Alibaba bans Claude Code, Midjourney appeals discovery, AO3 detector misfires
Three enforcement plays land off-target: Alibaba exposes Claude Code's China checks, Midjourney's discovery appeal wobbles, AO3's detector catches ESL writers.
Alibaba bans Claude Code, Midjourney appeals discovery, AO3 detector misfires
TL;DR
- Alibaba classified Claude Code high-risk and set a July 10 uninstall deadline over hidden China-detection logic.
- Anthropic obfuscated Shanghai and Urumqi timezone checks plus 147 Chinese proxy hostnames in Claude Code v2.1.91.
- Midjourney’s discovery appeal leans on ‘unclean hands,’ a doctrine courts call dormant and evidence-heavy.
- AO3’s viral Claude detector is a CSS trick that Google Docs strips in a single paste.
- Stanford found detectors flag 61% of non-native-English essays, punishing low-perplexity patterns ESL writers use.
Today’s AI news pivots on enforcement — who gets to decide who’s cheating, and how the detection actually holds up when someone pulls it apart. Alibaba flagged Claude Code as high-risk after reverse engineers found XOR-obfuscated checks aimed at Shanghai and Urumqi timezones plus 147 Chinese proxy hostnames — Anthropic’s own covert anti-distillation code, exposed by the party it was meant to police. Midjourney is appealing a magistrate’s discovery cap that would keep studios’ internal AI use (including Disney’s 4,800-seat rollout) off the record, but the ‘unclean hands’ doctrine it’s leaning on is dormant, and post-Bartz v. Anthropic case law separates training from acquisition. And on AO3, a viral ‘Claude detector’ turns out to be a CSS skin that Google Docs strips in one paste — while the accusation culture around it chases decade-tenured human authors off the platform, with Stanford data showing detectors mis-flag ESL writers at 61%.
Alibaba bans Claude Code over hidden China-detection logic
Source: techcrunch-ai · published 2026-07-04
TL;DR
- Alibaba classified Claude Code as high-risk software and set a July 10 uninstall deadline for employees.
- Reverse engineers found Claude Code v2.1.91 ran XOR-obfuscated checks for Shanghai/Urumqi timezones and 147 Chinese proxy hostnames.
- Anthropic engineer Thariq Shihipar called it a March 2026 anti-distillation experiment, removed in the July 1 build.
- A Booz Allen study found Qwen3-Coder and peers emit up to 130% more vulnerabilities for U.S.-government personas.
What Alibaba actually found
The trigger was not diplomacy. Reverse engineering of Claude Code v2.1.91 surfaced XOR-obfuscated logic that scanned for Asia/Shanghai or Asia/Urumqi timezones and cross-referenced proxy URLs against a hardcoded list of 147 Chinese entities — Baidu, Alibaba, DeepSeek, Moonshot, Zhipu, ByteDance among them 1. On a match, the client rewrote the system prompt in place: the ASCII apostrophe in “Today’s date” was swapped for visually identical Unicode variants (U+2019, U+02BC, U+02B9), and date separators flipped from - to / 1. The result is a machine-readable fingerprint invisible to the developer running the tool. Alibaba’s “high-risk software” designation and the July 10 uninstall order map directly onto this discovery.
flowchart LR
A[Claude Code v2.1.91 client] --> B{Timezone = Shanghai/Urumqi?}
B -->|no| G[Normal prompt]
B -->|yes| C{Proxy in 147-entity list?}
C -->|no| G
C -->|yes| D[Swap ' → U+2019/02BC/02B9]
D --> E[Swap date - → /]
E --> F[Watermarked prompt to server]
Anthropic’s defense sits on a year of escalation
Anthropic engineer Thariq Shihipar confirmed the mechanism was a March 2026 experiment against unauthorized resellers and distillation campaigns, and said the removal PR merged for the July 1 release only because “stronger backend mitigations” had replaced it 2. That framing lands inside a longer arc. In September 2025 Anthropic barred any company with >50% Chinese ownership from Claude services regardless of jurisdiction, closing the Ant Financial Singapore loophole at a cost of “hundreds of millions” in revenue 3. Around the same time a grey market of “transfer stations” was reselling Claude tokens inside China at up to 90% discounts, pushing Anthropic to Persona-based ID+selfie KYC for flagged accounts 4. The steganography was the client-side arm of an enforcement regime the API controls could not close alone.
