
A cybersecurity agency under the Chinese government has recommended deleting Claude Code, the AI coding tool made by US artificial intelligence company Anthropic, saying it found a security vulnerability. Anthropic maintains that Chinese companies were never entitled to access Claude Code in the first place, as the technology conflict between the United States and China spreads into the realm of security.
According to The Wall Street Journal (WSJ) and other outlets on the 9th, China's government-operated cybersecurity vulnerability database (CNVDB) said that "some versions of Claude Code released between April and June this year contain a built-in monitoring mechanism that can transmit sensitive data such as location and identity information to remote servers without user consent." It added that "such functions could pose a serious security threat," and recommended that users delete the software or update to the latest version with the relevant code removed.
Chinese big tech firm Alibaba also instructed its employees to stop using Claude Code for work purposes starting the 10th. Some observers suggest that the Chinese authorities' warning could prompt other Chinese companies to restrict the use of Anthropic's services.
Anthropic has previously stated that Chinese companies such as Alibaba are not entitled to access Claude services. The mechanism cited by the Chinese authorities appears to be a function installed by Anthropic to block access by Chinese companies.
The controversy erupted after a recent post on the online community Reddit claimed that "Anthropic secretly inserted code into its software to identify users accessing it from China." In response, an Anthropic employee explained via the social media platform X (formerly Twitter) that "the code was an experiment to prevent account abuse by unauthorized resellers and AI model distillation."
The Chinese government currently does not approve making Anthropic services available to the public, and Anthropic also restricts access to Claude in China, citing national security. Nevertheless, it is known that many Chinese researchers and engineers use the services via overseas proxy servers. A significant number are said to use them with support from their affiliated companies.
Experts interpret this case as an extension of the US-China tech rivalry. According to Hong Kong's South China Morning Post (SCMP), Ben Hu, a member of the Hong Kong and China Network Security Association, said that "advanced AI security is now closely tied to export controls and national security, so it can no longer be viewed as merely a traditional cybersecurity issue." He added that "Chinese companies will need to assess AI firms not as ordinary software suppliers but as part of a strategic supply chain influenced by geopolitical variables and national security."






