Skip to main content
Chinese AI lab computers display Claude AI tokens, highlighting gray market use for model training.

Editorial illustration for Chinese AI Labs Use Gray Market Claude Tokens to Train Models

Chinese Labs Bypass Claude Access via Gray Market Tokens

Chinese AI Labs Use Gray Market Claude Tokens to Train Models

4 min read

Anthropic checks phone numbers. It checks foreign credit cards and billing addresses. It bans companies more than 50 percent owned by entities in unsupported regions like China, and for some users it demands ID verification with a live selfie. By most measures, that makes Anthropic's access controls the tightest of any major AI provider operating in the Chinese market.

None of it is stopping the trade. Chinese developers are buying access to Claude for roughly a tenth of the listed price, routed through overseas proxy servers that operators call "transfer stations." These setups exploit free credits, swap out expensive models for cheaper substitutes without telling buyers, and pass requests through a chain of intermediaries that makes the whole system hard to trace back to any single source.

Zilan Qian, a researcher at the Oxford China Policy Lab, mapped out how this supply chain works in an analysis published by ChinaTalk. What she found raises questions well beyond pricing: about what geoblocking actually accomplishes, and about what else slips through the same cracks once a determined gray market gets built around a product designed to be locked down.

Qian concludes that the implications go far beyond the US-China tech rivalry. The methods a geoblocked developer uses to get access are structurally identical to those a bad actor could use to reach frontier models without being traced. When a request comes through a proxy, Anthropic initially sees the proxy's account and IP address, not the actual end user.

Why this matters Anthropic built Claude's access controls around the assumption that geography and pricing tiers could gate who trains on its outputs. A ten-percent gray market blows a hole in that assumption. If transfer stations can quietly swap in cheaper models and still deliver usable Claude-flavored outputs, then export controls and API restrictions are doing far less work than labs in San Francisco or Washington think they are.

For researchers and founders building on top of frontier APIs, the lesson is blunter: your outputs are a training resource for competitors the moment they're accessible at any price, official or not. It also complicates the distillation debate. Anthropic can write terms of service against it, but enforcement against thousands of individual proxy operators, students, and small companies is close to impossible.

We'd watch whether Anthropic tightens authentication at the account level rather than just the pricing level, and whether OpenAI or Google face the same gray-market arbitrage. This isn't a China-specific quirk. It's what happens when a valuable API meets a fragmented, price-sensitive global market.

Common Questions Answered

How are Chinese developers obtaining Claude access at a fraction of the listed price?

Chinese developers are purchasing Claude tokens through gray market channels that circumvent Anthropic's access controls. These methods involve routing requests through proxies and transfer stations that mask the actual end user's identity and location, allowing developers to bypass geographic restrictions and pricing tiers that Anthropic has implemented.

What access control measures has Anthropic implemented to restrict Claude usage in China?

Anthropic employs multiple verification methods including phone number checks, foreign credit card and billing address verification, bans on companies more than 50 percent owned by entities in unsupported regions like China, and ID verification with live selfies for some users. Despite these being the tightest access controls among major AI providers, they have proven ineffective at stopping the gray market trade.

Why do proxy-based access methods pose a security risk beyond just pricing concerns?

When requests come through proxies, Anthropic initially sees the proxy's account and IP address rather than the actual end user's identity. This structural anonymity means that bad actors could use identical methods to access frontier models without being traced, making it difficult to distinguish between legitimate gray market users and potentially malicious actors attempting unauthorized access.

What assumption about export controls has the gray market Claude trade undermined?

Anthropic built Claude's access controls on the assumption that geography and pricing tiers could effectively gate who trains on its outputs. The existence of a gray market selling Claude tokens at roughly one-tenth the listed price demonstrates that these export controls and API restrictions are doing far less work than labs in San Francisco or Washington believed they would.

LIVE12:26AI Agents Drive 14x Surge in Token Usage on OpenRouter