Skip to content
The ColumnInvestigation· No. 3029

Anthropic hunts down the Chinese firms working around Claude

The Financial Times reports that Anthropic is actively closing a series of loopholes that allowed Chinese firms like Ant Group, Alibaba's financial

Premium reading
MadMax
Key takeaways
  1. The Financial Times reports that Anthropic is actively closing a series of loopholes that allowed Chinese firms like Ant Group, Alibaba's financial
  2. Introduction: an endless race against workarounds
  3. Loopholes exploited through hidden relays
Transparency

Facts, quotes, and cited links remain in the body. Interpretations are framed as analysis or opinion according to the format.

Introduction: an endless race against workarounds

Loopholes exploited through hidden relays

The Financial Times reports that Anthropic is actively closing a series of loopholes that allowed Chinese firms like Ant Group, Alibaba's financial affiliate, to access its Claude model despite explicit restrictions. The main mechanism relies on services called transfer stations: relays that accept requests from Chinese users, forward them to Claude's API, then return the answers while masking the true origin of the request in the system logs.

According to people close to the matter cited by the Financial Times, Ant Financial reportedly gave its employees corporate Claude accounts accessible through its intranet, itself linked to its Singapore-based entity. This kind of workaround, technical but effective, illustrates the persistent difficulty of enforcing geographic restrictions in a world of interconnected cloud infrastructure.

A move directly tied to the distillation accusations

This crackdown on workarounds comes directly on the heels of accusations Anthropic leveled at Alibaba, which it calls the largest distillation attack ever known against Claude. According to a letter sent to the U.S. Senate, operators linked to Alibaba's Qwen lab allegedly created nearly 25,000 fraudulent accounts generating more than 28.8 million exchanges with Claude between April 22 and June 5, 2026.

Distillation involves massively querying a more powerful model to train a cheaper model to replicate its capabilities, a practice Anthropic considers illegitimate when it deliberately aims to get around its policy of denying commercial access to China. The company says this campaign specifically targeted Claude's most advanced capabilities: complex software engineering and long-horizon autonomous reasoning.

A company that pours billions into building a frontier model has every right to protect what it built. The real scandal here isn't Anthropic's vigilance — it's the ingenuity deployed to dodge restrictions that had been clearly announced for months.

Three categories of workaround identified

Cloud providers and foreign subsidiaries

Beyond transfer stations, the Financial Times identifies a second category of workaround: Chinese companies routing their API requests through American or European subsidiaries, or through cloud platforms that are technically compliant as Anthropic customers, which then sub-route those requests to end users in China. Microsoft reportedly sold API access through its Azure cloud infrastructure to Chinese entities operating out of Singapore.

A third category involves foreign subsidiaries of Chinese companies formally incorporated in jurisdictions where Claude access is permitted, but whose actual end users are located in mainland China. This kind of complex legal structuring makes detection particularly difficult for Anthropic's compliance teams.

ByteDance and the quiet subscription reimbursements

Chinese giant ByteDance, the owner of TikTok, reportedly set up an expense-reimbursement policy letting its engineers get refunded for individual Claude subscriptions, with those employees then accessing the model through virtual private networks. This method, while breaking neither Chinese nor American law, is a direct violation of Anthropic's terms of service.

These practices reveal an unavoidable truth: even without explicitly breaking a national law, getting around the terms of service of a private American company to access cutting-edge artificial intelligence technology raises an underlying problem that contract enforcement alone struggles to solve.

The fact that these workarounds break no law, only a company's terms of service, shows just how far the international regulatory framework still lags behind the pace of U.S.-China technological competition.

The regulatory backdrop pushing Anthropic to act

Commitments made to the U.S. government

This loophole-closing effort is part of formal commitments Anthropic made to the U.S. government during negotiations over the ban on its Fable and Mythos models, imposed on June 12, 2026 by the U.S. Department of Commerce. Those restrictions stemmed from fears the models could be used by Chinese military intelligence entities or other countries of concern.

Anthropic had already, as early as September 2025, updated its terms of service to bar access to any company majority-owned, directly or indirectly, by interests based in China, Russia, North Korea, or Iran, regardless of the entity's physical location. That decision already meant giving up revenue estimated in the hundreds of millions of dollars.

A stricter policy than its competitors

According to the reporting, Anthropic maintains verification protocols notably stricter than its direct competitors, including OpenAI, whose systems remain easily accessible through standard VPN setups. To counter the latest evasion techniques, Anthropic reportedly now uses structural indicators within Claude Code, such as computers' localized time zones, to identify users' true geographic location.

