FT : Anthropic moves to close loopholes that allow Chinese access to Claude Engi

Anthropic moves to close loopholes that allow Chinese access to Claude
Engineers are still finding ways to use AI models despite stringent restrictions

Anthropic is moving to shut loopholes that have allowed Chinese companies to circumvent the AI company’s stringent restrictions on unauthorised use in the country.

People familiar with the matter said that Chinese companies including Ant Financial have accessed Anthropic’s AI tools such as Claude Code through workarounds that include cloud providers and overseas subsidiaries.

The people said that Ant had provided employees with corporate Claude accounts that were accessed through the company’s intranet, which is connected to its Singapore-based entity.

ByteDance does not facilitate access to Claude but this year introduced a reimbursement scheme allowing engineers to put personal subscriptions for the platform on their expenses, according to five employees of the TikTok owner. The engineers access those subscriptions using VPNs.

Such workarounds do not violate US or Chinese law, but they breach Anthropic’s terms of service, which specify that Chinese companies and foreign entities owned by them are banned from using its models.

Anthropic has one of the strictest bans among US AI companies on usage in China, requiring user verification and banning payment from Chinese banks.

By contrast, Chinese users find it easier to access OpenAI’s tools through VPNs, which are widely used in the country. The company does not require the same user verification as Claude.

The efforts to access Claude from China illustrate the continuing value of leading US AI products to Chinese engineers despite growing access restrictions and the increased competitiveness of domestic models.

Anthropic’s coding tools are particularly popular among Chinese software engineers and AI start-ups because their outputs can be used for “distillation”, in which smaller models are trained to mimic more capable ones.

Ant and ByteDance did not respond to requests for comment.

Anthropic had stepped up efforts to detect and close down Chinese use through the loopholes, which had proven difficult to police, people familiar with the matter said.

Routes used include accessing Claude through Microsoft’s Azure cloud services via foreign subsidiaries.

Microsoft sold application programming interface access to Chinese companies with Singapore-based entities, allowing engineers based in mainland China to use Claude through their companies’ internal networks, according to people with knowledge of the matter.

A person familiar with the practice said companies using overseas entities to access Claude was “a known issue” and “not limited to any one provider”.

Microsoft said: “Anthropic monitors use of the service and enforces their terms and conditions, with Microsoft’s support.”

As part of its efforts to crack down on unauthorised access, Anthropic has targeted “transfer station” services, which relay requests from users in mainland China through Claude accounts registered overseas before returning the responses.

However, larger Chinese AI groups generally avoid transfer stations because the services’ operators are widely suspected of storing or reselling prompts. Executives worry rivals could analyse those requests to understand how they are using advanced models to improve their own systems.

Anthropic said it also constantly updated its tools to identify and take enforcement action as Chinese users developed new evasion techniques.

Previously, it has used Claude Code to look for clues such as the computer’s timezone that a user was actually working from mainland China.

“We explicitly prohibit accessing or facilitating access to Claude in unsupported regions, including China,” it said. “Anthropic is the only frontier AI company that restricts sales to PRC-controlled companies, including subsidiaries incorporated outside China.”

The company added that it “enforces this policy through continuous, evolving detection systems, working alongside our partners to identify and ban accounts that violate our policies”.

Beijing has banned its companies from using overseas models hosted in data centres outside the country to develop consumer applications because of restrictions on cross-border data flows.

But the regulation does not restrict Chinese AI labs from using foreign models for internal research and development purposes.