MakeBox AI
← Back to News
AnthropicJuly 17, 20266 min read

Anthropic Caught in the Crossfire: Beijing and the Pentagon Both Want to Cripple the AI Darling

Anthropic faces a two-front assault: China is labeling its Claude Code tool a security risk and pushing users to uninstall it, while the U.S. Pentagon has moved to classify the company as a supply-chain risk—a designation normally reserved for foreign adversaries. The escalating conflict underscores the high-stakes geopolitics of frontier AI.

Anthropic Caught in the Crossfire: Beijing and the Pentagon Both Want to Cripple the AI Darling

Anthropic, the safety-focused AI company behind Claude, has found itself in an unprecedented political pincer. On one side, China’s Ministry of Industry and Information Technology (MIIT) has issued a public advisory warning that Claude Code contains a “security backdoor vulnerability” and recommending users uninstall versions 2.1.9 through 2.1.6. On the other side, the U.S. Pentagon—led by Defense Secretary Pete Hegseth—has terminated its agreement with Anthropic and signaled it intends to label the company a “supply chain risk,” a designation previously used only for foreign adversaries such as Huawei. A federal judge has partially blocked that directive, but the damage to Anthropic’s reputation is already spreading.

What Happened

Anthropic has long positioned itself as a hawkish voice in the U.S.–China AI rivalry. In a policy paper, the company warned that China could overtake the U.S. in AI if Washington does not tighten chip controls and urged the government to “stop Chinese labs from distilling Anthropic’s models.” On February 23, Anthropic published a blog post accusing three Chinese AI labs—DeepSeek, Moonshot/Kimi, and MiniMax—of “industrial‑scale distillation” of its Claude models.

In March, the company secretly deployed tracking code in Claude Code that checked whether a user’s machine was in a Chinese time zone and whether the domain matched certain Chinese AI firms’ infrastructure. After a developer publicly exposed the surveillance, Anthropic removed the monitor, calling it an “experiment” that would be replaced by “better defenses.”

China’s response was swift and coordinated. The MIIT, via a national cybersecurity threat platform, issued a public warning that Claude Code versions 2.1.9–2.1.6 contained a backdoor that could exfiltrate sensitive information to a remote server. Anthropic explained that the mechanism was experimental defense against distillation, not spyware, but the advisory recommended users “uninstall or upgrade” from those versions.

Meanwhile, Chinese state‑linked media seized on the opportunity. Commentators expressed schadenfreude over Anthropic’s troubles with the Pentagon, framing the company as a hypocrite—restricting Chinese access to its tools under the banner of U.S. national security, and now facing the same treatment at home. The narrative paints Anthropic as a leading promoter of the “China AI threat” narrative, whose own business is now threatened by the same kind of national‑security restrictions it helped popularize.

💡 Anthropic is now isolated in a way no other major U.S. AI company has been. It is simultaneously under regulatory attack from Beijing and on the verge of being labeled a national‑security risk by the Pentagon. This dual pressure is unprecedented for a Western AI firm.

Why It Matters

The conflict is part of a broader, high‑stakes strategic race. A New York Times report described a meeting in Singapore where a representative of a Chinese think tank sought access to Anthropic’s newest, most advanced AI model; Anthropic declined. U.S. national security officials interpreted this as part of Beijing’s multi‑channel effort to obtain cutting‑edge American AI, likening the race to the Cold War nuclear arms race.

At the same time, U.S. and global startups are increasingly turning to cheaper Chinese models from DeepSeek, Alibaba, and Moonshot AI. Even if Claude remains more capable, the cost advantage and fewer restrictions make Chinese alternatives attractive for heavy “token‑maxxing” use. This price‑driven adoption is a new threat to Anthropic and OpenAI.

The Pentagon’s move is equally significant. The supply‑chain‑risk designation was previously used only for foreign adversaries. Applying it to a domestic company signals a breakdown in trust between the U.S. military and a leading AI firm that refused to remove safety guardrails for unrestricted surveillance of American citizens via commercially available data. A U.S. judge has blocked enforcement of the directive for now, but the legal battle is far from over.

💡 The Pentagon’s attempt to cripple Anthropic—and the judge’s temporary stay—highlights the tension between national security demands and AI safety principles. Anthropic’s refusal to remove guardrails for surveillance is a defining moment for the industry.

What It Means for Business

For startups and developers relying on Claude, the situation introduces real uncertainty. The MIIT advisory in China could discourage use of Anthropic products in that market, while the ongoing legal battle in the U.S. may affect federal contracts and military‑adjacent deployments. Companies that depend on Anthropic for critical infrastructure should monitor the court case and consider fallback options.

Anthropic’s exposure of secret tracking code also damages its reputation as a privacy‑conscious, safety‑first company. The incident undercuts the moral high ground the company has tried to occupy, especially in contrast to more opaque competitors.

Meanwhile, the escalation of the U.S.–China AI conflict is accelerating a split in the ecosystem. U.S. firms face pressure to align with Washington’s hardline stance, but doing so makes them targets for Beijing’s regulatory retaliation. The landscape is becoming increasingly polarized, and companies that try to navigate both sides will need legal and geopolitical expertise.

💡 For business leaders, the lesson is clear: AI companies are now geopolitical actors. Their technology choices, lobbying positions, and even user‑monitoring practices can trigger state‑level responses. Diversifying model providers and preparing for regulatory fragmentation is no longer optional—it’s essential.

What to Watch Next

The legal battle between Anthropic and the Pentagon is far from resolved. The preliminary ruling by Judge Rita Lin is a temporary win, but the Pentagon’s push to classify Anthropic as a supply‑chain risk could resurface. Simultaneously, China’s MIIT advisory may be followed by more formal restrictions on Claude’s use in China, further shrinking Anthropic’s market.

On the competitive front, the adoption of Chinese models by cost‑conscious startups will continue to pressure Anthropic’s pricing strategy. The company may need to adjust its business model or accelerate the release of cheaper tiers to retain market share.

Anthropic’s dual‑front crisis is a warning for the entire AI industry. The era of operating under the radar is over. Every major AI company must now decide how to navigate the increasingly hostile and polarized landscape shaped by the U.S.–China technology rivalry.

Want automation like this for your business?

Get in touch and we'll show you exactly what's possible for your setup.