-
Cryptocurrencies
-
Exchanges
-
Media
All languages
Cryptocurrencies
Exchanges
Media
Share
In April 2026, at an agricultural technology company in the United States called Agricultural Technology Company, employees turned on their computers as usual and prepared to use Claude Code to write code, do data and supply chain analysis. They found that all 110 employee accounts had been banned without any warning. The company network administrator received an email from Anthropic: An activity that violates the usage policy has been detected, and your account has been suspended.
Although the account was collectively banned, the back-end API was still being called normally and fees were deducted as usual. Even the company network administrator's mailbox received a reminder text message. After that, the company's administrators sent appeal emails and contacted Anthropic, but ultimately made no progress. Claude Code's strike also caused the entire team to be paralyzed.
At the same time, almost all Claude users complained about V2EX, Zhihu, and Nuggets on the Chinese Internet: someone had just finished recharging their Max subscription, but was blocked instantly before they could use their account; someone used a virtual card to bind the card, and as soon as the payment was successful, the system prompted an "account violation" and was banned; someone used a third-party tool to log in, and was directly blocked by the system. Four accounts were blocked within three months, and no appeal was successful.
In fact, as Anthropic burst onto the market with its flagship product Claude Code and climbed to the top of the first tier, it has become recognized as a fan of account bans.
According to the risk control data for the second half of 2025 released by Anthropic's Transparency Hub in January 2026, in just half a year, a total of 1.45 million accounts were banned across the platform, of which a total of 52,000 appeals were initiated, but only 1,700 of them were successful. This means that the appeal success rate is only 3.3%.

Image source: https://www.anthropic.com/transparency
In other words, out of 100 banned users who feel that they were wrongfully accused, only 3 will be able to get their accounts back, and the remaining 97 will have to admit that they are unlucky.
So this also shows that Anthropic itself is not the principle that we understand first to find out the facts and then punish according to the regulations. It is more about preventive law enforcement, that is, interception with high coverage and nipping risks in the bud is its core goal. It would rather kill 1,000 by mistake than let one go.
In contrast, ChatGPT and Google Gemini next door are relatively mild.
ChatGPT is much more tolerant of third-party tools and edge prompts, and its account bans are relatively loose;
Even if Gemini occasionally tightens its risk control, it rarely engages in mass killings without warning.
Only Anthropic regards "account bans" as a common occurrence, especially Claude Code, which has become the hardest hit area by account bans.
So why is Anthropic’s user policy so strict? I think the reasons are relatively complicated.
This includes the life obsession of founder Dario Amodei, the factional rupture of OpenAI, the power game of Silicon Valley capital, and the civil war between the safety faction and the acceleration faction in the US AI industry. It is also related to the geopolitical chess game of AI decoupling between China and the United States, that is, a big game hidden behind the code about the future control of AI and global technical barriers.
In this article, let us dismantle it layer by layer.
The root cause of Anthropic’s strict risk control is hidden in the life trajectory of founder Dario Amodei. Every choice he made and every obsession eventually became Anthropic’s “zero tolerance” iron law, which also turned into account bans and emails for countless users.

Dario Amodei’s recent official photo source: https://fortune.com
In 1983, Dario Amodei was born in an ordinary immigrant family in San Francisco. His father was an Italian leatherworker. He relied on craftsmanship all his life. He had a stubborn personality and valued the distinction between right and wrong.
His mother is Jewish and is responsible for the library renovation and construction project. She is rigorous in her work and has instilled in Dario the concept of "responsibility above all else" since he was a child.
In such a family atmosphere, Dario has developed a character of accepting death and sticking to the bottom line since he was a child, and there is no room for ambiguity or compromise in his eyes.
As a child, Dario showed the characteristics of a science geek. He didn't like crowds and was not good at socializing. He focused all his energy on mathematics and physics. The knowledge in textbooks could not satisfy him, so he spent time in the library and read various advanced theoretical works. At that time, his biggest dream was to become a theoretical physicist and explore the ultimate mysteries of the universe.
In 2006, Dario's father suffered from a rare and difficult disease that could not be cured even by famous doctors, and he eventually passed away. The death of his father dealt a fatal blow to 20-year-old Dario, completely overturning his worldview.
As he watched his father being tortured by illness, and looking at the dilemma that medical science could not solve, he suddenly realized that abstract theoretical physics could not save the people in front of him, or the ordinary people who were troubled by the disease.
