Original briefings. Zero spin.
Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.
Alibaba Bans Claude Code as Anthropic's Hidden China Tracker Turns a Corporate Dispute Into a Full Diplomatic Incident
Since Anthropic's covert tracking code in Claude Code was exposed by web developer 'Thereallo' and confirmed by Anthropic engineer Thariq Shihipar on X, the story has moved from a privacy controversy into a concrete corporate rupture.
Alibaba Makes It Official
Alibaba issued an internal notice seen by the South China Morning Post, classifying Claude Code as high-risk software with security vulnerabilities. Starting July 10, all Alibaba employees are prohibited from using Claude Code at work. They are also required to uninstall all Anthropic models and agent products and switch to Alibaba's own AI assistant, Qoder.
CNBC confirmed the ban independently Monday. Both Alibaba and Anthropic declined to comment to CNBC.
This follows Anthropic's June letter to the Senate Committee on Banking, Housing, and Urban Affairs, in which Anthropic accused Alibaba of carrying out what it called "the largest known distillation attack" on its models to date, describing the behavior as "brazenly" and "illicitly" extracting Anthropic's AI capabilities.
The Loophole Problem Is Bigger Than One Company
Alibaba is not the only Chinese firm implicated. The Financial Times reported that Ant Group, the Chinese fintech giant, had provided employees with corporate Claude accounts accessed through a Singapore-based entity, effectively routing around Anthropic's China restrictions. ByteDance, TikTok's parent, launched a reimbursement program on April 2 that allows engineers to expense personal Claude subscriptions, with access via VPN. A person familiar with ByteDance's policy told CNBC the program is meant to help staffers "experience and learn" about a wider range of AI products. Ant and ByteDance declined to comment on those reports.
The Financial Times also reported that Anthropic is actively working to close the third-country routing loopholes.
The Contradiction Privacy Advocates Won't Let Go
Anthropic has publicly refused to let the U.S. government use Claude to surveil American users and has taken a public stance against that use of its technology. Then it ran four months of undisclosed tracking on Chinese users using what researchers described as "prompt steganography" — hidden markers flagging users' timezone, proxy settings, and potential ties to Chinese AI labs. Shihipar said the code was added in March as an "experiment" to fight reseller abuse and distillation, and that Anthropic "had been meaning to take it down for a while" because stronger mitigations had since been built.
Privacy advocates are not buying the housekeeping explanation. The code was live for months before an outside researcher found it. Users had no disclosure. That's the same standard Anthropic used to object to government surveillance, applied selectively.
Anthropic's Defense Has Real Substance
Anthropic's underlying concern is not trivial. According to the Washington Post, Chinese firms have "consistently matched" U.S. AI model capabilities "within months" over the past year. Unauthorized resellers were selling access to Anthropic's free models for $1 a month and pro subscriptions, which retail for up to $100, for as little as $12, per the Post. A new model from Chinese company Zhipu AI outperformed Anthropic's Claude Opus 4 at finding computer vulnerabilities, the Post reported, and Opus 4 was only released in May.
Distillation, training a new model on another model's outputs, is not illegal. U.S. firms do it too. But running millions of queries against Claude to rapidly advance a competing model violates Anthropic's terms of service. Anthropic has joined OpenAI in pushing the U.S. government to treat industrial-scale distillation as intellectual property theft. At a recent Senate hearing, Sen. Tim Scott (R-S.C.) agreed that legal intervention is warranted.
The tracker was Anthropic's internal enforcement mechanism. The problem is it was hidden.
What the Chinese Tech Ecosystem Is Actually Doing
The wave of Reddit and GitHub posts exposing the tracking code triggered blowback in China well before Alibaba's formal ban. The ban itself, combined with China's framing of the hidden code as a "back-door risk," reframes a copyright/IP dispute as a national security issue. That framing gives Chinese regulators and companies political cover to push domestic AI tools regardless of capability gaps.
Alibaba's Qoder is now the mandated replacement. Whether it matches Claude Code's capabilities for Alibaba's developers is a separate question that neither Alibaba nor outside analysts have publicly answered.
The Unresolved Question
Anthropic's Shihipar said the company has "landed stronger mitigations" that made the hidden tracker obsolete. Anthropic has not publicly described what those mitigations are or whether they also operate without user disclosure. Until Anthropic answers that question on the record, the privacy concern doesn't close, regardless of whether the specific tracking code has been removed.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.