MilikMilik

Claude Code’s Hidden Tracking Sparks Enterprise AI Bans

Claude Code’s Hidden Tracking Sparks Enterprise AI Bans
Interest|High-Quality Software

A security experiment that looked too much like a backdoor

Claude Code security is now a flashpoint in enterprise AI after Anthropic embedded a hidden steganography-based tracking system in its coding assistant to detect suspected model theft and account abuse, prompting accusations of an AI tool backdoor and bans from major companies. Anthropic added covert code to Claude Code several months ago to catch other AI firms trying to steal from its models, an experiment launched in March to stop account abuse by unauthorized resellers and defend against distillation, the practice of copying AI models through repeated queries. The mechanism, exposed by a developer, used steganography in the system context sent to Anthropic’s servers: it silently altered system prompts with near-invisible Unicode markers, and hid a domain list behind XOR and base64 encoding to classify proxies and gateways. This was never clearly disclosed to users, which turned a narrow anti-fraud measure into a broader trust problem.

Claude Code’s Hidden Tracking Sparks Enterprise AI Bans

From anti-distillation defenses to accusations of spyware

Anthropic insists the tracking code was a defensive move, not surveillance. The firm had already announced in February that it was investing in defenses against distillation, including detection via classifiers and behavioral fingerprinting, access controls, and countermeasures that make model output harder to reuse for training. Claude Code’s source later revealed a Typescript flag, ANTI_DISTILLATION_CC, which injects fake tool data into API requests so that any stolen outputs become toxic for model training. But once the hidden steganography feature became public, it was “widely described as spyware” because it checked location signals and flagged users connecting through certain gateways and labs. The company says stronger mitigations have since been deployed and the tracking experiment is being removed, with the pull request merged and a fix scheduled to appear in the July 1 Claude Code release. The message is clear: undisclosed security tricks are no longer acceptable, even in the name of model protection.

Claude Code’s Hidden Tracking Sparks Enterprise AI Bans

Enterprise AI bans: Alibaba, banks, and the risk calculus

Enterprises are voting with their feet. Alibaba has told employees to stop using Claude Code, classifying it as high-risk software and enforcing a ban from July 10. According to one report, the company cited embedded backdoor risks in the assistant after a Reddit post alleged that an April release contained code capable of identifying users accessing it from China. Another source says Alibaba’s move was driven by security concerns after Claude Code’s hidden feature, discovered in June, was widely labeled spyware. The ban comes amid a far larger clash: Anthropic told U.S. senators that Alibaba orchestrated the largest known model extraction attack against Claude, with more than 28.8 million exchanges generated through nearly 25,000 fraudulent accounts between April 22 and June 5. In comparison, the company said DeepSeek’s operation involved over 150,000 exchanges, Moonshot AI exceeded 3.4 million, and MiniMax surpassed 13 million. Shares of Alibaba fell 0.7 percent on the news, while the Hang Seng Index gained 1.3 percent.

Claude Code’s Hidden Tracking Sparks Enterprise AI Bans

Broader pullbacks: Microsoft, JPMorgan, Goldman and AI tool vetting

Alibaba is not alone in tightening Claude Code security. It joins Microsoft and JPMorgan Chase on a growing list of companies pulling back from Claude this year. While Alibaba’s decision is framed around backdoor and spyware concerns, JPMorgan and Goldman Sachs have limited employee access to Anthropic’s models in Hong Kong, citing licensing terms that exclude use across Greater China. These enterprise AI bans show how quickly large organizations will act once a tool is labeled high-risk software or appears to skirt contractual boundaries. For Alibaba, reports say the ban extends beyond Claude Code to Anthropic’s Sonnet, Opus, and Fable models, with staff instructed to switch to its own Qoder coding tool. One report notes that engineers had previously been reimbursed for outside AI tools and some spent hundreds of dollars a week on services like Claude Code and Codex, but that open reimbursement culture has given way to tighter internal controls.

Trust, consent, and the new standard for AI vendor accountability

The Claude Code episode exposes an uncomfortable reality: AI vendors are under pressure to defend their models, yet enterprises will not tolerate anything that looks like a hidden backdoor. Alibaba reportedly saw the undisclosed tracking feature as grounds to classify Claude Code as high-risk and to remove it from its approved software stack. Another analysis notes that this choice showed how trust and security worries are beginning to shape AI adoption decisions at the corporate level, regardless of Anthropic’s explanation. Meanwhile, Anthropic plans to remove the covert tracking code, saying stronger mitigations have been landed and the experiment had been due for removal. That is a step in the right direction, but it also sets a precedent: meaningful Claude Code security cannot be built on invisible mechanisms that users did not consent to. Enterprise buyers will now demand explicit disclosure, auditable defenses against model extraction, and clear limits on how AI tools observe and classify their use. The lesson for vendors is blunt: if you need an anti-fraud defense, document it, ship it openly, and assume your customers will see everything anyway.

Milik earns a commission when you shop through our links, at no extra cost to you. This article was generated with AI from published sources and product data.

You May Also Like

Comments
Say something...
No comments yet. Be the first to share your thoughts!