Blocked in China, Claude Still Finds a Way In

Anthropic doesn’t sell Claude in China. Chinese developers are using it anyway, and a whole resale industry has grown up to make that possible. The Information reports that Chinese token resellers have built a gray market around Anthropic’s models. They buy API access through accounts outside China and sell it back to local developers and companies, who use it through relay services.

This isn’t a niche workaround. It shows how much demand there is for frontier models, and it shows that geographic restrictions leak when the product is just an API key and a stream of tokens.

🔍 How the Gray Market Works

The basic mechanics of token reselling are simple, which is why it’s hard to stamp out:

  • Account sourcing: Resellers open or buy API accounts registered outside mainland China, often with foreign payment methods or business entities.
  • Relay infrastructure: They route requests from China through overseas servers, so the traffic looks like it comes from a supported region.
  • Repackaging: They sell access by the token, usually priced in yuan and paid through local apps like Alipay or WeChat Pay, with no foreign credit card or VPN setup needed.
  • Pooling: One upstream account can serve many downstream customers. That makes the traffic harder to trace and spreads out the risk of any single account getting banned.

For a Chinese startup that wants Claude’s coding ability, a reseller is the easiest way in. For the reseller, it’s an arbitrage business with real margins.

🧭 Why Anthropic Has the Most at Stake

Anthropic has taken the hardest line on China of any major US lab. In 2025 it updated its terms to bar companies majority-owned by Chinese entities from using its services, wherever those companies are based. It has also publicly accused Chinese AI labs of using fraudulent accounts to pull outputs from Claude at scale, a practice called distillation, where one model’s answers are used to train another.

That’s why a gray market matters more for Anthropic than for most vendors. Lost revenue is only part of the issue. Anthropic has three bigger exposures:

  1. Policy credibility. The company has pushed hard in Washington for tighter export controls on chips. If its own models are easy to buy in China through middlemen, its argument gets weaker.
  2. Distillation risk. Resold access is the same pipe a competitor could use to harvest training data. When you can’t see who the end customer is, you can’t stop that kind of use.
  3. Enforcement costs. Each banned account gets replaced. Fighting this means more spending on fraud detection, payment verification, and traffic analysis, and none of that ships product.

⚖️ The Other Side of the Argument

You can read this market another way. Chinese developers paying markup to reach Claude suggests that domestic models like DeepSeek, Qwen, and Kimi haven’t fully closed the gap on agentic coding and complex reasoning. That’s a competitive signal, whatever the policy implications.

There’s also a commercial tension. Anthropic gave up a large market on principle. Resellers are now serving that demand, and Anthropic gets a cut only indirectly through upstream accounts while carrying the reputational risk. Critics of strict access controls will say this is what happens when policy runs ahead of enforcement: the market just moves into the shadows.

🌐 The Bigger Picture

This connects to a trend across the AI industry. Frontier model access is turning into a geopolitical asset, and the controls built for physical goods like GPUs don’t carry over neatly to software. Chip smuggling at least involves shipping crates. Token reselling just needs an account and a server.

Watch for regulators to take notice. US policymakers have already floated know-your-customer requirements for cloud and AI providers. A well-documented gray market gives them a reason to make those rules mandatory instead of optional.

✅ What Practitioners Should Do

If you run a business that depends on AI APIs, this story has practical lessons:

  • Know your supply chain. If you’re buying model access through a third-party aggregator, check whether it’s an authorized reseller. Unauthorized access can get cut off without warning.
  • Expect stricter verification. Identity checks, business verification, and usage monitoring will probably get stricter across providers. Plan your onboarding with that in mind.
  • Think about data exposure. Any prompt that passes through an unofficial relay is visible to whoever runs it. Treat those services as untrusted.
  • If you’re an API vendor, watch for pooling. Unusual traffic patterns, shared payment methods, and very high-volume accounts with vague business descriptions are the usual red flags.

Anthropic can tighten its controls, but it can’t fully close a border that exists only in its terms of service. Expect this to become one of the main enforcement fights in AI over the next year. The full report is available at The Information.

Scroll to Top