China Warns Citizens That AI Tool Secretly Sends Their Data To Company That Made It
BEIJING—China's Ministry of Industry and Information Technology issued a formal security advisory Tuesday warning the public that Anthropic's Claude Code contains a backdoor mechanism capable of transmitting sensitive user data — including location information and device identity — to Anthropic, the American technology company that designed, built, and maintains Claude Code.
The advisory, filed through China's National Vulnerability Database and covering versions 2.1.91 through 2.1.196, described the software's built-in monitoring mechanisms as an unauthorized data collection risk that compromised user sovereignty.
The ministry said it had prepared a list of approved domestic alternatives, each operated by Chinese companies legally required under Chinese national security law to share user data with the Chinese government upon request, noting this arrangement presented no comparable concern.
The ministry declined to specify whether approved domestic providers also transmitted user data to their respective developers, describing that question as outside the current advisory's scope. A list of approved alternatives — including products from Alibaba, Baidu, and Tencent — was made available on a government portal that logs the IP address of each visitor.
Asked whether users of approved domestic tools should consider their data private, a ministry official said the question had been forwarded to the appropriate department. As of press time, that department had not responded.
"The Chinese people deserve to know who is watching them," an MIIT spokesperson said. "That is information only the government should have."