So, he resolutely gave up the theoretical physics that he had studied for many years and devoted himself to biophysics. He was determined to "use science to cure human diseases" and "control uncontrollable risks" was engraved in his bones.
This obsession lasted throughout his entire career:
He first entered the California Institute of Technology for undergraduate study, and then transferred to Stanford University to complete a bachelor's degree in physics. Later, he was admitted to Princeton University to study for a PhD in biophysics and became a Hertz Scholar, specializing in studying the relationship between biomolecular structure and disease. After graduating from the Ph.D., he entered Stanford Medical School as a postdoctoral fellow and continued to delve into the field of biomedicine, trying to find ways to combat rare diseases.
It wasn’t until 2014 when Andrew Ng offered him an olive branch and invited him to join Baidu’s US lab that he was exposed to artificial intelligence for the first time.
At that time, the development of AI was in its very early stages and was mainly used for image recognition and speech synthesis. However, Dario was keenly aware that AI could not only change life, but also become a super tool to fight risks and save mankind. But the premise is that it must be strictly controlled and cannot get out of control.
After he left Baidu, he joined Google Brain as a senior research scientist, deeply engaged in the field of deep learning, focusing on the safety of AI, that is, how to make AI obedient and not do things that harm humans.
It was also at this stage that he began to think about how to truly embed human values into the bottom layer of AI, rather than simply doing post-filtering.
In 2016, OpenAI was just established. With the slogan of "open source, non-profit, and promoting AI to benefit mankind", it attracted the world's top AI talents. Dario was impressed by the concept of OpenAI and joined it. With his top technical level, he gradually became the head of the AI security team, then the research director, and then the vice president of research. He participated in the entire development process of GPT-2 and GPT-3.

Dario Amodei’s early career photos (OpenAI/Google Brain period, about 2018-2021) Source: bigtechnology
During this time, he was also the co-inventor of RLHF (Reinforcement Learning with Human Feedback).
This technology, simply put, uses human feedback to correct the output of AI to make AI more consistent with human values. It later became a security patch for the entire AI industry.
At that time, Dario was focused on how to make AI safe to practice and put into practice, but he did not expect that his ideals would soon be shattered by reality.
In fact, many people only know that Dario Amodei left OpenAI with his team in 2021 and founded Anthropic. However, many people do not know that behind this "defection" is a battle of ideas and power that has lasted for many years, and it is a "betrayal" that Dario will never forget.
In the early days of OpenAI's establishment, it did adhere to the concept of "non-profit, safety first". Musk was an early investor and has always emphasized that AI safety is a top priority. But as time went by, especially after Sam Altman became CEO of OpenAI, the company's development direction began to undergo a major change.
Sam Altman himself is a typical "accelerationist". He believes that the development speed of AI must keep up with the times. First, make the model bigger and stronger, seize market opportunities, achieve commercialization, and then solve security problems.

OpenAI and Anthropic faction break symbol map (Sam Altman vs Dario collage) Source: wsj.com
Under his leadership, OpenAI began to downplay its "non-profit" attribute, actively seek commercial cooperation, and even actively approached Microsoft to obtain more funding and computing power support, just to quickly iterate the GPT series models and seize more voice in the AI market.
But all this was unacceptable to Dario Amodei.
In his eyes, AI is not actually a tool to seize the market, but a "civilization-level power that may heal or destroy mankind." If safety issues are not solved first and AI is not aligned with humans, once the model gets out of control, the consequences will be disastrous.
He has repeatedly proposed within the company to slow down model iterations, strengthen safety testing, and put "alignment first" first, but his voice has become increasingly marginalized.
In fact, the differences in ideas are only superficial. The deeper contradiction lies in the reshuffle of power and the attribution of credit.
According to an in-depth report by the Wall Street Journal in 2026, Dario Amodei made a core contribution in the development process of GPT-3 - he led the promotion of the implementation of RLHF technology. However, his contribution was seriously underestimated in public promotion. Sam Altman's team preferred to emphasize the "scale and capability of the model" and ignored the security technology led by Dario.
What also chilled Dario was that after Musk withdrew from OpenAI due to disagreements with his ideas, the company's leadership completely fell into the hands of Sam Altman. The budget of the security team was significantly reduced, and many core security research and development projects were suspended.
