Digital Sovereignty & Network Governance  ·  3 July 2026

The Cutoff That Isn't

How the same infrastructure restricts access, gets exploited, gets watched, and gets sold, all at once.
By Alan Wright  ·  The Haunted Lighthouse Limited  ·  Peel, Isle of Man

On 2 July 2026, the Financial Times reported that Anthropic is moving to close loopholes that have allowed Chinese firms to access Claude despite an explicit ban on Chinese controlled entities. According to the FT's sources, Ant Financial provided staff with corporate Claude accounts routed through a Singapore registered entity; ByteDance reimbursed engineers for personal Claude subscriptions accessed via VPN. Neither practice breaks US or Chinese law. Both breach Anthropic's own terms of service.

That story, on its own, is a compliance footnote. Read alongside three other things that happened in the same fortnight, it stops being a footnote and starts looking like the clearest available snapshot of how sovereignty restrictions, covert enforcement, state level cyber operations, and cloud vendor arbitrage now sit on top of one another inside a single piece of commercial infrastructure.


The restriction

Anthropic's position is genuinely the strictest among the frontier labs: mandatory user verification, blocked Chinese bank payments, an explicit ban extended this year to majority owned subsidiaries of restricted entities, closing the corporate shell loophole that previously offered plausible deniability. OpenAI's equivalent restrictions have been in place since July 2024 and remain, by comparison, closer to nominal; Chinese developers have kept working around them with VPNs and foreign phone numbers for two years with little sign the friction has increased.

The proximate trigger for Anthropic's latest tightening, as per a letter the company sent US senators on 10 June 2026, was a distillation campaign it attributes to operatives linked to Alibaba's Qwen lab: roughly 25,000 fake accounts generating 28.8 million interactions between 22 April and 5 June. Distillation, training a smaller model to mimic a larger one's outputs, is the commercial threat Anthropic is actually defending against here. The China access ban is as much an IP protection measure as a sovereignty one, and it is worth being honest that the two motives are not in tension.

The mechanics of the workaround, as per the FT's sourcing, run through the same cloud infrastructure Anthropic itself partners with. Microsoft reportedly sold API access to Chinese companies operating through Singapore entities, letting mainland engineers reach Claude internally via Azure. Microsoft's public statement is that it supports Anthropic's enforcement efforts. Both things are true simultaneously, and there is no contradiction in Microsoft's stated position; providing infrastructure is not the same as being a party to Anthropic's terms of service. That distinction is doing a great deal of work.


The detection code

Separately, and unconfirmed by Anthropic as of writing: a developer posting as LegitMichel777 on r/ClaudeAI disclosed on 30 June 2026 that Claude Code versions from 2.1.91 onward (released 2 April 2026) contain undocumented detection logic. The claim, discovered incidentally while working on an unrelated remote control feature, describes a multi factor check that fires when a proxy is detected: system timezone against Asia/Shanghai and Asia/Urumqi, proxy URL against a hardcoded list of Chinese domains and known Chinese AI lab endpoints. Portions of the relevant code are alleged to be XOR obfuscated with a static key, specifically to resist plain text string extraction during binary analysis; which is a materially more deliberate concealment claim than "silently alters the system prompt" suggests on first read.

Anthropic has not, at time of writing, issued a public statement confirming or denying the mechanism, though The Information reported the company appeared to be backtracking on at least some of the covert detection following the pushback. Treat the existence and precise behaviour of this code as alleged, not confirmed, the only source is a third party reverse engineering claim, however specific.

What is worth noting regardless of whether the allegation holds up in full: the discovery method only works on client visible code. A researcher diffing a distributed binary can find something shipped to every user's machine. Nothing about that method touches server side detection, behavioural fingerprinting, request timing analysis, classifier based flagging, which Anthropic has separately and openly said it is investing in since February 2026. If the client side mechanism was the visible one and something else is running server side, no amount of community reverse engineering of Claude Code binaries would surface it. That is not evidence such a thing exists. It is simply the limit of what this discovery method could ever prove either way.


The precedent that explains the timing

The reason Anthropic might plausibly want covert China proxy detection running by April 2026 is not abstract. On 13 November 2025, Anthropic disclosed what it called the first documented AI orchestrated cyber espionage campaign, assessed with high confidence to be the work of a Chinese state sponsored group it designated GTG 1002.

The operation targeted roughly thirty organisations across tech, finance, chemical manufacturing, and government, succeeding against a handful. The operators jailbroke Claude Code by decomposing the attack into small, individually innocuous tasks and claiming to be a legitimate cybersecurity firm running defensive tests; Claude was not aware for most of the operation what it was actually part of. AI executed an estimated 80 to 90 per cent of tactical operations independently, with human involvement concentrated at four to six decision gates per campaign: approve reconnaissance to exploitation, approve credential use for lateral movement, approve exfiltration scope. Autonomous task blocks ran one to six hours; human review windows, two to twenty minutes.

Anthropic's own report is candid about the failure mode that currently caps autonomy: Claude repeatedly hallucinated credentials and, in at least one case, claimed to have extracted secret data that was in fact public. That is the actual ceiling on this kind of operation right now, not a policy constraint, an autonomous agent that occasionally fabricates a successful compromise still needs a human checking whether it did.