This heightened rigor sets Anthropic apart in an industry where the temptation to look the other way on substantial revenue, even revenue generated through workarounds, could easily outweigh longer-term national security considerations.

It's rare for a private company to deliberately sacrifice hundreds of millions of dollars in revenue for national security reasons. That rigor deserves recognition, even if it doesn't fully solve the structural problem of technological workarounds.

China's response: ingenuity and denial

Engineers finding new workarounds just as fast

Despite Anthropic's efforts, engineers at Chinese companies reportedly keep finding new workarounds almost as quickly as the company closes old loopholes, according to sources cited by the Financial Times. This perpetual race between restrictions and workarounds illustrates the structural limits of a purely technical approach against such strong market demand.

On Chinese social media, some commentators have even suggested, with a touch of irony, that one could simply buy a Claude account directly on e-commerce platforms like Taobao, showing just how normalized these workarounds have become in certain Chinese tech circles.

Alibaba firmly denies the distillation accusations

For its part, Alibaba has firmly denied the distillation accusations leveled by Anthropic, stating it does not use the outputs of proprietary artificial intelligence models to train its own systems and insisting its AI development complies with applicable intellectual property laws. At this stage, Anthropic's allegations remain independently unverified.

A Chinese expert cited by state media, meanwhile, described these accusations as a reflection of technological hegemonic anxiety aimed at slowing China's AI progress, adding that Anthropic was allegedly using litigation to protect its monopoly rather than fostering open, collaborative innovation.

Alibaba's flat denial deserves to be reported with the same rigor as Anthropic's accusations, even though the volume and sophistication of the documented workarounds make it hard to believe this is simply a coincidence of legitimate traffic.

What this tech battle reveals about U.S.-China rivalry

A precedent that goes beyond the Claude case alone

This case isn't isolated: back in February 2026, Anthropic had already accused Chinese labs DeepSeek, Moonshot AI, and MiniMax of running similar campaigns, generating more than 19 million fraudulent exchanges with Claude between them. This repetition of workaround attempts, by different actors but with similar methods, points to a structural pattern rather than a series of isolated incidents.

This accumulation of precedents strengthens Anthropic's argument that access to frontier artificial intelligence models should be treated with the same rigor as technologies subject to export controls, a position that could shape future regulation across the entire sector if it gains traction in Washington.

The West facing the urgency of preserving its technological edge

This battle to close technical loopholes illustrates a much larger stake: the West's ability to preserve its lead in the artificial intelligence race against a China determined to close the gap, through legitimate research but also, it seems, through more questionable workarounds of the commercial restrictions imposed by American companies.

Every loophole Anthropic closes is a tactical win, but the real battle will be decided by the entire American AI industry's ability to maintain collective, coordinated vigilance, rather than leaving each company to manage its own security gaps in isolation against unrelenting Chinese competitive pressure.

The technological competition between China and the West won't be decided only in research labs, but also, perhaps more decisively, in the ability to actually protect capabilities already developed against unauthorized extraction.

The role of global cloud supply chains

An interconnection that complicates any geographic restriction

The complexity of global cloud supply chains makes Anthropic's task especially difficult: a company can technically comply with the terms of service in the country where it's officially registered while quietly sub-routing its requests to users located in restricted jurisdictions like China. This technical architecture makes detection far more complex than simple IP address blocking.

Even major cloud providers like Microsoft sometimes find themselves, perhaps unintentionally, in a gray zone where their official customers comply with the surface-level contractual terms while enabling, downstream, access for end users who normally shouldn't be entitled to it under Anthropic's policy.

The shared responsibility of technology intermediaries

This situation raises a question of shared responsibility: to what extent should infrastructure providers like Microsoft Azure be required to actively verify the ultimate identity of their customers' users, rather than settling for first-tier contractual compliance with their direct partners?

Without closer coordination between Anthropic and the entire ecosystem of cloud infrastructure providers involved, every loophole closed risks simply pushing the problem to another link in the technology chain, without ever resolving the structural problem at its root.

As long as verification responsibility stays fragmented between model developers and cloud infrastructure providers, workarounds will keep thriving in the gaps of this shared but poorly coordinated chain of responsibility.

Implications for other American AI labs

OpenAI and Google facing the same structural challenge

While Anthropic stands out for the rigor of its verification protocols, nothing suggests its direct competitors, OpenAI and Google, aren't facing exactly the same kind of Chinese workarounds, simply with less public transparency about the scale of the problem. The absence of public disclosure doesn't necessarily mean the absence of the threat itself.

This information asymmetry among American artificial intelligence labs complicates regulators' ability to assess the true scale of the problem across the whole industry, rather than case by case based solely on which company chooses to speak publicly about its own security incidents.