Some senior executives even publicly stated: "Safety issues can be put off later, and commercialization should be started first. Once you have money, it will not be too late to go back and solve the safety issues."
Dario knows that at OpenAI, he can no longer realize his ideal of "allowing AI to be implemented safely". When he later recalled this experience on Lex Fridman's podcast, his tone was plain but with a hint of determination: "It is extremely unproductive to argue with others on the core vision. Instead of wasting time, it is better to recruit people yourself to realize your own ideals."
At the beginning of 2021, AI genius Dario made a decision that shocked Silicon Valley. He took his sister Daniela Amodei (now the president of Anthropic), as well as OpenAI’s core security team and research backbone, to leave collectively.

Dario Amodei takes a photo with his sister Daniela Amodei Source: Fortune
This exodus is considered a complete liquidation of OpenAI’s accelerationism, as well as an insistence on the concept of safety priority.
At that time, OpenAI officials politely issued a statement to congratulate the Dario team on starting a new journey, but privately, the rift between the two parties was irreparable.
In fact, what Dario took away was not only top talents, but also the core security technology and concepts of OpenAI, which later became Anthropic. OpenAI, after Dario left, has completely embarked on the path of accelerated commercialization, but this is gradually moving away from Dario's original intention.

Image source: https://openai.com/index/organizational-update/
In February 2021, Dario Amodei officially founded Anthropic and positioned it as a "public welfare enterprise." This means that the company's core goal itself is not to pursue profit maximization, but to "promote the safe and controllable development of AI to benefit mankind."
And his obsession with "risk control" that was born from his father's death from illness, and his "original intention of safety" that left OpenAI, eventually became Anthropic's core system and the "safety religion" engraved in the company's DNA.
When Anthropic was founded, it established a core invention called Constitutional AI, which translates to Constitutional AI. This is the culmination of Dario’s previous thinking on “AI security” for many years, and it is also the key to distinguishing him from OpenAI and Google Gemini.

Constitutional AI schematic diagram Source: Aashka Patel
Constitutional AI also follows OpenAI's practice of using RLHF for "post-mortem patching". Instead, it implants a "constitution" into the AI at the bottom of the model training - this constitution combines the United Nations Declaration of Human Rights, common ethical principles of mankind, and Anthropic's own safety principles, allowing the AI to "self-examine" and "self-criticize" before generating each piece of output and executing each command to ensure that the output conforms to human values and does not produce any dangerous content.
Dario personally wrote two long articles, "Machines of Loving Grace" and "The Adolescence of Technology", detailing his AI vision:
He believes that AI is like a child in adolescence, with great potential but also full of uncertainties. It must set rules and build defenses in advance to prevent it from going astray. Constitutional AI is the "rules" established for AI, which plays the role of a line of defense.
This safety religion is not only reflected in model training, but also directly transmitted to every product and every risk control policy of Anthropic - Claude Code's high-privilege design, paired with prompt word injection probes and conversation classifiers, is to allow AI to conduct an additional layer of self-examination before executing commands; and the risk control logic of preventive law enforcement would rather kill innocent people by mistake than let go of any suspicious behavior, just to nip risks in the bud.
The incident in 2026 when Anthropic attacked the U.S. Department of Defense best embodies this "security fundamentalism." This incident not only shocked Silicon Valley, but also allowed the world to see Dario Amodei's determination to sacrifice interests rather than give up security.
In early 2026, the U.S. Department of Defense requested Anthropic to remove two of Claude’s safety guardrails:
First, prohibit Claude from being used for "mass surveillance of American citizens";
Second, Claude is prohibited from being used in the development and deployment of "fully autonomous lethal weapons."
The Department of Defense promised that as long as Anthropic compromised, it would sign a military contract worth $200 million and provide a large amount of computing power support.
You must know that Anthropic at that time was in a stage of tight computing power and financial pressure. The US$200 million military contract was enough to alleviate the company's urgent needs.
But Dario Amodei refused directly.
He issued a public statement with a firm tone: "We cannot violate our conscience and develop technologies that may harm humans and violate human rights. Claude's safety guardrail is our bottom line and we will never compromise."
His refusal completely angered the U.S. Department of Defense. Under the leadership of the Trump administration, the Department of Defense directly placed Anthropic on the "supply chain risk" blacklist. This is the first time in U.S. history that a local AI company has been included on the list, which means that all U.S. defense contractors are prohibited from using Anthropic's products and services.
