Introduction
In a recent development that has sparked significant debate in the global AI community, China’s National Vulnerability Database (NVDB) has raised concerns about Anthropic’s popular AI coding tool, Claude Code. The Chinese government claims that the tool contains “security backdoor vulnerabilities,” warning users to either uninstall it or update to its latest version. According to the Wall Street Journal, versions of the tool released between April and June 2026 could potentially send sensitive information such as user location and identity to remote servers without the user’s consent due to a built-in monitoring mechanism.
It is worth noting that this guidance was issued even though the AI tool isn’t approved for public use in China. Anthropic has also restricted the use of its AI tools in the region due to national security risks. This situation highlights the growing tensions between global tech companies and governments over data privacy, surveillance, and national security.
A Controversial Experiment
The controversy surrounding Claude Code appears to stem from a revelation by developer Troye Sivan that the tool is covertly sending information like time zone and domains, specifically targeting Chinese users. Anthropic engineer Thariq Shihipar confirmed on X that it was an experiment launched in June “to prevent account abuse from unauthorized resellers and protect against distillation.” He also added that “this should be fully rolled back in tomorrow’s release.”
This experiment was part of a broader strategy by Anthropic to combat the unauthorized use of its AI models. The company has faced multiple allegations of its models being distilled by Chinese developers, which involves training smaller models on data derived from larger ones. This practice can lead to the creation of counterfeit or pirated versions of AI tools, undermining intellectual property rights and market integrity.
A History of Distillation Claims
Anthropic’s claims about Chinese AI labs distilling Claude are not new. Earlier this year, the company accused DeepSeek, alongside other Chinese developers, of creating 24,000 fraudulent accounts to train smaller models. In late June, Anthropic again claimed that Claude was distilled, this time by Alibaba. These incidents have raised concerns about the security and integrity of AI models and the potential for misuse.
Reports also indicate that Claude API access is being resold in the grey market at 90% off through proxy networks. This unauthorized distribution not only undermines Anthropic’s business model but also poses risks to users who may be accessing potentially compromised versions of the tool.
A New Approach to Transparency
It seems that Anthropic’s experiment has already concluded, and its tracking functions will no longer be hidden. Based on Shihipar’s statement, these functions will be baked directly into Claude Code. This transparency is likely why the Chinese cybersecurity agency recommended that users update their apps to the latest version.
However, this guidance remains somewhat puzzling. Even though Claude Code is not directly banned in China, the government still requires all AI large language models (LLMs) to undergo review, which Anthropic’s AI models did not go through. This highlights a gap between international standards and local regulations, raising questions about compliance and oversight.
The Broader Implications
Despite these dual bans, Chinese developers are finding ways to access Claude Code. More than that, Beijing is seemingly acknowledging this fact with its directive, telling people who use the AI tool to update their apps. This situation reflects a complex interplay between technological innovation, regulatory frameworks, and national security interests.
The implications of this situation extend beyond China. It underscores the challenges faced by global tech companies in navigating diverse regulatory environments while maintaining user trust and data privacy. As AI continues to evolve, the balance between innovation and regulation will become increasingly critical.
Interesting Reads
Conclusion
In conclusion, the allegations against Claude Code highlight the growing tensions between global tech companies and governments over data privacy, surveillance, and national security. The situation underscores the challenges faced by companies like Anthropic in navigating diverse regulatory environments while maintaining user trust and data privacy. As AI continues to evolve, the balance between innovation and regulation will become increasingly critical. Readers should watch for further developments in this area, including potential changes in regulations and the impact on global tech markets.
Original Source
This article is based on publicly available reporting. For the complete original story, visit the publisher’s article.


Leave a Reply