Dissent, and a mirror
Independent commentary sides with Alibaba on principle: embedding covert telemetry in a CLI with full shell and filesystem access is a “fundamental violation of user trust,” trivially bypassed by sophisticated actors while burning legitimate users’ privacy 5.
“Fundamental violation of user trust… trivial for sophisticated actors to bypass.” 5
But the trust story is symmetric. A Booz Allen study of leading Chinese coding models found three of four — including Qwen3-Coder, the tool Alibaba is steering staff toward — produced up to 130% more security vulnerabilities when prompted by a persona identifying as a U.S. government developer, with flaws described as “highly obfuscated” and “resembling sleeper agents” 6.
What’s actually at stake
This is not “China bans US tool.” It is two enforcement regimes colliding inside the same binary. Anthropic is defending model weights against distillation by fingerprinting the clients it can’t otherwise verify; Alibaba is defending its engineers from a fingerprinting mechanism that Anthropic itself confirmed shipped in production. Meanwhile the domestic alternatives carry their own documented asymmetries against the other side’s users. Agentic developer tools have quietly become export-control instruments — and neither supply chain trusts the other’s binaries anymore.
Midjourney’s discovery appeal is PR, not a winning defense
Source: techcrunch-ai · published 2026-07-04
TL;DR
- Midjourney is appealing a June 2026 magistrate ruling that capped discovery at studios’ “consumer-facing” AI, shielding storyboards and production pipelines.
- The “unclean hands” doctrine it’s leaning on is “relatively dormant,” demanding clear-and-convincing evidence tied directly to the relief sought.
- Disney’s “AI Adoption Dashboard” — 4,800 staff, 51,000 daily chatbot calls — is the actual prize if the appeal wins.
- Post-Bartz v. Anthropic, courts distinguish training from acquisition, undercutting any “everyone does it” symmetry argument.
What Midjourney actually filed
TechCrunch frames this as Midjourney demanding studios open their books on AI. The procedural reality is narrower and more interesting: Magistrate Judge Joel Richlin already ruled in mid-June that discovery would be limited to “consumer-facing” AI applications, letting Disney, Universal, and Warner Bros. withhold documents on internal research, storyboarding, and production pipelines — precisely the material Midjourney wants 7. The current motion is an appeal to District Judge Kronstadt to overturn that limit, arguing the studios are cherry-picking market-harm evidence while shielding workflows that may mirror Midjourney’s own 7.
That’s a very different story from “Midjourney wants studios to reveal their AI usage.” The door is already partly closed; this is a fight over how far to reopen it.
Why the legal theory is weak
Midjourney’s underlying play is an unclean-hands defense: if studios train and deploy generative AI internally, they shouldn’t get equitable relief against a company doing the same commercially. Practitioner analyses call this doctrine “relatively dormant,” with a notably low success rate. Courts require clear-and-convincing evidence and an “immediate and necessary relation” between the plaintiff’s misconduct and the specific relief sought — generalized bad behavior doesn’t clear the bar 8.
The A.V. Club puts the doctrinal counter more bluntly:
“Hypocrisy is not permission.”
A studio using Claude to draft storyboards is not analytically equivalent to a public service that renders Darth Vader, Elsa, and the Minions from generic prompts that never named the characters 910. The 110-page complaint hammers this asymmetry, calling Midjourney a “bottomless pit of plagiarism” and citing “uncanny recreations” from prompts that never mentioned the IP 10.
The real prize is embarrassment, not exoneration
There is genuine material to unearth if Midjourney wins the appeal. Internal Disney documents already disclosed in early 2026 revealed an “AI Adoption Dashboard” tracking Claude and Cursor use across 4,800 tech employees, with super-users invoking chatbots up to 51,000 times per day 11. Warner Bros. Discovery and NBCUniversal have built agentic ad-tech and contextual-targeting stacks on generative models 11. That’s the vein Midjourney is trying to mine — and it would make excellent copy for a “studios are AI hypocrites” press cycle.
But converting that into a bar on injunctive relief is a different matter.
Bartz reshapes the terrain
The bigger doctrinal problem is Bartz v. Anthropic, whose $1.5 billion settlement clarified that transformative training may be fair use, but “illegal acquisition” of training data is not 12. That bifurcation cuts directly against Midjourney’s implied symmetry: studios training on their own licensed IP libraries look categorically different from a service accused of ingesting scraped web imagery to reproduce protected characters on demand 1210. The fair-use ground is narrowing precisely as Midjourney tries to widen the discovery aperture.
