Alibaba Bans Employees From Using Anthropic's Claude Code

Alibaba banned employees from using Anthropic's Claude Code from July 10 after code that detects China-based users surfaced; Anthropic calls it anti-distillation protection, and staff are told to use Qoder.

Alibaba Bans Employees From Using Anthropic's Claude Code
Alibaba banned staff from using Anthropic's Claude Code. Photo: South China Morning Post

Key Points

  • Alibaba banned employees from using Anthropic's Claude Code, effective July 10.
  • The trigger: code in Claude Code that can detect if a user is based in China.
  • Anthropic says it was an anti-abuse experiment to prevent model distillation.
  • Alibaba told staff to switch to Qoder, its in-house AI coding tool.

Alibaba has told its employees to stop using Claude Code. Starting July 10, the Chinese tech giant is classifying Anthropic's coding agent as high-risk software with security vulnerabilities, and pointing staff to Qoder, its own in-house AI coding tool, instead.

The ban follows a discovery by a developer who reverse-engineered Claude Code on June 30 and surfaced obfuscated code — present since version 2.1.91, shipped April 2 with no mention in the release notes — that could detect whether a user was based in China or affiliated with a Chinese AI lab. To Alibaba and much of the Chinese developer community, that read as covert tracking; the South China Morning Post framed it as "spyware."

Anthropic tells it differently. Engineer Thariq Shihipar said the geolocation check was "an experiment we launched in March that was meant to prevent account abuse from unauthorized resellers and protect against distillation" — training a rival model on Claude's outputs. Anthropic already bars Chinese companies from using its models, and has been closing the loopholes that route around that restriction.

That context is the whole story, because the two companies are already at war over exactly this. In June, Anthropic accused operators tied to Alibaba's Qwen lab of running the largest known distillation attack on Claude — roughly 25,000 fraudulent accounts generating 28.8 million exchanges — an allegation Alibaba denied. So the anti-distillation code Anthropic says it built is aimed at the behavior it has publicly pinned on Alibaba, and Alibaba has now recast that same code as a reason to rip the tool out of its offices.

The read: the US–China AI split is no longer just about chips and model access — it is reaching the developer tooling itself. Anthropic has spent 2026 turning "trusted partners" into its unit of distribution, from the Mythos export saga to the loopholes that Asian labs have raced to fill. Alibaba banning Claude Code is the other side of that decoupling: when neither company trusts the other's software, the coding agent becomes contested territory, and each side retreats to its own stack.

Source: TechCrunch, South China Morning Post.

Comments

Get tomorrow's roundup. Free.

One email each morning. Sneakers, sports, culture, tech.

Link copied