Login Start Free Trial

Alibaba Bars Its Staff From Anthropic's Claude Code, Deepening a US-China AI Standoff

The Chinese giant flagged the coding tool as high-risk over an alleged user-detection feature. Anthropic says the mechanism was built to fight abuse, and separately accuses Alibaba of siphoning its models.

Alibaba has told employees to stop using Anthropic's Claude Code at work, according to a person familiar with the order, a move that hardens a widening dispute between the two companies and puts a fresh crack in the software ties between American and Chinese AI.

The ban takes effect on July 10, the person said, and steers Alibaba staff toward the company's own coding assistant, Qoder. An internal review at Alibaba flagged Claude Code as high-risk software over concerns that it contained hidden mechanisms capable of identifying China-linked users. The order was first reported by Chinese media, including the financial publisher Yicai, before Reuters carried the account. Alibaba has not publicly confirmed the decision, and neither company responded to requests for comment.

Claude Code is Anthropic's AI assistant for programmers, and it had found an enthusiastic audience among Chinese developers even though Anthropic restricts access for users and companies in China. That popularity is part of what makes the break notable. Chinese coders liked the tool enough to route around the limits placed on it.

A Hidden Feature, and Two Ways to Read It

The ban followed a discovery posted online. On June 30, a Reddit user going by LegitMichel777 said they had reverse-engineered Claude Code and found code that quietly inspected a user's setup.

According to that account, which several outlets examined, a version of Claude Code released on April 2 checked whether a computer's timezone was set to Shanghai or Urumqi, or whether it was routing through a proxy tied to a hidden list of Chinese technology firms and AI labs, some 147 entries in all. Rather than raising a visible flag, the mechanism was said to slip subtle markers into the prompts that Claude Code sent back to Anthropic's servers.

To Alibaba and to the developers who surfaced it, that looked like covert user detection aimed at China.

Anthropic's account is different. A member of the Claude Code team, posting on X on Tuesday, described the feature as an experiment launched in March to stop unauthorized resellers from abusing accounts and to guard against model distillation, the copying of a model's abilities by training on its outputs. He said it was never meant to surveil users and that it would be removed in the next update. By several accounts the mechanism was already being rolled back around July 1, after roughly three months in operation.

The two descriptions are not mutually exclusive. A safeguard meant to catch abuse in China and a tool that detects Chinese users can be the same code seen from opposite sides of a widening trust gap.

The Distillation Accusation Behind It

The detection feature did not appear in a vacuum. It grew out of an accusation Anthropic had made weeks earlier.

In a June 10 letter to two US senators, Anthropic said it had been hit by what it called the largest attack of its kind against the company. It accused operators linked to Alibaba's Qwen AI lab of running close to 25,000 fraudulent accounts to pull its models' programming and reasoning abilities out through more than 28 million conversations between late April and early June. Anthropic framed the effort as distillation and warned that it could speed China's path toward matching the company's most advanced systems, which it referred to as its Mythos Preview capabilities.

Distillation is not exotic. It is a known technique in which a cheaper, weaker model is trained on the responses of a stronger one, absorbing some of its capability at a fraction of the cost. What Anthropic alleges is that this was done to its models at scale and without permission.

Alibaba has not answered the accusation publicly. Its silence, paired with a ban that recasts Claude Code as the security threat, has effectively flipped the charge around. One company says its model was strip-mined. The other has labeled the miner's tool the hazard.

Why a Ban, and Why It Lands Now

Anthropic's China restrictions have always been porous, and the person describing Alibaba's order to Reuters explained why. An individual developer can spin up a server in the United States and make traffic look American, which makes access rules hard to enforce one user at a time. Companies are a different matter. They carry legal and compliance exposure that a lone coder does not, which gives a corporate ban teeth that individual limits lack.

The move also fits a direction Chinese industry was already taking. As US developers tighten the rules against unauthorized resale and distillation of their systems, Chinese cloud and AI firms have leaned harder on homegrown and open-source options, among them DeepSeek and Alibaba's own Qwen, alongside models from Moonshot and Zhipu. Pushing staff onto Qoder rather than Claude Code is a small, concrete instance of that shift.

A Difficult Stretch for Anthropic in Asia

Alibaba's decision caps a hard few weeks for Anthropic in the region. In June, the Financial Times reported that JPMorgan had stopped its Hong Kong staff from choosing Claude models off an approved list, and that Goldman Sachs had earlier done something similar, both tied to Anthropic licensing terms that carved out Greater China. Anthropic told the paper that Claude had never been officially supported in Hong Kong.

The company has had a turbulent run at home too. On July 1 it restored public access to two of its newest models, Fable 5 and Mythos 5, after US authorities lifted export controls that had forced a suspension in June. Anthropic said it brought the models back following discussions with US officials and added new safeguards aimed at blocking certain cybersecurity tasks.

Set against that backdrop, the Alibaba ban is one more line drawn on a map that keeps fragmenting. Where a developer sits now helps decide which AI they are allowed to use.

The Bigger Contest

Underneath a single corporate policy sits the rivalry that has come to define the industry. Washington and Beijing are each pressing to lead in AI, and the instruments of that competition now include access controls, security reviews, blocked software and public accusations of theft.

The traffic does not run one way. Even as Anthropic curbs Chinese access to Claude, Chinese models have been picking up users inside the United States, a trend that has unsettled some American industry figures who worry about a reverse dependency. The security-and-trust arguments Alibaba is using against Claude Code echo the ones US officials aim at Chinese apps and models.

For developers on both sides, the practical result is a narrowing of choices. Claude Code will keep running on the machines of programmers who want it and can reach it. Inside Alibaba, starting July 10, it will not.

Browse

Related Article