent years and billions of dollars developing. The urgency isn't just commercial — it directly touches American and Western national security.
The West cannot afford to treat this as a simple commercial dispute between private companies: it touches on the very capacity to maintain a technological lead against a strategic rival investing massively to close that gap, by whatever means available.
Discover
INVESTIGATION: Epstein a Foreign Agent? The Letter That Moves…
On July 21, 2026 , Jamie Raskin, Ranking Member of the…
TESTIMONY: Assam, 700,000 Displaced and a State Rebuilding Every…
On July 20, 2026 , Al Jazeera reported that at least…
ANALYSIS: Gaza's Phase Two, a Ceasefire Stalled in Cairo
On July 28, 2026 , a Hamas delegation left for Cairo…
Conclusion: a vigilance that will have to stay permanent
What we know for certain about these workarounds
The Financial Times, drawing on sources close to the matter, documents several concrete methods used by Chinese companies like Ant Group and ByteDance to access Claude despite Anthropic's restrictions, while the American company intensifies its detection efforts in direct response to accusations of massive distillation targeting Alibaba.
A technological race with no quick end in sight
As long as Chinese demand for access to frontier American artificial intelligence models remains this strong, and as long as global cloud infrastructure remains this interconnected, this race between restrictions and workarounds will keep evolving, forcing Anthropic and the entire industry to maintain constant technical vigilance rather than a definitive fix.
By Maxime Marquette, columnist
Columnist's transparency note
Who I am and how I built this investigation
I am a columnist and analyst, not a cybersecurity or intellectual property law expert. This piece draws on reporting from the Financial Times, Reuters, and specialized artificial intelligence analysis. I had no access to any internal data from Anthropic, Alibaba, or Ant Group.
My limits and my acknowledged biases
I believe the West must preserve its technological edge over China, which colors my favorable reading of the protective measures taken by Anthropic. I acknowledge that I cannot independently verify the distillation accusations leveled against Alibaba, nor fully assess the validity of China's denial of those accusations.
Sources
Primary sources
Anthropic, official statements on security and access restrictions — 2026
AIToolsRecap, Anthropic Moves to Close Loopholes Letting Chinese Firms Like Ant Access Claude — July 3, 2026
Secondary sources
Financial Times, technology section on Claude access workarounds — July 2026
AI to ROI, weekly AI news analysis — July 2026
Reuters, Anthropic says Alibaba illicitly extracted Claude AI model capabilities — June 24, 2026
The Wall Street Journal, Anthropic Claims Alibaba Ran Brazen Campaign to Access Its Claude AI Model — June 25, 2026
Get the geopolitics analyses
Conflicts, powers, alliances: the MadMax thread without the noise.
Cite this article
Maxime Marquette (2026). Anthropic hunts down the Chinese firms working around Claude. MadMax. https://mad-max.co/en/article/anthropic-traque-les-entreprises-chinoises-qui-contournent-claude
Enjoyed this piece? Get the next one.
One chronicle a week, straight to your inbox. No noise.
This article was generated with AI assistance, under human supervision.
Comments
Be the first to weigh in.