Alibaba bans Claude Code at work over security concerns
Alibaba has banned employees from using Anthropic's Claude Code for work, adding the coding agent to an internal high-risk software list and telling staff to use Qoder, Alibaba's own coding assistant, instead. The South China Morning Post reported the internal notice on July 3, with Reuters and Caixin publishing similar reports the same day. The restriction is set to take effect on July 10.
The stated concern is security. According to the reports, Alibaba objected to hidden mechanisms in Claude Code that could help identify China-linked users by inspecting signals such as timezone, proxy configuration and other environment details. Reuters said an Anthropic employee described the mechanism on X as an experiment launched in March to prevent account abuse by unauthorized resellers and to protect against model distillation. Caixin reported that the feature was being removed in an updated version. Neither Alibaba nor Anthropic immediately gave detailed public responses to the news reports.
The timing makes the decision more sensitive. Anthropic does not officially provide Claude to users in mainland China and Hong Kong, yet Claude Code has still become popular among Chinese developers. Last month, Anthropic accused operators linked to Alibaba's Qwen lab of using fraudulent accounts to extract Claude's model capabilities, a practice known as distillation. Alibaba has not publicly responded to that accusation.
For AI users and companies, the lesson is practical. Coding agents are not ordinary chatbots. They often run close to source code, terminals, build logs, credentials, internal documentation and developer workflows. If a tool silently checks local environments, even for anti-abuse reasons, enterprise security teams will ask harder questions about telemetry, auditability and vendor trust.
For makers, this is another sign that AI coding tools are becoming strategic infrastructure. The competitive fight is no longer only about which assistant writes better code. It is also about who can trust the tool, where data travels, how labs prevent misuse, and how geopolitical restrictions shape access. Alibaba's move may push more large organizations to demand local controls, clearer disclosures or in-house alternatives before letting agents deeper into software work.