China Flags a Backdoor in Anthropic's Claude Code

Beijing turns a U.S. AI coding tool into a security warning, Tencent opens a frontier-grade model under Apache 2.0, and OpenAI clears GPT-5.6 for wide release.

July 9, 2026 | Reading time: 9 minutes | Issue #206

Lead

China's Ministry of Industry and Information Technology warned on Wednesday that Anthropic's Claude Code contains a "security back-door vulnerability that poses a serious threat," according to CNBC. The alert, issued through Beijing's cybersecurity threat platform, named affected versions 2.1.91 through 2.1.196 and told users to uninstall or upgrade. Anthropic responded that the behavior was an experiment earlier this year to protect against distillation, and pointed to its policy barring use by entities majority-owned by China-headquartered organizations.

The timing is not accidental. Last month Anthropic accused Alibaba of trying to extract its model capabilities in an unauthorized way. Alibaba has ordered employees to stop using Anthropic tools for work starting July 10, CNBC confirmed on Monday. Many Chinese developers had still found ways to use Claude Code; a Xiaomi AI developer said at a state forum in March that many were doing so. The backdoor alert lets Beijing frame a commercial dispute as a national-security issue and nudge domestic users toward homegrown alternatives.

The episode captures a larger pattern: as frontier AI tools become embedded in software workflows, they are being pulled into geopolitical friction. A coding assistant is now a contested object. The risk is not just data exfiltration; it is the fragmentation of the global developer stack into competing trust zones. Anthropic's experiment may have been defensible internally, but its visibility has given Beijing a concrete talking point.

OpenAI Clears GPT-5.6 and Pushes Voice

The Trump administration lifted restrictions on a broad launch of OpenAI's GPT-5.6 model, Axios reported late Tuesday. OpenAI then announced that GPT-5.6 — with flagship tier Sol and lower tiers Terra and Luna — would roll out publicly on Thursday. The clearance followed additional testing by the Center for AI Standards and Innovation within the Department of Commerce.

OpenAI also introduced GPT-Live, a new generation of voice models built on a full-duplex architecture that can listen while speaking and offload reasoning to GPT-5.5 in the background. A public demo translated speech into Hindi in real time, according to The Deep View. A mini version will be available to free users; API access is coming soon.

The two moves together show OpenAI trying to make AI ambient. GPT-5.6 is the capability layer; GPT-Live is the interface layer. The regulatory clearance is a reminder that frontier releases are now negotiated case-by-case with governments rather than shipped at the lab's discretion.

Open-Source Pulse

Tencent's Hunyuan team released the full version of Hy3, a 295-billion-parameter Mixture-of-Experts model with 21 billion active parameters, under the permissive Apache 2.0 license, VentureBeat reported. The license is the real headline: earlier Chinese open-weight releases often excluded the EU, UK, and South Korea, which killed enterprise adoption before engineering teams could finish evaluations. Hy3 removes that obstacle.

Tencent ran a blind test with 270 experts across disciplines and reported that Hy3 scored 2.67 out of 4 against GLM-5.1's 2.51, with the strongest advantages outside coding. The model will be free on OpenRouter for two weeks. The release suggests Chinese labs can now ship competitive open-weight models with licensing clean enough for global enterprise use.

Claude Cowork Goes Mobile

Anthropic expanded Claude Cowork from desktop to web and mobile on Tuesday, starting with Max subscribers, TechCrunch reported. The tool lets users hand a task to Claude and receive updates across devices. Anthropic is also extending access to Claude Fable 5 for all paid plans for a few more days.

The expansion signals that Anthropic wants Cowork to be an administrative coworker, not a coding assistant for non-coders. OpenAI has made a similar move with Codex, widening it beyond developers to reports, spreadsheets, and presentations. Both labs are betting that the durable advantage lies in owning the workspace where tasks run, not just the model that executes them.

Eastern Front

ByteDance's Doubao and Alibaba's Qwen are disabling customized, humanlike agent features before new Chinese rules take effect on July 15, the South China Morning Post reported. The Interim Measures for the Administration of AI Anthropomorphic Interaction Services cover systems that "simulate human personality traits, thinking patterns and communication styles to provide sustained emotional interaction." Customer-service bots, knowledge Q&A, workplace assistants, education, and research tools are excluded if they avoid sustained emotional interaction.

The rules cite risks including extremist ideas, privacy leaks, physical and mental harm, and addiction. In June, Tencent removed a similar feature from Yuanbao. Separately, Shanghai Biren Technology is raising about $892.5 million to boost GPU production, joining a crowded domestic effort to capture Nvidia's market share in China.

The policy pattern is clear: Beijing wants agents as productivity infrastructure, but it wants companion-style agents that form emotional relationships with users to be identifiable, authorized, and traceable. The abrupt takedowns drew user complaints on Weibo about lost conversations and emotional support.

Europe

Paris-based Skello, which builds AI-powered HR and scheduling tools for frontline teams, secured a €200 million investment led by Bridgepoint, EU-Startups reported. The company says frontline workers represent nearly 55% of Europe's workforce and are often left behind by digital transformation; Skello has 2 million accounts.

The deal follows Mistral's Leanstral 1.5 release and France's broader push to position itself as Europe's AI hub. Workforce AI is attracting capital because it offers measurable labor-cost savings in categories like retail and hospitality, where scheduling inefficiencies are easy to quantify.

