The whole story rests on one internal directive, seen by reporters at the South China Morning Post (a Hong Kong newspaper). Alibaba declined to comment. Anthropic stays silent. We ran it as news - but it's a single-source report that nobody involved has confirmed.
- Confirmed officially: nothing. Alibaba declined to comment; Anthropic hasn't publicly addressed either the ban or the claims of 'hidden code.'
- Reported by media (South China Morning Post, republished by TechCrunch and others): an internal directive that, from July 10, bans employees from using Claude Code and classifies it as high-risk software.
- Reported and unproven: claims of hidden code that reads time zones and proxy settings and scans for the names of Chinese companies. No independent technical analysis backs them up.
- Our mistake: the headline and dek presented the ban as established fact. The accurate record is 'reportedly.'
The headline and dek presented the Claude Code ban at Alibaba and the claims of 'hidden code' as established fact, when the whole story rests on an internal directive cited by the South China Morning Post; Alibaba declined to comment, and Anthropic hasn't confirmed it. The piece has been rewritten as a single-source report, the sources are labeled as media, and a 'Risk / uncertainty' box has been added.
Correction. We wrote 'Alibaba banned Claude Code' as established fact. It wasn't. It rests on an internal directive seen by reporters at the South China Morning Post. Alibaba declined to comment, and Anthropic stays silent - nobody involved has confirmed anything publicly.
The difference matters exactly here, because the story is convenient. It fits everything we already believe about the decoupling between China and American AI companies. That's exactly why we swallowed it fast. Stories that confirm what you expect sail through without checking. That's where you get burned most often.
If the directive is authentic, the story is still interesting, just a different one: a company swaps a foreign tool for its own (Qoder - Alibaba's own coding tool) and justifies the switch with security risks. Genuine concern and a convenient pretext look identical from here, and it's possible both are true at once.
Coding tools became geopolitics. Until a year ago you picked an editor for convenience; now the choice carries the question 'whose is it and what does it see.' Whoever builds through them needs to know what their code sends out - no matter whose tool it is. I don't need a leaked document to tell me that.
The story rests on a single media source (SCMP), citing a non-public internal document. Alibaba declined to comment, Anthropic hasn't confirmed it. The technical claims of 'hidden code' haven't been independently verified. The directive may well be authentic; as of July 13, 2026, we have no way to prove it.