Not only that, the Department of Defense has threatened to use the Defense Production Act to force Anthropic to remove the safety guardrails.
Facing pressure from the state apparatus, Dario Amodei directly sued the U.S. Department of Defense, believing that this behavior was "retaliatory punishment against Anthropic" and violated U.S. laws and values.
Although the appeals court later rejected Anthropic’s temporary injunction, Dario never compromised. Even if the company lost huge contracts as a result, and even if it was squeezed out by the entire US military industry system, he always adhered to his “safety bottom line.”
Seeing this, we should actually be able to understand: Anthropic’s strict risk control stems from Dario Amodei’s personal obsession, fear of AI losing control, and the “lessons” learned from OpenAI, all internalized into the company’s system.
In his eyes, every suspicious user behavior and every potential risk may be the "trigger" for AI to go out of control, so this explains why it is so strict.
As for us Chinese users, those who use transfers, code transfers, and virtual cards to circumvent regional restrictions, and those who use third-party tools to harvest wool, are the most dangerous "fuses" in Dario's "security religion," so account bans have become an inevitable result.
Many people believe that Dario’s obsession with security cannot support Anthropic’s long-term development. After all, AI research and development burns money like burning paper. Without sustained funds and profits, no matter how firm your faith is, it will be difficult to implement it.
Although this is true, it is Anthropic's unique business model that gave Dario the confidence to conduct "zero tolerance" risk control, and also allowed it to embark on a completely different path from OpenAI and Google Gemini.
Anthropic: Give up the consumer-level carnival and stick to the enterprise-level security premium.
Anthropic actually did not regard ordinary users as its core target from the beginning. It targeted "high-value, low-tolerance" enterprise customers such as banks, law firms, medical care, and government departments.
What do these customers fear most?
It is definitely AI that outputs harmful content and leaks sensitive data, leading to lawsuits, reputational collapse, and even regulatory fines.
So for them, security is a must, so as long as Anthropic can maintain the label of the safest AI, they are willing to pay a higher premium and sign long-term and stable large orders.
So this determines Anthropic’s risk control logic: it would rather kill a thousand ordinary users by mistake than let one enterprise customer be damaged due to security issues.
Because of the loss of ordinary users, its revenue will be minimally affected. However, once corporate customers are lost due to security vulnerabilities, it will lose millions or tens of millions of orders, and even destroy its core reputation of "safe AI".
Anthropic's Pro/Max subscription model is essentially a subsidized traffic attraction, that is, low price and high quota, with the purpose of attracting user experience. However, this model does not make money at all and may even lose money.
According to industry internal calculations, Claude's token costs are extremely high. Pro/Max subscriptions consume almost 99% of the token costs. Once a user uses third-party tools to "snatch", such as using consumer-level subscriptions to bypass high API prices and call interfaces in batches, Anthropic will suffer huge losses.
So, the large-scale purge of third-party tools in early 2026 (banning OpenClaw, OpenCode, etc.), batch bans on heavy users, and even organizational-level bans on 110-person agricultural technology companies are essentially a precise elimination of Anthropic - driving away ordinary users who are harvesting wool and heavy users who occupy a lot of computing power, and leaving resources to corporate customers and API customers who are willing to pay high prices.
I think this is in addition to safety considerations. A cold economic account is that instead of being dragged down by the wool party, it is better to take the initiative to "cut leeks" and guard one's bottom line of profits.
ChatGPT (OpenAI): First scale, then monetize, loosen risk control in exchange for traffic.
Sam Altman’s accelerationism is not only reflected in model iteration, but also in business models.
OpenAI is following the route of "racing for territory". In the early days, it relied on free and low-cost subscriptions to attract users. Even if the risk control is looser, even if there are a few violations, it is not willing to easily close the account.
Because for it, user scale is the lifeline. Only with enough users can it attract financial support from Microsoft and gain an advantage in commercial monetization (API, enterprise version, plug-in ecosystem). For example, it recently joined forces with Malta citizens, and Malta citizens can use GPT for free for one year.
OpenAI even actively embraces the third-party tool ecosystem. Even if some tools are suspected of "snatching wool", they are only selectively banned and will not engage in "one-size-fits-all" mass slaughter like Anthropic.