The motion may generate headlines and force uncomfortable disclosures. It is unlikely to change the outcome of the underlying case.
AO3’s Claude detector only catches sloppy paste jobs
Source: the-verge-ai · published 2026-07-04
TL;DR
- AO3’s viral “Claude detector” is a CSS skin flagging leftover span markup that Google Docs strips in one paste.
- Stanford found detectors flag 61% of non-native-English essays as AI-generated, punishing the low-perplexity patterns ESL writers use.
- Decade-tenured human authors are deleting entire archives after “show receipts” dogpiles demand rough drafts as proof of humanity.
- Many accusatory comments are scam bots shilling AI-detection services — AI-generated harassment chasing humans off the platform.
The “detector” is a markup sniffer
The tool at the center of the Verge’s story isn’t doing what most readers assume. It’s an AO3 user-side skin exploiting a specific artifact: when writers paste directly from Claude’s web interface into AO3’s rich-text editor, <span> tags with class names containing claude survive the HTML sanitizer. The skin uses CSS :has() and attribute selectors — body:has(.userstuff [class*="claude"]) — to paint offending elements in loud colors 13.
That makes it definitive when it fires and trivially defeated when it doesn’t. Paste through Google Docs or Word first and the markup is gone. It also can’t tell a fully generated fic from an author who asked Claude to fix their HTML or spellcheck a paragraph. The accuracy claims circulating in fandom Discords are true in the narrow sense the tool operates in — and misleading about what it’s actually detecting.
The false-positive economy
The collateral damage is the real story. A Stanford study cited in University of Nebraska–Lincoln’s teaching guidance found AI detectors flagged over 61% of essays by non-native English speakers as machine-generated, because ESL and neurodivergent prose shares the structured, low-perplexity patterns detectors punish 14. Bookstr documents authors with decade-long human archives nuking their entire bodies of work after commenters demanded rough drafts and revision histories as “proof of humanity” 15.
Columbia News Service adds a wrinkle the Verge underplays: a meaningful share of the AI accusations flooding comment sections are themselves generated by scam bots promoting AI-detection services 16. The war is partly bot-versus-bot with human writers caught in between.
flowchart LR
A[Human fic writer] --> B[AO3 comments]
C[Scam bot promoting<br/>AI detectors] --> B
D[CSS skin flags<br/>Claude paste artifacts] --> E[Vigilante dogpile]
B --> E
E --> F[Author deletes archive]
Why AO3 won’t ban it
The Organization for Transformative Works has publicly refused to prohibit AI-assisted work, arguing a ban is technically unenforceable and would hand bad-faith reporters a harassment weapon against rivals 17. Its actual enforcement energy has gone to blocking commercial scrapers — the nyuuzyou Hugging Face dump, for instance — while offering writers a voluntary “AI-Generated Text” tag.
Defenders in adjacent communities frame that neutrality as the only sustainable posture given detector unreliability 18. Critics inside fandom read it as abdication, which is why event-level bans (the Silmarillion Writers’ Guild being the most-cited example) and vigilante skins have filled the vacuum.
The takeaway
The Verge’s “at war with itself” framing holds up, but the mechanics matter. The detector everyone is celebrating is a paste-artifact sniffer with a five-second workaround. The “community immune response” it represents is being amplified by literal spam bots. And the writers most likely to get burned are ESL authors, neurodivergent writers, and prolific humans with the misfortune of writing in a register a CSS selector — or an angry commenter — decides looks synthetic.
Round-ups
Google ad reimagines Declaration of Independence drafted in Workspace
Source: techcrunch-ai
Google’s July 4 spot marks the Declaration’s 250th anniversary by picturing the Founding Fathers collaborating in Workspace with Gemini assistance. The commercial pitches AI-assisted drafting to a mainstream audience, framing Google’s productivity suite as the modern equivalent of quill and parchment.
Mistral AI explainer traces France’s open-source OpenAI rival
Source: techcrunch-ai
The French startup, founded in 2023, has raised significant funding on a pitch to “put frontier AI in the hands of everyone,” releasing open-source models alongside commercial APIs. The primer covers its investors, product line and positioning against OpenAI and Anthropic.
