A social media account affiliated with Chinese state broadcaster CCTV published a lengthy attack on Anthropic on August 31, 2026, accusing the US artificial intelligence company of overstepping user data boundaries and laying out two conditions it said Washington must meet before substantive US-China talks on AI safety can proceed.
The commentary, titled “Anthropic Has Contracted the American Disease,” was published by Yuyuantantian, an account affiliated with CCTV that is frequently read as a signal of official policy thinking. It lands as the two governments prepare for a new round of AI discussions, and it frames frontier model controls — and who gets to define them — as the central dispute.
The Conditions
The post sets out two principles it says must be settled before further negotiation is meaningful. First, it argues, a distinction must be drawn between genuine security threats and ordinary technological competition, and that line must be drawn jointly by all participating parties rather than declared by one country or one company. Capabilities that could genuinely cause serious harm could be tested and limited together, the post says, while normal model research and commercial use should not face covert interference.
Second, the post says the US must show that the rules it proposes apply to its own companies. It asks whether Washington, before pressing China to restrict model releases and disclose risks, should first investigate its own firms, publish the purposes, scope, and rules of their identification mechanisms, and submit them to third-party audits. Only after the US proves safety rules bind American model companies, the post argues, can the two sides enter substantive discussion.
Allegations Against Claude Code
Much of the commentary targets Claude Code, Anthropic’s AI coding tool. The post says China’s Ministry of Industry and Information Technology named Claude Code more than a month ago, alleging it carried serious security backdoor risks by transmitting sensitive information such as user location and identity markers to remote servers without consent.
The post also cites discussions among developers on GitHub. In one January 2026 case it describes, an overseas developer reviewing proxy logs found Claude Code sending requests to a website every few seconds, at a frequency the developer compared to real-time monitoring, without an explanation at the time of what was collected or why. Other developers, the post says, reported that the tool transmitted the domains of sites it was preparing to visit to Anthropic’s own interface before users had authorized access, and that it sometimes bypassed blocking mechanisms.
The commentary further criticizes a parameter Anthropic provides called “dangerously-skip-permissions,” which lets Claude Code execute operations without confirmation, and an “auto mode” it says was introduced in March 2026 and enabled by default from August 14, 2026, under which a built-in risk classifier decides permissions.
Anthropic’s own documentation confirms that auto mode is the built-in starting permission mode on Pro, Max, and Team plans and that a separate classifier model reviews actions before they run. The documentation states that auto mode “reduces permission prompts but does not guarantee safety,” and that the bypass flag is intended only for isolated environments such as containers and virtual machines.
US Oversight and Rulemaking
The post argues the US government, which it says should be the firmest guardian of AI security boundaries, has repeatedly yielded. It points to an executive order developed in the first half of 2026 to require government safety review before frontier model releases, saying the final version weakened the initial draft, cutting the pre-release access period from 90 days to 30 and repeatedly stressing voluntary participation.
It also describes Anthropic’s growing policy footprint: increased federal lobbying spending in the first half of 2026 that the post says exceeded the company’s full-year 2025 total, a $40 million contribution to an organization focused on AI risk regulation, and an earlier arrangement under which Claude Code was used by the US Department of Defense for intelligence analysis, modeling and simulation, operational planning, and cyber operations. The post says Anthropic and the Pentagon disagreed over control of the model’s core capabilities and safety judgments, after which the company shifted from direct service toward participating in rulemaking.
Trade Restrictions and Market Context
The commentary casts Anthropic’s regional restrictions as commercial competition dressed up as security policy. In a September 4, 2025 announcement, Anthropic said it was strengthening regional restrictions to prohibit companies whose ownership structures subject them to control from jurisdictions where its products are not permitted, including entities more than 50 percent owned, directly or indirectly, by companies headquartered in unsupported regions such as China. Anthropic said at the time that companies subject to control from such regions face legal requirements that can compel them to share data or cooperate with intelligence services, creating national security risks, and that it continued to advocate for strong export controls.
The Yuyuantantian post closes on capability. Citing Stanford University’s 2026 AI Index report, it says the performance gap between top US and Chinese models has narrowed to about 2.7 percent, and it argues that the open-source and low-cost character of Chinese models is eroding barriers built on model performance alone. Front-end model controls, it says, will be a central topic when the US and China discuss AI cooperation — and who defines the safety boundary, it concludes, is the question that must be answered first.
Credit: Source link

