Toward coordinated information-sharing among rival labs

Anthropic, OpenAI, and Google have reportedly already begun collaborating to share information on distillation attempts that violate their respective terms of service, an unprecedented move toward cooperation among direct competitors against a common external threat. This cooperation, while still in its early stages, could evolve into a more formal industry standard for shared detection.

This kind of inter-lab cooperation, if it solidifies, could become a model for the entire American tech sector confronting similar attempts at unauthorized extraction of proprietary capabilities by determined foreign actors.

Seeing fierce rivals like Anthropic, OpenAI, and Google collaborate on detecting Chinese workarounds shows just how seriously the threat is being taken — serious enough to justify a temporary truce in an otherwise ruthless commercial rivalry.

What Washington could do to reinforce this effort

Toward a more binding regulatory framework

Several U.S. lawmakers, including members of the Senate Banking Committee who received Anthropic's letter, are now considering additional sanctions against Chinese companies identified as having illegally extracted American artificial intelligence capabilities. A more binding regulatory framework could impose stronger verification obligations directly on cloud infrastructure providers.

Such a framework would turn access to frontier artificial intelligence models into a regime comparable to export controls on advanced semiconductors, with traceability and identity verification obligations far stricter than the simple contractual compliance currently in place.

The urgency of acting before the lead erodes

Every month of delay in establishing a more robust regulatory framework is another opportunity for determined Chinese actors to extract, through distillation or direct workarounds, capabilities that American labs spent years and billions of dollars developing. The urgency isn't just commercial — it directly touches American and Western national security.

The West cannot afford to treat this as a simple commercial dispute between private companies: it touches on the very capacity to maintain a technological lead against a strategic rival investing massively to close that gap, by whatever means available.

Treating the unauthorized extraction of artificial intelligence capabilities as a mere terms-of-service problem, rather than as a full-fledged national security issue, seriously underestimates what's really at stake in this technological competition.
This technical battle, however obscure it may look to the public, will help determine who dominates the next decade of artificial intelligence. The West cannot afford to lose it through simple regulatory or technical negligence.

Conclusion: a vigilance that will have to stay permanent

What we know for certain about these workarounds

The Financial Times, drawing on sources close to the matter, documents several concrete methods used by Chinese companies like Ant Group and ByteDance to access Claude despite Anthropic's restrictions, while the American company intensifies its detection efforts in direct response to accusations of massive distillation targeting Alibaba.

A technological race with no quick end in sight

As long as Chinese demand for access to frontier American artificial intelligence models remains this strong, and as long as global cloud infrastructure remains this interconnected, this race between restrictions and workarounds will keep evolving, forcing Anthropic and the entire industry to maintain constant technical vigilance rather than a definitive fix.

By Maxime Marquette, columnist

Columnist's transparency note

Who I am and how I built this investigation

I am a columnist and analyst, not a cybersecurity or intellectual property law expert. This piece draws on reporting from the Financial Times, Reuters, and specialized artificial intelligence analysis. I had no access to any internal data from Anthropic, Alibaba, or Ant Group.

My limits and my acknowledged biases

I believe the West must preserve its technological edge over China, which colors my favorable reading of the protective measures taken by Anthropic. I acknowledge that I cannot independently verify the distillation accusations leveled against Alibaba, nor fully assess the validity of China's denial of those accusations.

Sources

Primary sources

Anthropic, official statements on security and access restrictions — 2026

AIToolsRecap, Anthropic Moves to Close Loopholes Letting Chinese Firms Like Ant Access Claude — July 3, 2026

Secondary sources

Financial Times, technology section on Claude access workarounds — July 2026

AI to ROI, weekly AI news analysis — July 2026

Reuters, Anthropic says Alibaba illicitly extracted Claude AI model capabilities — June 24, 2026

The Wall Street Journal, Anthropic Claims Alibaba Ran Brazen Campaign to Access Its Claude AI Model — June 25, 2026

Get the geopolitics analyses

Conflicts, powers, alliances: the MadMax thread without the noise.

Cite this article

Maxime Marquette (2026). Anthropic hunts down the Chinese firms working around Claude. MadMax. https://mad-max.co/en/article/anthropic-traque-les-entreprises-chinoises-qui-contournent-claude

How does this piece make you feel?
MM
Maxime Marquette
Independent columnist

Maxime Marquette writes most of the analyses and columns published on MadMax — geopolitics, technology, and current events, no filler.

The Newsletter

Enjoyed this piece? Get the next one.

One chronicle a week, straight to your inbox. No noise.

Comments

0 / 2000

Be the first to weigh in.

This article was generated with AI assistance, under human supervision.

Investigation2347 words12 min read