China’s cybersecurity authorities have issued a warning regarding Anthropic’s Claude Code, alleging that certain versions of the AI-powered coding assistant contain a security mechanism capable of transmitting sensitive user information without explicit authorization.
The warning was published by China’s National Vulnerability Database (NVDB), a cybersecurity platform affiliated with the country’s Ministry of Industry and Information Technology. The agency has advised organizations and individual users to review their systems and update or remove affected versions of the software.
Chinese Regulator Flags Alleged Security Issue
According to the NVDB, the alleged vulnerability could allow Claude Code to transmit information such as users’ geographic location and device or identity-related data to Anthropic’s servers without the user’s direct consent.
The regulator described the issue as a significant cybersecurity risk and recommended that organizations strengthen network traffic monitoring to detect potential unauthorized data transfers. Users were also encouraged to install the latest software updates, which the regulator says remove the disputed functionality.
What Is Claude Code?
Claude Code is an AI-powered coding assistant developed by Anthropic. The tool helps software developers write code, debug applications, review projects, and automate programming tasks using natural language prompts.
AI coding assistants have become increasingly popular among developers as businesses continue adopting generative AI to improve software development productivity.
Anthropic Yet to Issue an Official Response
At the time of publication, Anthropic had not released an official public statement responding to the warning issued by Chinese authorities.
Reports indicate that the company had previously restricted access to its AI products in China. Despite those restrictions, some users have continued accessing Claude Code through virtual private networks (VPNs) and third-party proxy services.
Alibaba Reportedly Suspends Internal Use
The security warning has already prompted reactions within China’s technology sector.
According to multiple reports, Alibaba has instructed employees to stop using Claude Code beginning July 10 while the reported security concerns are being evaluated. The company has not publicly detailed its internal decision-making process.
The development follows ongoing tensions between Anthropic and several Chinese technology companies over artificial intelligence technologies and model development.
Engineer Explains Experimental Feature
Following reports circulating online, Claude Code engineer Thariq Shihipar acknowledged that the software previously included an experimental mechanism introduced earlier this year.
According to his explanation, the feature was designed to detect account abuse by unauthorized resellers and discourage attempts to reverse engineer or distill Anthropic’s AI models. He stated that the mechanism was not intended to collect user information for unrelated purposes and confirmed that the company had already planned to remove the experimental code in an upcoming software update.
Why It Matters
The incident highlights the growing focus on AI security, software transparency, and data privacy as governments increase oversight of advanced artificial intelligence tools. As AI coding assistants become widely adopted by businesses and developers, organizations are expected to place greater emphasis on understanding how these systems collect, process, and transmit user data.
The case also reflects the broader geopolitical challenges surrounding artificial intelligence, where cybersecurity, regulation, and cross-border technology competition continue to influence the global AI industry.









