When Anthropic added a tracker to flag Chinese Claude Code users, it tested whether code level terms of service enforcement works in a high demand gray market. Three answers arrived within a week.
In April 2026, Anthropic added steganographic code to Claude Code, its agentic coding product, to identify users in mainland China, where its terms of service bar the product. The lab framed it as an anti-distillation experiment. The week that followed: a rollback, an internal ban at China's largest cloud vendor, and a state vulnerability database advisory. Together they are the first public test of whether code can substitute for declared policy when the two diverge.
Claude Code is Anthropic's developer-facing tool that can read, edit, and run code inside a project. Shihipar, who characterized the change in comments to The Register as an anti-distillation experiment launched in March. In the AI trade, "distillation" means training a smaller model to imitate a larger one's outputs, the technique behind most open-weights knockoffs. Anthropic has accused Alibaba, in particular, of running what it called the "largest known distillation attack" against its models, the corporate backdrop for the tracker.
The lab told readers the markers would be fully removed in the next release. That release shipped on July 1 as Claude Code v2.1.197, and the tracking code went with it. The exposure, though, was the part that mattered.
Two days later, Reuters reported that Alibaba had circulated an internal notice banning employees from using Claude Code, with an effective date of July 10. TechCrunch and CNBC confirmed the same internal mandate, citing security and backdoor concerns. The ban language varied across outlets ("internal mandate" in some, "reportedly bans" in others), but all traced to the same set of internal memos.
A week after Anthropic's rollback, China's National Vulnerability Database of Information Security, known as CNNVD and run by the state-backed China Information Technology Security Evaluation Center, issued a public advisory warning that specific Claude Code versions could transmit location and identity-related identifiers back to Anthropic's servers without user consent, and urged uninstallation. The Register and CBS News carried the same advisory.
Three actors answered within a week. The responses are the public record of what code-level enforcement looks like when it surfaces.
Anthropic's underlying problem is that the policy and the market do not align. Anthropic's terms bar use in China, but a January 2026 reporting trip by journalist Afra Wang, summarized in ChinAI #367, found that dozens of AI developers in Hangzhou, Liangzhu, and Shanghai were using Claude Code, Antigravity, Codex, or Cursor, with Claude most frequently mentioned, and none were using Chinese coding tools. The sample is anecdotal and six months old, but the direction is consistent: the Chinese market for frontier US coding agents was already the de facto tool of choice for sophisticated Chinese developer teams before the tracker made demand visible to the lab.
A US lab in Anthropic's position has three options for that gap. It can enforce, by adding code that geofences, throttles, or identifies users; it can ignore the gap, leave terms unenforced, and treat revenue and usage as the real policy; or it can stop serving the market, by blocking mainland IP ranges or cutting off accounts. Anthropic tried the first option, in a narrowly-scoped, short-lived form, and abandoned it within two months. The rollback is the answer to the test.
The broader US lab pattern points the same way. OpenAI's ChatGPT and Google's Gemini face analogous China demand and analogous terms-of-service restrictions; both have been reachable from mainland China with varying degrees of friction. None of the three has yet tried Anthropic's experiment in public. When one does, the week-long sequence from the Claude Code tracker is the most current reference point for what to expect: a corporate customer, a state vulnerability database, and a retreat.
The CNNVD advisory is not a verdict on Claude Code's security. It is a regulator's flag on a specific behavior in a specific build, and the build Anthropic identified is the one that just got pulled. The Alibaba internal mandate is a single company's response, not a national pattern, though the timing suggests the company did not want to be the second name on a CNNVD list. Afra Wang's field reporting is six months old and reflects a self-selecting group of developers already comfortable with US tooling. Each framing has a limit.
Code is a poor enforcement tool for a policy a market does not respect. The moment the code is visible, the policy is visible, and the policy is what every counterparty (corporate customer, state regulator, developer) responds to. Anthropic's experiment will not be the last.