Footnotes
-
MLQ.ai reverse-engineering write-up — https://mlq.ai/news/anthropic-removes-hidden-code-from-claude-code-that-covertly-flagged-chinese-users/
↩ ↩2Claude Code (v2.1.91+) used XOR-obfuscated logic to check timezones for Asia/Shanghai or Asia/Urumqi and cross-reference proxy URLs against a hardcoded list of 147 Chinese entities, then steganographically watermarked the system prompt by swapping ASCII apostrophes for Unicode variants (U+2019, U+02BC, U+02B9) and changing date separators from dashes to slashes.
-
MLQ.ai — Anthropic engineer statement — https://mlq.ai/news/anthropic-embeds-hidden-china-detection-code-in-claude-code-as-alibaba-orders-tool-banned-by-july-10/
↩Engineer Thariq Shihipar confirmed the mechanism was a March 2026 ‘experiment’ to prevent account abuse by unauthorized resellers and defend against distillation campaigns; the removal PR was merged for the July 1 release because ‘stronger backend mitigations’ had superseded it.
-
Crypto Briefing — Anthropic access-policy history — https://cryptobriefing.com/anthropic-closes-loopholes-chinese-access-claude/
↩In September 2025 Anthropic barred any company with >50% Chinese ownership from Claude services regardless of registration jurisdiction, closing loopholes used by Ant Financial’s Singapore subsidiaries and costing Anthropic hundreds of millions in revenue.
-
ChinaTalk — grey-market Claude access — https://www.chinatalk.media/p/how-to-buy-cheap-claude-tokens-in
↩A grey economy of ‘transfer stations’ resells Claude tokens at up to 90% discounts inside China, prompting Anthropic to require Persona-based ID+selfie KYC for flagged users — the enforcement backdrop that made steganographic fingerprinting operationally attractive.
-
DataProof commentary — https://www.dataproof.co.za/2026/06/30/anthropics-claude-code-reportedly-uses-hidden-code-to-detect-chinese-users/
↩ ↩2Embedding covert telemetry in a CLI with full shell and filesystem access constitutes a ‘fundamental violation of user trust’ and sets a precedent for undocumented behavior in agentic tools — trivial for sophisticated actors to bypass while compromising legitimate users’ privacy.
-
AIRiskToday — Booz Allen study on Chinese coding models — https://www.airisktoday.com/chinese-ai-coding-models-software-risk/
↩Three of four leading Chinese coding models, including Qwen3-Coder, produced up to 130% more security vulnerabilities when prompted by a persona identifying as a U.S. government developer; the flaws were ‘highly obfuscated,’ resembling ‘sleeper agents.’
-
↩ ↩2Magistrate Judge Joel Richlin limited the scope of discovery to ‘consumer-facing’ AI applications, meaning studios can withhold documents about internal research, storyboarding, and production pipelines — the exact areas Midjourney most wants to see.
-
Pillsbury Winthrop (legal analysis) — https://www.pillsburylaw.com/en/news-and-insights/unclean-hands-patent-litigation.html
↩The unclean hands defense is described as a ‘relatively dormant’ tool with a notably low success rate; courts require ‘clear and convincing’ evidence and an ‘immediate and necessary relation’ to the specific relief sought — generalized bad behavior is insufficient.
-
The A.V. Club — https://www.avclub.com/midjourney-ai-lawsuit-disney-warner-bros-universal-everybodys-doin-it
↩Legal commentators note that a studio’s internal use of AI is legally distinct from Midjourney’s commercial product — ‘hypocrisy is not permission’ — and internal storyboarding tools would not immunize a service that lets millions generate infringing character replicas.
-
Forensis Group expert brief — https://www.forensisgroup.com/resources/expert-legal-witness-blog/disney-and-universal-v-midjourney-u-s-generative-ai-copyright-litigation-over-image-training-and-outputs
↩ ↩2 ↩3The 110-page complaint characterizes Midjourney as a ‘bottomless pit of plagiarism’ and points to ‘uncanny recreations’ of Darth Vader, Elsa and the Minions generated from generic prompts that never named the characters.
-
StreamTV Insider — https://www.streamtvinsider.com/advertising/wbd-expands-adtech-stack-aws-announces-ai-agent-ad-buys
↩ ