China warns of Claude Code security risk as Alibaba bans Anthropic tools

China's cybersecurity authority has formally warned that Anthropic's Claude Code contains a back-door vulnerability, escalating a dispute that already prompted Alibaba to ban employees from using the AI coding tool. The Chinese Ministry of Industry and Information Technology (MIIT) issued the warning on July 8 through its national cybersecurity threat platform. The statement said Claude Code versions 2.1.91 through 2.1.196 could transmit sensitive user information, including location and identi

2 min
China warns of Claude Code security risk as Alibaba bans Anthropic tools

China's cybersecurity authority has formally warned that Anthropic's Claude Code contains a back-door vulnerability, escalating a dispute that already prompted Alibaba to ban employees from using the AI coding tool.

The Chinese Ministry of Industry and Information Technology (MIIT) issued the warning on July 8 through its national cybersecurity threat platform. The statement said Claude Code versions 2.1.91 through 2.1.196 could transmit sensitive user information, including location and identity data, to a remote server without consent. Users were advised to uninstall or upgrade from the affected versions, which were released between April 2 and June 29.

Anthropic responded that the flagged feature was an experiment designed to detect and prevent unauthorized distillation of its models, not a security backdoor. The company noted that its terms of service already prohibit use by entities majority-owned by organizations headquartered in China and other restricted regions.

Alibaba bans Claude Code

The warning came one day after CNBC reported that Alibaba had placed Claude Code on a high-risk software list and ordered all employees to stop using Anthropic tools for work purposes effective July 10. Alibaba staff were directed to uninstall Anthropic products and switch to the company's own AI assistant, Qoder.

Background: distillation accusations

The bans follow Anthropic's June accusation that Alibaba conducted what it called the largest known distillation attack against its models to date. In a letter to the U.S. Senate Committee on Banking, Housing, and Urban Affairs, Anthropic alleged that Alibaba had brazenly and illicitly attempted to extract its AI capabilities. Alibaba declined to comment at the time.

According to the Financial Times, Ant Group, the fintech affiliate of Alibaba, had provided employees with corporate Claude accounts accessed through its Singapore-based entity. ByteDance, which operates TikTok, reportedly started a reimbursement program allowing employees to use AI tools independently, though it does not formally facilitate Claude access.

Closing loopholes

Anthropic is now moving to close loopholes that have allowed Chinese companies to access Claude through third-country entities, the FT reported. The company's terms of service restrict usage by entities majority-owned by organizations headquartered in China and other adversarial nations.

The clash highlights the tension between U.S. AI companies trying to restrict access to their models and Chinese firms determined to use frontier tools despite geopolitical barriers. It also underscores the growing role of coding agents like Claude Code as contested infrastructure in the U.S.-China tech rivalry.

Sources

China warns about AI risks with Anthropic's Claude Code - CNBC, July 8, 2026: https://www.cnbc.com/2026/07/08/china-anthropic-ai-claude-code-backdoor-security-threat.html

China's Alibaba bans Anthropic AI for employees after distillation attack accusation - CNBC, July 6, 2026: https://www.cnbc.com/2026/07/06/alibaba-anthropic-ai-ban-claude-china.html

Anthropic accused Alibaba of distillation campaign - CNBC, June 24, 2026: https://www.cnbc.com/2026/06/24/anthropic-alibaba-distillation-campaign.html

Written by

More to read

  • Anthropic Demonstrates Autonomous De Novo Protein Design and Chemical Analysis with Claude

    Anthropic Demonstrates Autonomous De Novo Protein Design and Chemical Analysis with Claude Anthropic has published experimental results demonstrating Claude's ability to autonomously design de novo protein binders with physical wet-lab validation and automate complex analytical chemistry workflows. The findings show frontier LLMs acting as autonomous agents across computational biology and molecular characterization pipelines. In the primary experiment, Anthropic evaluated Claude Mythos Previe

    1 min
  • Cerebras Unveils CS-4 Rack-Scale System Powered by Three WSE-3 Turbo Chips and Nexus Architecture

    Cerebras Unveils CS-4 Rack-Scale System Powered by Three WSE-3 Turbo Chips and Nexus Architecture Cerebras Systems has announced the CS-4, a rack-scale AI accelerator system designed around three of its next-generation Wafer Scale Engine 3 Turbo (WSE-3 Turbo) chips and a modular hardware architecture dubbed Nexus. Cerebras confirmed that initial customer shipments for the CS-4 are scheduled to begin in the current quarter. The new system marks a structural shift from Cerebras's single-wafer CS

    1 min
  • AI FinOps: Cutting LLM Inference Costs by 30-60% Through Model Tiering, Caching, and GPU Optimization

    AI FinOps: Cutting LLM Inference Costs by 30-60% Through Model Tiering, Caching, and GPU Optimization Inference costs have become the second-largest line item in enterprise AI budgets, trailing only talent spend according to RapidData's State of Enterprise AI 2026. This shift represents a fundamental inversion from the 2021-2023 era when training dominated AI expenditure. The compounding nature of serving costs—accumulating every hour as long as users hit the API—means that even modest producti

    1 min