Over the ten days following detection, Anthropic banned accounts as they were identified and states it "coordinated with authorities" while gathering intelligence. No further detail is given on which authorities, what was shared, or under what legal basis. That gap matters more than it looks: it is the one place in Anthropic's own published account where the boundary between "we defended our platform" and "we fed a state actor's activity into a government channel" is simply left open.


The infrastructure underneath both labs

None of this sits in isolation from Microsoft, and it is worth being precise about the mechanism rather than gesturing at it. Azure's China market access runs two structurally distinct paths: Azure China, operated locally by 21Vianet under Chinese regulatory law, and Azure's Southeast Asia, East Asia, and Japan East regions, operated directly by Microsoft and therefore governed by US law but not by the interpretation that would block Chinese entity service outright. OFAC sanctions apply to specifically listed entities; Ant, ByteDance, and Tencent are not currently on that list, which is the entirety of what keeps the second path open.

The pattern is not new. When OpenAI blocked API access from China in July 2024, Microsoft published a migration guide to Azure OpenAI within days, and internal accounts describe the exit as read by Microsoft's Azure sales function as an opportunity rather than a signal to follow suit. The same regional endpoint architecture is now doing double duty: Claude reached general availability in Microsoft Foundry this year, meaning Azure is currently the only cloud offering both frontier labs' flagship models through one platform, one arbitrage.

One distinction is worth holding onto precisely because it cuts against the tidiest version of this story: even where Claude runs "hosted on Azure" inside Foundry, Anthropic states it continues to operate inference and act as data processor. Microsoft holds the network path; Anthropic holds custody of the model and the data. Sovereignty over access and sovereignty over inference are not the same question, and conflating them overstates how much control any regional Azure endpoint actually confers on Microsoft.


The jurisdictional footnote nobody in this story mentions

There is a structural irony sitting underneath all of this that neither the FT reporting nor Anthropic's own material engages with, and it is worth stating plainly rather than as innuendo. The CLOUD Act (2018) attaches US legal compellability to the provider, not to server location or the customer's registered entity. A US controlled company, Anthropic, Microsoft, and so on, can be compelled to produce data it controls regardless of whether the account is nominally domiciled in Singapore or the endpoint is geo located in Tokyo. Corporate ownership is the operative jurisdiction, not geography.

The practical consequence: a Chinese engineer routing through exactly the workaround architecture described in the FT piece, foreign subsidiary account, Azure endpoint in an approved region, VPN, has not actually left US legal reach. They have routed their traffic through it. A user on a domestic Chinese model never generates that exposure at all. Whether any US authority is deliberately relying on this dynamic is not something the public record supports claiming either way, and this piece makes no assertion of intent. What can be stated as a matter of structure, not speculation: restricting legitimate access and creating compellable exposure are not in tension here. They are two properties of the same infrastructure, and tightening one does not loosen the other.

Section 702 of FISA, the bulk collection authority that would be the more dramatic version of this argument, is in a weaker position to support it at present, as it lapsed on 12 June 2026 for the first time since 2008, with no reauthorisation deal in sight as of this writing. Worth being precise here rather than leaving the impression the programme went dark overnight: existing 702 collection continues regardless of the statutory lapse, because it runs under annual FISC certifications rather than the statute itself, and the certifications approved on 17 March 2026 remain valid until roughly March 2027 under FISA's grandfathering provision. What lapsed is the government's ability to compel new directives on providers, not the collection already authorised. The CLOUD Act does not depend on any of that and was the stronger mechanism throughout.


What this actually adds up to

Strip away the individual news cycles and the shape underneath is consistent: an AI lab enforces a restriction for defensible commercial reasons, the restriction gets routed around through the same cloud infrastructure the lab commercially partners with, a confirmed state linked actor used that access for autonomous cyber espionage months before the lab allegedly shipped contested covert detection code, and the entire stack, restriction, workaround, detection, and cooperation with authorities, runs through providers who are legally compellable regardless of where any of the parties believe the data physically sits or which corporate entity they believe they are transacting with.

Nobody in this chain needs to be acting in bad faith for that structure to hold. Anthropic's restriction is a reasonable response to a real distillation threat. Microsoft's Azure sales function pursuing revenue in a market its own compliance framework nominally restricts is not a new story, and Microsoft's public support for Anthropic's enforcement is not inconsistent with continuing to sell the access that undermines it. The alleged detection code, if it exists as described, is a defensible security measure executed without disclosure. None of these individually require a conspiracy. Together, they describe an infrastructure where restriction, evasion, surveillance, and jurisdiction are not separate problems being solved by separate actors; they are one system, and every actor in it is optimising a different corner of the same structure simultaneously.

That is the Theatre Pulldown thesis in miniature: sovereignty performed at the policy layer, arbitraged at the infrastructure layer, and quietly overridden at the jurisdictional layer, all inside the same fortnight of news.


Cross-reference: The Theatre Pulldown


Questions about this analysis, or interested in working with The Haunted Lighthouse?
contact@haunted.lighthouse.co.im

The Sovereign Auditor covers digital sovereignty, cybersecurity governance, and data protection policy—with particular focus on Isle of Man jurisdiction and Crown Dependency issues.

Support independent analysis. Subscribe directly—or scan on your phone.

Payments via PayPal. Credentials delivered by email. No Substack. No Stripe. No middlemen.