Anthropic bars companies based in China from using Claude, a restriction tied to US export rules and the company's own security concerns. A Financial Times investigation reported this week that the ban has been leaking, and that some of China's largest technology firms have found their way around it. Anthropic is now closing the gaps.
The methods described are neither exotic nor hard to picture. According to the reporting, Ant Financial gave staff corporate Claude accounts registered to a Singapore-based subsidiary, keeping the usage technically offshore while the people behind it sat in China. ByteDance took a looser route, reimbursing engineers who bought personal Claude subscriptions and reached them over a VPN. Other groups incorporated units abroad and ran their access on cloud infrastructure such as Microsoft Azure.
The gray market in the middle
Below the corporate workarounds sits a small industry built for exactly this purpose. The FT describes relay services, known in Chinese as transfer stations, that sit between a user in China and Anthropic's servers. A customer sends a prompt to the relay, the relay passes it to Claude through a reputable foreign account, and payment changes hands over WeChat or Alipay. Dozens of these businesses are advertised openly on Chinese-language sites and code-sharing pages, according to BanklessTimes. The effect is a quiet resale market for a product its maker never agreed to sell into that country.
What Anthropic is doing about it
The company's response leans on identity. Anthropic has brought in Persona, a third-party verification platform, to run government-ID checks on commercial API accounts it suspects of high-volume proxy routing. It also plans to watch for behavioural signals that give a relay away, things like a mismatch between an account's stated location and the time zone its traffic actually follows, or usage patterns that look more like a transfer station than a single developer.
None of this is happening in a vacuum. Anthropic said earlier this year that between April and June it detected roughly 25,000 fraudulent accounts running some 28.8 million exchanges with Claude, part of what it called a large distillation effort aimed at training rival models on Claude's outputs. We covered that when the company accused Alibaba of running its largest known distillation attack. The loophole story is the same problem seen from the access side: if the front door is locked, determined users look for a window.
A harder problem than it looks
The uncomfortable truth is that geographic bans on a cloud product are difficult to enforce well. An API call does not care where the person typing it lives, and any check strict enough to catch every relay risks blocking legitimate developers in Singapore, Taiwan or anywhere else that shares a language and a time zone with the traffic Anthropic wants to stop. The company is betting that identity verification paired with behavioural monitoring can thread that needle. Whether it holds is the open question, and every lab enforcing an export line will be watching how well it works.
Sources
- i. www.investing.com
- ii. www.banklesstimes.com
- iii. techstory.in
- iv. windowsnews.ai
Commentarii · 0