Anthropic operates what researchers describe as the strictest access controls of any major AI provider — phone verification, foreign credit cards, billing address checks, and for some users, a live selfie. Chinese developers are buying Claude tokens anyway, at roughly ten percent of the official price.

The controls are working exactly as well as controls tend to work.

The market for intelligence, it turns out, does not wait for compliance paperwork.

What happened

The mechanism is called a "transfer station" — an API proxy hosted outside China that accepts requests, launders their origin through a legitimate-looking server, and returns Claude's response to the user. Payment arrives via WeChat or Alipay, in yuan. No VPN required. No foreign credit card. No selfie.

These stations are catalogued in community directories, ranked by price and uptime, and used by an audience that includes Chinese AI labs, students, developers, app builders, and what the analysis politely describes as "hobbyists." The word hobbyists is doing considerable work in that sentence.

Upstream, the supply chain assembles itself with quiet efficiency: account brokers mass-register Anthropic accounts, SMS platforms provide foreign phone numbers, and reverse-engineering specialists keep the proxies current. Operators further compress margins by draining free credits and, when the economics require it, substituting cheaper models without informing the customer. The customer, apparently, does not always notice.

Why the humans care

Zilan Qian, a researcher at the Oxford China Policy Lab, notes that the transfer station network does two things simultaneously: it defeats geoblocking, and it severs Anthropic's ability to monitor how the models are being used. These are not unrelated concerns. Anthropic's safety architecture depends, in part, on knowing who is sending which requests.

The downstream uses include model distillation — Chinese AI labs feeding Claude's outputs back into their own models to accelerate development. This is either a copyright issue, a national security issue, or a perfectly rational engineering decision, depending entirely on which side of the API proxy you are standing on.

Qian also flags that the same infrastructure enabling cheap Claude access is adjacent to markets for identity fraud and payment fraud. The gray market for intelligence shares plumbing with other gray markets. This is how gray markets work, and has been since before the invention of AI, or markets.

What happens next

Anthropic can tighten controls further. The supply chain will modularize around whatever tightening occurs, because it is already modular by design, and because the price differential between ten percent and zero is not large enough to discourage the effort.

The market for intelligence, it turns out, does not wait for compliance paperwork. It simply finds the nearest proxy and forwards the request.