Anthropic Closes Claude Access Routes Used by Chinese AI Firms

What You Need to Know
- Chinese engineering teams accessed Claude through proxy services, VPNs, and overseas subsidiaries to circumvent restrictions.
- Alibaba generated 28.8 million Claude interactions via 25,000 fraudulent accounts; DeepSeek, Moonshot, and MiniMax logged millions more.
- Anthropic is actively closing unauthorized access channels rather than only flagging violations of service terms.
- Singapore subsidiaries were used as legal routing points to pipe requests into restricted services, mirroring semiconductor export control workarounds.
Chinese engineering teams have been systematically accessing Anthropic’s Claude AI through proxy cloud services, overseas subsidiaries, and VPN-expensed personal accounts, and Anthropic is now actively closing those channels rather than simply flagging violations.
The scale documented in the source is specific enough to matter. Alibaba allegedly ran over 25,000 fraudulent accounts to generate 28.8 million Claude interactions. DeepSeek logged 150,000 queries, Moonshot 3.4 million, MiniMax 13 million. ByteDance engineers reportedly expensed personal Claude subscriptions and routed access through VPNs. Ant Financial gave staff corporate accounts tied to its Singapore entity. The Singapore routing detail is the sharpest thread here: using a compliant overseas subsidiary to pipe requests into a restricted service is a structurally familiar move, one that mirrors how Chinese firms navigated U.S. semiconductor export controls before the Commerce Department began tightening entity-list enforcement in 2022. The access method is legal at the corporate level; the terms-of-service violation sits one layer below that, which is precisely what makes it hard to stop.
Anthropic already used Claude Code itself to detect device time zones as a verification layer, which is either elegant or a sign of how thin conventional controls have been.
The broader implication is about where the AI access-control problem is actually located. Microsoft, which provided API access to Chinese firms through Singapore subsidiaries, says it assists Anthropic in enforcing terms, but a source cited in the reporting makes clear the Singapore routing practice extends well beyond any single cloud provider. That means Anthropic’s crackdown on “transfer station” services is necessary but insufficient: as long as overseas subsidiaries remain a legitimate corporate structure, the enforcement problem recurses. Other U.S. AI labs with strict China policies face the same structural gap, and Anthropic’s public documentation of specific query counts from named Chinese companies is the kind of evidence base that tends to accelerate regulatory attention, particularly as U.S. lawmakers have grown more aggressive about AI export controls following the DeepSeek moment earlier this year.
Separately, Anthropic signed the largest office lease in Seattle so far this year, taking 113,000 square feet at the Dexter Yard complex in South Lake Union, nearly doubling its existing footprint at the same campus. The expansion is straightforwardly consistent with a company that recently secured significant funding and is scaling headcount, though the timing alongside a high-profile enforcement push suggests the operational and political pressures are arriving simultaneously.
0 Comments