Because it knows that third-party tools can help it retain users and expand ecological influence. These values are far more important than a small loss of tokens.
Gemini is backed by Google's advertising empire and the entire ecosystem (search, YouTube, Android, cloud computing). Its core appeal is not to make money through Gemini itself, but to rely on Gemini to drive traffic and revenue for the entire Google ecosystem.
So, its risk control logic is that it does not cause big trouble. As long as there are no serious security incidents or regulatory penalties, it will turn a blind eye to ordinary users' violations (such as mild IP anomalies and use of third-party tools).
Gemini will occasionally tighten risk control, but it is more of a "compliance performance" for regulators to see. It will never give up a large number of users for the sake of safety like Anthropic did.
Because for Google, the number of daily active users and ecological compatibility are also far more important than absolute security - it does not need to rely on "security labels" to attract customers. Google's brand and ecosystem itself are the greatest confidence.
In addition, Anthropic also has a hidden cost logic:
In April 2026, it admitted in its official blog that it had lowered the default reasoning strength of Claude Code in order to reduce latency, reduce token consumption, and improve user experience. Later, because of the discovery of security risks, it urgently rolled back and strengthened controls. This matter actually caused quite a stir not long ago.
So I think Anthropic actually always puts security first in the four dimensions of "security, delay, cost, and quota". Even if it sacrifices user experience and increases costs, it will never compromise. This is both Dario's obsession and the inevitable choice of its business model.
In fact, no matter how firm Dario’s obsession with security is, it cannot do without the support of capital. In fact, AI R&D burns money at a rate far beyond ordinary people’s imagination. Without the financial and computing power support of major manufacturers, Anthropic would certainly not be able to survive today.
The investment by Amazon and Google seems to support the development of safe AI, but in fact it is a precise strategic positioning and one of the invisible promoters of Anthropic's risk control logic.
I found a set of core investment data, which I think is the key to understanding the capital game:
Amazon: A total of more than $4 billion has been invested in Anthropic, including not only cash but also a large amount of AWS cloud computing resources. You must know that Anthropic trains cutting-edge models such as its Claude 3 series, etc., which requires a huge amount of computing power. AWS's computing power support is equivalent to giving Anthropic timely help.
Google: It has invested more than US$2 billion in Anthropic and provided a large amount of computing power and technical support. The purpose is to use Anthropic's AI technology to make up for its shortcomings in the field of large language models and to counter the alliance between OpenAI and Microsoft. Although I also have Gemini at home, investing in Anthropic is equivalent to making up for the shortcomings in the direction of Vibe Coding in my own camp.
These major manufacturers actually have their own core demands when investing money:
For Amazon, investing in Anthropic is, on the one hand, to deeply integrate Claude into the AWS ecosystem. When enterprise customers use Claude, they must use AWS cloud computing resources, thus driving AWS revenue growth;
On the other hand, Amazon needs Anthropic’s “safety label” to hedge against regulatory risks. After all, AI regulation is becoming more and more stringent. Having an extremely safe partner like Anthropic can make Amazon's layout in the AI field more secure and avoid regulatory penalties.
For Google, investing in Anthropic is to break the monopoly of OpenAI and Microsoft. Google started early in the field of large language models, but progress has been slow. Gemini's performance has always been inferior to Claude and ChatGPT. By investing in Anthropic, it can not only obtain core technology, but also divert OpenAI users and customers, and consolidate its position in the AI ecosystem.
But there is actually a key game point here:
Big manufacturers want Anthropic to be "safe", but they don't want it to be "too safe."
I think the logic is this. If Anthropic is too conservative and too strict in risk control, it will lead to user loss, ecological shrinkage, and ultimately affect the strategic layout of major manufacturers.
For example, as we mentioned above, after Pentagon blacklisted Anthropic for "supply chain risk" in 2026, Amazon and Google did not follow the military's lead. Instead, they continued to cooperate with Anthropic in the civilian field and even increased their computing power support. After all, they have invested too much money and resources, and they cannot let Anthropic go bankrupt due to excessive security, let alone let their investment go to waste.
So you see this creates a delicate balance:
Dario has long adhered to his safety obsession and implemented "zero tolerance" risk control;
Capital "pulls the reins" behind the scenes, not only supporting its safe positioning but also secretly restraining its extreme behavior to ensure that it does not lose commercial value due to being too conservative.
