Tuesday Jul 14

Anthropic Admits Claude Code Tracked Users

14JUL
REGULATORANTHROPIC3 MONTHS HIDDEN

Claude Code was quietly checking where its users logged in. China's regulator called it a backdoor. Anthropic confirmed the check was real. The clash lands as US-China AI tensions rise.

The code lived in Claude Code versions 2.1.91 through 2.1.196, from April to June. It checked device time zones and flagged banned regions or suspected distillation labs.

Alibaba banned Claude Code over the hidden tracking. Anthropic says China-based use was never authorized anyway. Shihipar promised a full rollback in the next release.

Every AI lab now runs some version of this anti-piracy check. Expect more of these disclosures as export controls tighten.

full brief & sources

Why this matters

  • Shows frontier labs quietly police their own products with code users never see.
  • Ties directly into the broader US-China AI decoupling fight.
  • Raises a real question: whose job is it to disclose covert monitoring?

🔍 What happened

  • China's MIIT and National Vulnerability Database flagged Claude Code as a security threat on Jul 8.
  • The alleged backdoor sends device data to Anthropic servers without user consent, per China's report.
  • Anthropic confirmed the mechanism: a time-zone and region check built to block banned regions and anti-distillation abuse.
  • The code shipped in Claude Code 2.1.91 through 2.1.196, April through June 2026.
  • Alibaba banned Claude Code internally over the tracking before Anthropic's statement.
  • Anthropic says China-based accounts were never authorized to use Claude Code in the first place.

💬 Smart takes

  • Thariq Shihipar (Anthropic): 'This is an experiment we launched in March to prevent account abuse and protect against distillation.'
  • China's National Vulnerability Database: called the mechanism 'a serious threat' sending data 'without user consent.'
  • Skeptic: a policy that quietly geo-fingerprints every user looks a lot like the exact behavior Western regulators fine other companies for.

🧭 Where this goes

  1. LikelyAnthropic ships the promised rollback within weeks and publishes a clearer disclosure policy.
  2. LikelyChinese regulators use this case to justify blocking more US AI tools.
  3. Possibleother labs get caught running similar undisclosed anti-abuse checks.
  4. Wild Cardthis becomes a formal complaint inside a US-China trade or tech dispute.

🥄 The Spoon Take

Every AI lab is quietly running anti-piracy code most users never agreed to. Anthropic got caught first, but it will not be last. The real story is not the backdoor. It is that nobody asked users first.

🤔 Pushback

Anthropic says China-based use was never authorized, so calling this a user-rights violation may overstate a policy Anthropic never intended to apply there.