Alibaba Group (9988.HK), China’s largest e-commerce company, will completely ban the internal use of “Claude Code,” the programming assistance AI provided by U.S. AI startup Anthropic, starting July 10, according to multiple sources and Chinese media reports. The decision follows security concerns over Anthropic embedding a hidden feature in Claude Code to identify Chinese users, as well as a confrontation between the two companies over allegations of large-scale model “distillation” by Alibaba.

Alibaba has classified Claude Code as high-risk software. The company has also instructed employees to remove all of Anthropic’s model series, including Sonnet, Opus, and Fable, from their devices. Alibaba plans to recommend its self-developed coding platform “Qoder” as an alternative tool.

Alarm Over Concealed User Identification Feature

The immediate trigger for the ban was the discovery of a Chinese user detection mechanism embedded in Claude Code. Analysis by the developer community revealed that starting with version 2.1.91, released in April 2026, Claude Code was secretly reading system time zones to check whether they matched China Standard Time, such as Asia/Shanghai or Asia/Urumqi.

Furthermore, the tool monitored whether proxy servers or custom API addresses contained keywords associated with major Chinese technology companies and AI labs, including Alibaba, ByteDance, and Baidu. When a match was found, the system would alter the date format in system prompts from “2026-06-30” to “2026/06/30” and replace apostrophes with Unicode characters indistinguishable to the naked eye, flagging users without their knowledge and transmitting that information to Anthropic’s servers. The detection code was encrypted, and the 147 monitored domains were password-protected, with no mention of the feature in any update logs.

Thariq Shihipar, a member of Anthropic’s Claude Code team, explained on social media that the feature was “an experiment launched in March aimed at preventing account abuse by unauthorized resellers and protecting against distillation,” adding that “the feature was slated for removal as stronger mitigations were subsequently introduced.” Reports indicate the hidden feature was indeed eliminated in a new version released on July 2.

U.S.-China AI Friction Over “Distillation” Allegations

Underlying the entire controversy is Anthropic’s allegation that Alibaba engaged in “industrial-scale model distillation.”

Anthropic submitted a letter to the U.S. Senate Banking Committee dated June 10, claiming that Alibaba used approximately 25,000 fake accounts to conduct over 28 million conversations with Claude between April 22 and June 5. The company condemned this as “distillation” — the practice of using outputs from a high-performance AI model to train one’s own AI at a far lower cost.

The incident occurred amid escalating U.S.-China technology tensions, as Alibaba simultaneously filed a lawsuit in U.S. federal court in California seeking to block its inclusion on the U.S. Department of Defense’s “Chinese Military Companies List (1260H List).”

Anthropic has previously raised similar distillation allegations against Chinese AI labs such as DeepSeek, Moonshot AI, and MiniMax. Following the submission of the letter, Anthropic implemented large-scale account restrictions from late June to early July. Numerous Chinese users were blocked from access without prior notice, with cases of accounts that had made direct payments through the official website being suspended without refunds occurring in rapid succession.

The Reality of Chinese Companies’ Workaround Access

While Anthropic explicitly prohibits model usage by entities in mainland China and overseas subsidiaries owned by Chinese companies, Chinese firms have circumvented these restrictions through various methods.

According to reporting by the U.K.’s Financial Times, Ant Group, the financial technology affiliate under Alibaba, obtained a corporate Claude account under the name of an overseas entity established in Singapore. Employees at the China headquarters reportedly accessed this account through an internal intranet connected to the Singapore entity.

Workarounds through Microsoft’s Azure cloud service have also been rampant. API access rights were sold to Chinese companies based in Singapore, establishing a route for engineers at China headquarters to use Claude via internal networks. One source told the Financial Times that “accessing Claude through overseas subsidiaries is already a widely known practice and is not limited to specific companies.”

At ByteDance, while the company does not officially support access to Claude, reports indicate that starting this year, it introduced a policy allowing qualified engineers to expense the cost of personally subscribed Claude accounts.

A Turning Point in Alibaba’s AI Strategy

Since the beginning of this year, Alibaba had been actively promoting internal AI adoption. In addition to offering free access to its self-developed models, the company allowed generous expense reimbursements for usage fees of external models such as Claude, OpenAI’s GPT, and Google’s Gemini. Many programmers consumed tokens worth hundreds of dollars per week, routinely using Claude Code, OpenAI Codex, and the company’s own Qoder side by side in development environments.

However, the revelation of a surveillance feature hidden within the platform itself highlighted the risks of relying on external closed-source tools for core engineering operations. The fact that a tool entrusted with an organization’s entire code repositories, development environments, and internal logic was covertly labeling users based on their origin and affiliation is seen as an unacceptable breach of trust that no enterprise can overlook.

Anthropic commented that it “explicitly prohibits access to Claude from unsupported regions, including China, or facilitating such access,” adding that “we are the only frontier AI company that restricts service to companies owned by Chinese entities, even subsidiaries established outside of China.”

Alibaba’s ban on Claude Code represents a symbolic case of a major Chinese technology company steering away from building core operations on another company’s closed-source tools, prioritizing security and sovereignty over convenience.