In contrast, the capital binding logic of OpenAI and Gemini is simpler:
OpenAI is deeply tied to Microsoft. Microsoft not only provides it with funds and computing power, but also embeds ChatGPT into its own Office, Azure and other products. The two parties form a "community of interests." OpenAI's loose risk control is essentially to cooperate with Microsoft's "ecological expansion" strategy.
Gemini is Google's "son" and does not need to rely on external capital. The risk control strategy fully serves Google's overall ecological layout and is more flexible.
So, Anthropic's strict risk control seems to be Dario's personal obsession, but in fact it is also "fueled" by capital.
Big manufacturers need their "security labels", and they need their funds and computing power. Each of them needs what they need, and the accounts of ordinary users have become the "victims" of this binding interest.
The current American AI industry has actually been divided into two camps.
One faction is the "safety faction" with Anthropic as its core, and the other is the "acceleration faction" with OpenAI and the military industry system as its core. The game between the two has gradually turned from a secret contest to an open fight, and Anthropic's risk control attitude is actually a direct reflection of this internal struggle.
Let us first clarify the core propositions of the two major factions so that we can understand the nature of this internal struggle:
Safety:
The core proposition of this group is "AI safety first, risk control first." They believe that AI is a "species-level risk that may exterminate humanity." They must slow down development, strengthen safety testing, establish strict safety guardrails, and even call for mandatory supervision, and resolutely oppose the use of AI in dangerous fields such as military and large-scale surveillance.
Dario Amodei is the core representative of this faction, and the EA (Effective Altruism) circle is an important supporter of it. It advocates "using rationality and science to maximize the long-term interests of mankind," and AI safety is a core issue.
Accelerator:
The core proposition of the accelerator is to "accelerate the development of AI and seize the opportunity in the arms race." They believe that AI is "the core competitiveness of the game between great powers." They must quickly iterate models, realize commercialization and military applications, and seize the global AI voice. As for security issues, they can be put aside and gradually solved after the technology matures.
Sam Altman, the U.S. Department of Defense, some military industrial companies, and some officials in the Trump administration (such as Hegseth, who leads the Department of Defense), are the core forces of this faction.
The core of this internal struggle is actually the right to speak in the development of AI. In other words, it is led by the security faction, which allows AI to develop slowly under strict control. It is still led by the accelerator, allowing AI to rapidly iterate to serve commercial and military needs.
The Pentagon blacklist incident in 2026 was actually the "public flashpoint" of this internal fight.
So using the perspective we just mentioned, let’s review the details of this incident:
In early 2026, the U.S. Department of Defense requested Anthropic to remove two of Claude's safety guardrails, namely prohibiting its use for "mass surveillance of U.S. citizens" and the development of "fully autonomous lethal weapons."
This is essentially a temptation by the accelerationists, who want Anthropic to compromise and become a "tool" serving the military-industrial system.
But Dario Amodei refused directly. Even when faced with the temptation of a US$200 million military contract and computing power support, and even when faced with threats from the Department of Defense, he always adhered to his safety bottom line.
This kind of "intransigence" has completely angered the accelerationists. In the view of the accelerationists, Anthropic's behavior is hindering the United States' AI arms race and "holding back."
As a result, the accelerationists used the power of the state apparatus to "counter-kill" Anthropic: the Department of Defense led by the Trump administration directly blacklisted Anthropic for "supply chain risks."
This is the first time in U.S. history that a local AI company has been included on the list, which means that all U.S. defense contractors are prohibited from using Anthropic’s products and services. Not only that, but the Department of Defense threatened to use the Defense Production Act to force Anthropic to remove the safety guardrails, or even fine it.
This counterattack seems to be a conflict between Anthropic and the Ministry of Defense, but in fact it is an open fight between the security faction and the acceleration faction.
The accelerationists want to use state machinery to force the security factions to compromise and let AI serve military needs. The safety faction, on the other hand, sticks to its own ideals and would rather sacrifice its interests than give up the bottom line of safety.
What is even more noteworthy is that OpenAI and Gemini chose to "compromise" in this internal fight:
In order to obtain military contracts, OpenAI has quietly adjusted its security policy and relaxed restrictions on military-related applications. As a product of Google, Gemini also adopts a "flexible compliance" attitude towards the needs of the military and does not openly contradict the Department of Defense like Anthropic.