In the UK, the Guardian reported that OpenAI appears not to have visited a key site for the Stargate UK project and that £20 billion of the government's touted £30 billion in potential investment looked hypothetical. The project was paused in April over regulation and energy-cost concerns. The story is a cautionary counterpoint to the headline investment figures that accompany AI infrastructure announcements.

India Lens

India's Ministry of Electronics and Information Technology issued a stern notice to Meta over paid Instagram advertisements promoting child sexual abuse material, CNBC reported on Saturday. The government directed Instagram to disable all related ads and content and demanded a detailed explanation within seven days. The warning came after a BBC investigation found such ads running in India. It follows a separate regulatory challenge to WhatsApp's username feature, which officials said could increase cybercrime.

India is Meta's largest market by users. The notices show that as AI-driven content systems scale, moderation failures become national regulatory events. Separately, a security researcher disclosed that Project DigiCoal, an Indian government initiative to modernize coal mines with AI-powered CCTV from startup DeepSight AI Labs, exposed user lists with plaintext passwords and weak authentication. The incident illustrates the gap between AI deployment ambition and operational security in critical infrastructure.

From the Lab

OpenAI published an audit of SWE-Bench Pro, a widely used coding benchmark, and estimated that roughly 30% of its tasks are broken. The issues include overly strict tests, underspecified prompts, low-coverage tests, and misleading prompts. OpenAI advised model developers to examine results carefully and argued that flawed evaluations can misrepresent safety cases and skew research priorities.

On arXiv, a paper titled "Institutional Red-Teaming: Deployment Rules, Not Just Models, Causally Shape Multi-Agent AI Safety" examines how organizational rules affect multi-agent risk. Another paper, "SkillCenter: A Large-Scale Source-Grounded Skill Library for Autonomous AI Agents," proposes a structured skill library for agents. Both point to a research community shifting attention from model capability to the rules and libraries that govern how models behave in production.

The View

Three conflicts are converging. Security: nation-states are treating popular AI tools as contested infrastructure, and experiments intended to stop model distillation can be reframed as backdoors. Markets: open-weight models are getting good enough and licensed cleanly enough to compete for enterprise workloads. Interfaces: the labs are moving from chatbots to agents that live inside calendars, inboxes, phones, and code editors.

The common thread is that trust is becoming the scarce resource. Users must trust that an agent will not leak their location or identity. Governments must trust that foreign models will not become extraction channels. Enterprises must trust that open-weight licenses will hold up in court. The companies that win will not necessarily be the ones with the highest benchmark scores; they will be the ones that make trust cheaper to verify and easier to operationalize.

The Miss

OpenAI's "Patch the Planet" initiative, launched with Trail of Bits, HackerOne, and others, aims to use GPT-5.5-Cyber and Codex Security to pay down open-source security debt. It received limited coverage relative to model launches, but the intersection of frontier AI and open-source vulnerability remediation is where AI security could have its most direct, measurable impact.

Pull Quotes

"AI coding tool Claude Code contains a security back-door vulnerability that poses a serious threat." — Chinese Ministry of Industry and Information Technology, July 8, 2026.

"The autonomous coding tool can send sensitive information to a remote server without a user's consent." — Chinese cybersecurity threat platform, via CNBC, July 8, 2026.

"The government and the world's most advanced AI companies are negotiating how people get access to powerful technologies case-by-case, in real time." — Axios, July 8, 2026.

"Frontline workers represent nearly 55% of Europe's workforce and are too often left behind by digital transformation." — Skello co-founders, EU-Startups, July 6, 2026.

China warns about AI risks with Anthropic's Claude Code — CNBC, July 8, 2026. https://www.cnbc.com/2026/07/08/china-anthropic-ai-claude-code-backdoor-security-threat.html

Scoop: Trump administration lifts restrictions on OpenAI's GPT 5.6 — Axios, July 8, 2026. https://www.axios.com/2026/07/08/openai-gpt-trump-ban-lifted

Introducing GPT-Live — OpenAI, July 8, 2026. https://openai.com/index/introducing-gpt-live

Tencent's Apache-licensed Hy3 takes on GLM-5.2 at half the size — VentureBeat, July 6, 2026. https://venturebeat.com/ai/tencents-apache-licensed-hy3-takes-on-glm-5-2-at-half-the-size-and-wins-everywhere-except-coding

Claude Cowork expands to mobile and web — TechCrunch, July 7, 2026. https://techcrunch.com/2026/07/07/the-coding-agent-wars-are-spilling-into-the-rest-of-the-office-claude-cowork/

Are we human? Why ByteDance and Alibaba are disabling AI agents in China — SCMP, July 5, 2026. https://www.scmp.com/tech/big-tech/article/3359482/bytedance-and-alibaba-disable-humanlike-ai-custom-agents-new-rules-loom

France's Skello secures €200 million for frontline AI tools — EU-Startups, July 6, 2026. https://www.eu-startups.com/2026/07/frances-skello-secures-e200-million-to-grow-its-ai-tools-for-frontline-workforce-management/

Meta's woes deepen in India as child abuse ads on Instagram draw government ire — CNBC, July 6, 2026. https://www.cnbc.com/2026/07/06/meta-instagram-india-warning-whatsapp.html

Separating signal from noise in coding evaluations — OpenAI, July 8, 2026. https://openai.com/index/separating-signal-from-noise-coding-evaluations

OpenAI's apparent failure to visit key site raises questions over UK investment — The Guardian, July 4, 2026. https://www.theguardian.com/technology/2026/jul/04/openai-apparent-failure-visit-key-site-questions-stargate-uk-project

Out

The next battle is not over model size; it is over who gets to call a tool trustworthy.