Anthropic, the company behind the AI assistant Claude, goes to great lengths to prevent people in China from using its models, yet its safeguards have often failed. According to a WIRED report, over the past year, startups, researchers, and tech enthusiasts across China have developed increasingly sophisticated workarounds to access Claude, which many consider the world's most capable AI assistant.
The Cat-and-Mouse Game
Chinese users typically access other Western AI tools like OpenAI’s ChatGPT using virtual private networks (VPNs), foreign phone numbers, and international payment methods. However, Anthropic has taken more aggressive steps, such as banning accounts it suspects are owned or controlled by people located in China. On Chinese social media, users frequently report being suspended from Claude without warning despite taking these precautions, according to WIRED.
The Underground Economy
The circumvention efforts have created a thriving underground economy. Accounts are sold on Chinese ecommerce platforms like Taobao and through illicit marketplaces on Telegram. More recently, a cottage industry of “transfer stations” has emerged. These services act as intermediaries, purchasing access to Anthropic’s API outside China and then redistributing Claude API tokens to users inside the country. WIRED reported that this setup gives startups and professional users more stable and reliable access to the AI assistant.
Michael Aciman, a spokesperson for Anthropic, stated that the company uses a range of evolving detection systems, including identity verification, to enforce its policies. He added that Anthropic has also worked to detect and disrupt proxy networks used to provide access to the chatbot in China.
Why Chinese Users Prefer Claude
Despite the difficulties, Claude remains popular in China, especially among programmers. WIRED spoke to academics and engineers at multiple tech companies during a recent reporting trip, who said they preferred using Claude over Chinese models to generate code and are eager to try each new Anthropic release. Even though Chinese companies like DeepSeek and Z.ai offer some of the most capable open-source large language models, third-party tests still show they lag behind leading closed models like Claude.
Zilan Qian, a research associate at the Oxford China Policy Lab, looked into the black market for reselling Western AI tokens to Chinese users. He noted that Chinese software developers overwhelmingly prefer tools like Claude Code and OpenAI’s Codex compared to domestic offerings. “Analysis shows that Chinese models are still six to nine months behind the US models, and for specific things like coding and developing, you can obviously tell the gap,” Qian said.
Matt Sheehan, a senior fellow at the Carnegie Endowment for International Peace, added: “For both Chinese AI policymakers and technical people, they have much less of a problem drawing on and using American ideas or products, regardless of the geopolitical or ideological rivalry.”
| Access Method | Description | Risk Level |
|---|---|---|
| VPN + foreign phone + payment | Standard approach for ChatGPT; also used for Claude but more likely to be banned by Anthropic | Medium |
| Purchased accounts (Taobao, Telegram) | Pre-registered accounts sold on black markets | High (account suspension) |
| Transfer stations | API token resale via intermediaries outside China | Lower (more stable) |
Implications for Enterprise Technology Leaders
For CTOs and technology procurement leaders, this circumvention ecosystem highlights the demand for top-tier AI coding tools in China, even under restrictive conditions. The reliance on unofficial access channels introduces security risks, including data leakage and unaccountable API usage. Enterprises that rely on AI models for critical development tasks must consider both the regulatory landscape and the stability of access. As Anthropic and other US AI firms tighten geolocation controls, the gap between Chinese and US AI capabilities, particularly in coding, may persist for the near term.