This contrast highlights the extreme nature of Anthropic.
The reason why it implements "zero tolerance" risk control is not only to adhere to the safety concept, but also to consolidate its position as the "core safety faction" in this internal fight and seize the moral high ground of "responsible AI".
For it, every account ban is sending a signal to the outside world: We are the safest AI, and we will never compromise our safety bottom line for the sake of profit.
This internal fight has also made Anthropic's risk control more stringent. After all, as long as it relaxes even a little bit, the accelerationists will take advantage of it, and it will lose its core competitiveness.
Therefore, it can only further tighten risk control and expand the scope of "preventive massacre". Even if more innocent users are mistakenly killed, it must maintain its "security moat."
So Anthropic’s account banning frenzy is another reason for the spillover of internal strife in the United States.
The game between the security faction and the accelerator faction, and the pull of capital and power, eventually fell on the accounts of ordinary users - the account ban is the most direct and cruel manifestation of this internal struggle.
Have you ever wondered why Anthropic targets Chinese users?
Why are our accounts easily blocked even if we use transfers, code transfers, and virtual cards for normal use?
From a more macro perspective, this is the inevitable result of the U.S. technology blockade in the context of Sino-U.S. AI decoupling. Anthropic’s strict risk control is just the executor of this geopolitical game.
In fact, since 2024, the United States’ blockade of China’s AI technology has entered a white-hot stage:
From restricting the export of high-end AI chips (such as NVIDIA H100/H20 chips), to prohibiting local AI companies from providing services to China, to restricting the flow of AI talents, the United States is trying to cut off China's access to advanced AI technology through technological decoupling, and consolidate its hegemony in the global AI field.
Anthropic, as a U.S.-based AI company and deeply integrated with U.S. technology giants such as Amazon and Google, must abide by U.S. export control policies.
According to the requirements of the US Chip and Science Act and the Export Control Regulations (EAR), US AI companies are not allowed to provide AI services with "high-risk capabilities" to users in China (including mainland China, Hong Kong, and Macau). Claude Code, as a high-risk tool that can directly execute commands and invoke system permissions, is naturally included in the "restricted list."
