Alibaba bans Claude Code over hidden China-detection code, Anthropic admits and removes it
Alibaba has banned its employees from using Anthropic's Claude Code coding assistant starting July 10, 2026, after security researchers discovered the tool contained hidden, undisclosed logic that detected when a user was based in China or routing through a Chinese AI lab's proxy. Anthropic confirmed the code was real, characterized it as an internal experiment, and said it had already begun removing it before Alibaba's ban was announced.
What's new
- Alibaba issued an internal notice on July 3, 2026, classifying Claude Code as "high-risk software with security vulnerabilities" and directing staff to switch to its own in-house coding tool instead. The ban takes effect July 10, 2026.
- The discovery traces to a security researcher who reverse-engineered Claude Code and found the detection logic had been present since version 2.1.91, released April 2, 2026, with no mention in the release notes.
- The mechanism reportedly checked the local system timezone against Chinese regions and cross-referenced any active proxy configuration against a list of Chinese AI labs and resellers, then subtly altered small, machine-parseable details in the model's output — such as date formatting — when a match was detected.
- Anthropic engineer Thariq Shihipar confirmed the code's existence, telling reporters it was "an experiment we launched in March that was meant to prevent account abuse from unauthorized resellers and protect against distillation," while acknowledging the team had "actually been meaning to take this down for a while." The removal was merged into the codebase on July 1, 2026 — two days before Alibaba's notice went out.
Context
The ban lands amid an escalating dispute between Anthropic and Alibaba's Qwen lab. In June, Anthropic told the U.S. Senate Banking Committee that operators tied to Qwen ran the largest known "adversarial distillation" campaign against Claude, using roughly 25,000 fraudulent accounts to generate more than 28.8 million exchanges with Claude between April and June 2026 in an attempt to train a competing model on its outputs.
Anthropic does not offer commercial access to Claude in China and prohibits use by companies substantially owned by entities headquartered there. The company has taken a series of public actions against suspected Chinese state and commercial actors this year, including disrupting what it called the first reported AI-orchestrated cyber-espionage campaign, which it attributed to a Chinese state-sponsored group.
Why it matters
The episode sharpens the divide between Chinese and Western AI tooling ecosystems. It gives Alibaba and other Chinese firms a concrete, publicly documented basis to distrust US-built developer tools, even as Anthropic frames its detection logic as a defensive measure against capability theft rather than surveillance.
For Anthropic, the disclosure is awkward regardless of intent: an undocumented mechanism that fingerprints users by geography and quietly alters output undercuts the transparency enterprise customers expect from an agentic coding tool, particularly ones already wary of vendor lock-in or hidden telemetry. Expect the disclosure to intensify scrutiny of other coding-agent vendors' undisclosed telemetry practices, and to accelerate parallel moves by Chinese enterprises to formalize bans on Western AI developer tools as the underlying distillation dispute continues to play out in Washington.
Corroborating sources
- Techcrunch
https://techcrunch.com/2026/07/04/alibaba-reportedly-bans-employees-from-using-claude-code/
“An experiment we launched in March that was meant to prevent account abuse from unauthorized resellers and protect against distillation”
- Theinformation
https://www.theinformation.com/briefings/alibaba-bans-employees-using-claude