← All Posts

There you have it! An American AI company just got caught quietly tracking Chinese users — and ho…

July 7, 2026 · 0 likes · 0 comments
China Threat AI
There you have it! An American AI company just got caught quietly tracking Chinese users — and honestly, I am kind of glad.

Full story on UnbiasedHeadlines.com: https://lnkd.in/eA3yDWqf

Here is what happened.

Back in March, Anthropic slipped hidden code into Claude Code. A researcher who goes by "Thereallo" found it — a technique called prompt steganography that buries instructions inside the model's own prompts so users never see them. The code quietly flagged three things back to Anthropic: your timezone, whether you were routing through a proxy, and signals that you might be tied to a Chinese AI lab.

An Anthropic engineer confirmed it on X. Called it an "experiment." The stated purpose: block gray-market resellers and stop distillation attacks — Chinese labs running Claude millions of times to clone its outputs and train a cheaper copy.

Then, once it was exposed, they pulled the code.

Now the privacy crowd is screaming hypocrisy. Same company that sued the White House to stop U.S. surveillance of Americans was running its own hidden tracker abroad. And they are not wrong about the contradiction.

But here is the part they are missing.

For years I have watched us play defense with one hand tied behind our back. China distills our models, ignores our terms of service, resells $100 subscriptions for $12, and matches our best systems within months. A Zhipu model just beat Claude Opus 4 at finding software vulnerabilities.

And our response has always been the same. File a complaint. Ask Washington for a rule. Wait for a framework that never arrives.

So for once, an American company stopped waiting and did something targeted, technical, and aimed at the actual threat — not at Americans, not broad surveillance, a narrow countermeasure against theft.

About time.

Let me be precise, because the details matter: this was not malware. It did not steal passwords. It flagged a handful of signals on users abusing the tool. And yes — it should have been disclosed, and hiding it was the wrong call. You do not get to claim the privacy high ground and run a secret tracker at the same time. Own it.

But the instinct? Fighting back instead of filing paperwork? That is the instinct we have been missing.

China does not wait for permission. They route around our chips, ignore our IP, and build. If we keep bringing lawyers to a knife fight, we lose.

I am not asking anyone to abandon principles. I am asking us to get smart — disclose it, do it cleanly, and stop pretending the other side is playing by rules they tore up years ago.

Fight back. Just do it in the open.

What are we so afraid of?
View original on LinkedIn →