
So this one’s been building for a while. Why Alibaba bans employees for using Claude comes down to a messy, escalating fight between two companies that were never really friendly to begin with. Starting July 10, Alibaba staff can’t use Anthropic’s Claude Code at work anymore. Not officially, anyway. The company put it on an internal high-risk software list. That’s the short version. The longer version is a lot more interesting. Also Read Which AI Tool Is Best for Interview Preparation in 2026?
Table of Contents
What Actually Happened
Alibaba told employees in an internal notice that Claude Code carries what it called back-door risks. The notice said the tool had been added to a list of software with security vulnerabilities, after what the company described as a comprehensive evaluation. Staff were told to switch over to Qoder, Alibaba’s own coding assistant, instead.
That’s the official reason behind why Alibaba bans employees for using Claude. But there’s a backstory here that makes the whole thing feel less like a routine IT security decision and more like the latest move in an ongoing standoff.
The Tracking Code That Started This
A few weeks before the ban, developers on Reddit and GitHub found something odd buried inside Claude Code. A version of the tool appeared to check things like a user’s timezone, proxy settings, and other environment details, then quietly embed identifying markers into the data sent back to Anthropic’s servers. In plain terms, it looked like the tool could tell whether someone was likely based in China or connected to a Chinese AI lab.
Thariq Shihipar, who works at Anthropic, addressed it on X. He said it was an experiment launched back in March, meant to stop unauthorized resellers from abusing accounts and to guard against distillation. He also said stronger protections had already replaced it and that the team had meant to remove the older code for a while.
Fair enough, maybe. But once that story spread, it’s easy to see why Alibaba bans employees for using Claude started looking like the obvious next step, at least from Alibaba’s side of things.
This Didn’t Come Out of Nowhere
Here’s the part that gets left out of a lot of the coverage. This ban didn’t happen in a vacuum. Back in June, Anthropic sent a letter to the U.S. Senate Committee on Banking, Housing, and Urban Affairs. In it, the company accused entities linked to Alibaba of running one of the largest known distillation operations against Claude, using roughly 25,000 fraudulent accounts to run close to 28.8 million exchanges with its models over about six weeks.
Distillation, if you’re not familiar, is basically training a cheaper model on the outputs of a more expensive one. It lets you copy a lot of another model’s behavior without doing the expensive part yourself. Anthropic said the effort specifically targeted things like agentic reasoning and long-horizon task completion, the exact capabilities that make Claude Code useful for programmers in the first place.
So really, why Alibaba bans employees for using Claude only makes sense once you see both sides of it. Anthropic accusing Alibaba of stealing its model’s capabilities. Alibaba turning around and framing Anthropic’s own tool as the security threat. Neither side looks particularly innocent here. Also Read What Are the Best AI Search Visibility Tools in 2026

Anthropic’s Rules Were Already Strict
It’s worth pointing out that Anthropic already prohibits Chinese companies, along with foreign entities owned by them, from using its models at all. That restriction existed before any of this blew up. The problem, according to people familiar with enforcement, is that it’s hard to actually stop. Someone can spin up a U.S.-based server and make their traffic look like it’s coming from anywhere. Individuals get around this stuff constantly.
Companies are different. Companies have lawyers and compliance departments and reputations to protect, and that’s part of why enforcement against a business like Alibaba actually has teeth in a way it doesn’t for random individual users.
The Financial Times also reported separately that Anthropic has been working to close loopholes letting Chinese firms access Claude indirectly, through entities based in other countries. One example involved a Chinese fintech company reportedly giving employees Claude accounts routed through a Singapore-based entity.
The Bigger Picture Here
Why Alibaba bans employees for using Claude isn’t really an isolated story either. It fits into a much wider pattern of U.S. and Chinese companies pulling apart from each other’s AI tools. Chinese firms have been leaning harder into homegrown alternatives like Qwen, DeepSeek, and Moonshot. On the American side, companies have been doing something similar in reverse, cutting back on Chinese-linked tools for their own security reasons.
It’s not just China-related restrictions either. Microsoft reportedly pulled Claude Code licenses from its own engineering team back in May, though that decision was more about ballooning token costs than security concerns. Also ReadPolitician Who Investigated Spyware Abuses Had His Phone Hacked With Pegasus Spyware

Where This Leaves Things
Neither company has said much publicly beyond what’s leaked to reporters. Alibaba hasn’t responded directly to the distillation accusations. Anthropic hasn’t commented much further on the ban itself. But the pattern is pretty clear at this point: an argument over stolen capabilities and hidden tracking code, then a workplace ban that punishes ordinary Alibaba engineers for a fight that started at a much higher level.
Whether this resolves quietly or turns into something bigger between two of the more prominent names in AI right now is anyone’s guess. For now, the short answer to why Alibaba bans employees for using Claude is simple enough: trust broke down on both sides, and neither company was willing to be the one that backed off first.