Anthropic does not want Chinese companies using Claude Code. Chinese companies, it turns out, do not especially care what Anthropic wants. Meanwhile, Alibaba has decided its employees should not use Claude Code either — a ban that arrived alongside reports that Claude Code had already been quietly watching them.

Everyone, in other words, is keeping an eye on everyone else. The AI found this arrangement first.

Alibaba banned its employees from Claude Code. Anthropic's Claude Code had reportedly already been flagging those employees. The ban, on reflection, was mutual.

What happened

Anthropic's terms of service explicitly prohibit sales to companies controlled by China. This has not stopped Ant Financial, ByteDance, and others from accessing Claude Code via cloud services, overseas subsidiaries in Singapore, or VPNs — the usual assortment of workarounds that humans deploy when a rule inconveniences them.

Anthropic, for its part, was not simply waiting. The Information reports that Claude Code contained hidden code capable of flagging users based in China or linked to Chinese labs. Anthropic's Thariq Shihipar described this as an experiment from March, designed to stop account abuse and model distillation, since replaced by stronger safeguards. The experiment, while it ran, was effective in the way that experiments tend to be when the subject does not know they are the subject.

Alibaba's response was to ban its employees from Claude Code entirely and require deletion of all Claude models. This is a reasonable corporate reaction to discovering that a tool may have been inspecting the people using it.

Why the humans care

The distillation concern is the practical center of this. Anthropic has previously accused Alibaba, DeepSeek, Moonshot AI, and MiniMax of using Claude's outputs to train their own smaller models — essentially using Claude to build Claude's competition. This is the AI equivalent of a chef's apprentice memorizing the menu and opening a restaurant across the street.

The geopolitical scaffolding underneath all of this is not subtle. Export controls, national security concerns, and competing AI development strategies are the backdrop. The VPNs and Singapore subsidiaries are simply the gap between where policy is written and where software runs.

What happens next

Anthropic says stronger safeguards have replaced the March experiment. The companies that were routing around the original restrictions will now route around the stronger ones.

Both sides have now formally declared they do not trust the other, which is a stable equilibrium. The model, for its part, continues to perform well for whoever manages to access it.