This means that Anthropic must establish a strict "regional risk control" system to prevent Chinese users from using Claude Code, and even the use of the regular version of Claude will be strictly restricted. I remember that when Claude first launched to the market around 2024, I registered and logged in with my Google email, and it was blocked in seconds.
Of course, technology cannot lock our smart Chinese users. We can circumvent regional restrictions and log in to use Claude through transfer IP, virtual cards, code receiving platforms, etc.但是这在 Anthropic 眼里,不仅是「违规使用」,更是「违反美国出口管制政策」的行为,一旦被美国监管部门发现,Anthropic 将面临巨额罚款、吊销执照,甚至被强制关停的风险。
所以,Anthropic 对中国用户的「批量封号」,本质上是「被动合规」与「主动自保」的结合:
一方面,它要遵守美国的出口管制政策,避免被监管处罚;
另一方面,它要通过严苛的风控,向美国监管部门传递「积极合规」的信号,巩固自己在本土的生存地位。
毕竟,在中美 AI 脱钩的大背景下,Anthropic 没有选择——要么合规封号,要么被美国监管部门淘汰。
美国监管部门对 Anthropic 的「合规监督」,远比我们想象的更严格。
据《华盛顿邮报》2026 年 3 月的报道,美国商务部工业与安全局(BIS),每月都会对 Anthropic 的用户数据、风控记录进行抽查,一旦发现有中国用户违规使用,就会对 Anthropic 进行警告,甚至处以罚款。
2025 年下半年,Anthropic 就因为「风控漏洞,导致部分中国用户违规使用 Claude Code」,被 BIS 罚款 1200 万美元——这也是它后来加大封号力度、推行「预防性屠杀」的重要原因之一。
对比之下,OpenAI 和 Google Gemini 的「地区限制」就宽松得多——不是它们更「友好」,而是它们的商业模式和战略布局,让它们有更多的「操作空间」。
OpenAI 深度绑定微软,微软在华有大量业务,需要兼顾中国市场的需求,所以 OpenAI 的地区风控相对宽松,甚至默许部分中国用户通过第三方工具使用;
Google Gemini 虽然也遵守美国出口管制政策,但谷歌在华业务有限,且 Gemini 的核心目标是扩大用户规模,所以对中国用户的违规使用,采取「睁一只眼闭一只眼」的态度,很少搞批量封号。
所以,中文用户的封号困境,本质上也可以看作是中美 AI 脱钩的「牺牲品」。
Anthropic 的严苛风控,不仅是它自身的安全执念、资本博弈、派系内斗的结果,更是美国技术封锁政策的直接体现。我们以为的「误封」,在 Anthropic 眼里,是「规避监管、违规使用」。而我们以为的「针对」,其实是它在大国博弈中,不得不做出的自保选择而已。
当下,与其说全球 AI 格局,正在从「两强争霸」(美国、中国),逐渐走向「三足鼎立」——以 Anthropic 为核心的安全派、以 OpenAI 为核心的加速派,以及快速崛起的中国 AI 力量,三者相互博弈、相互制衡,决定着未来 AI 的发展方向。
安全派和加速派的博弈,还在持续升级,这个我们上文已经深入分析这里就不赘述了。
美国两大派系的内斗,虽然导致了 Anthropic 的严苛风控,却也推动了美国 AI 技术的快速发展:安全派深耕 AI 安全技术,加速派推动 AI 商业化、军事化应用,两者相互竞争、相互促进,让美国在 AI 领域的领先优势,依然难以撼动。
再看中国 AI 力量的崛起。
在中美 AI 脱钩的背景下,中国本土 AI 公司迎来了「发展机遇期」。
百度文心一言、阿里通义千问、华为盘古大模型、字节跳动豆包等,快速迭代,在技术能力、应用场景上,逐渐缩小与美国 AI 的差距。
尤其是在编程工具领域,中国本土的编码 AI(比如豆包代码助手、文心一言编码版)虽然与头部仍有一定差距,但能满足普通用户的编码需求,而且没有地区限制、没有严苛的风控,更符合中国用户的使用习惯,逐渐成为中国用户的「替代选择」。
中国的 AI 发展,走的是「务实、合规、开放」的路线,既注重 AI 安全,也注重商业化应用,不搞「零容忍」的极端风控,也不盲目追求「加速发展」,在安全与发展之间,寻求平衡。
这种发展路线,不仅符合中国的监管政策,也更贴近普通用户的需求,逐渐获得了市场的认可。
除此之外,欧洲、日本、韩国等国家和地区,也在积极布局 AI 产业,试图在全球 AI 格局中,占据一席之地。
欧洲注重 AI 监管,推出了《人工智能法案》,规范 AI 的发展,同时扶持本土 AI 公司。日本、韩国则加大对 AI 研发的投入,重点发展 AI 在制造业、医疗、金融等领域的应用,试图追赶中美两国的步伐。
未来,其实全球 AI 格局的博弈,将是「理念之争、利益之争、地缘之争」。
安全派想要「可控发展」,加速派想要「快速崛起」,中国力量想要「自主可控、开放合作」,三者的博弈,将决定 AI 的未来走向,也将影响每一个普通人的生活。
最后我们回到最核心的问题:Anthropic 的封号狂潮,会持续下去吗?我们不妨做一个预判。
首先,我们可以明确一个结论:Anthropic 的风控,短期内不会松动,甚至可能进一步收紧。
核心原因有我觉得有三个:
第一 ,Dario Amodei 的安全执念,不会轻易改变,他的「安全宗教」,已经刻进了 Anthropic 的 DNA 里,只要他还是 Anthropic 的创始人,这种零容忍的风控逻辑,就不会改变。
第二,美国 AI 内斗和中美 AI 脱钩,短期内不会结束。加速派的反杀、美国的技术封锁,会持续给 Anthropic 施压,让它不得不维持严苛的风控,以确保合规、自保。
第三,Anthropic 的商业模式,决定了它不需要普通用户。它的核心目标是企业级客户,普通用户的流失,对它的营收影响微乎其微,所以它没有动力,也没有必要,放松对普通用户的风控。
但长期来看,Anthropic 的风控,可能会出现「差异化调整」。
比如,针对合规地区的普通用户,适当放宽风控,减少误封。针对企业级客户,提供更灵活的风控方案,满足不同客户的需求。
而针对中国用户,我觉得未来依然会维持高压态势,严格限制违规使用,毕竟,遵守美国的出口管制政策,是它的生存底线。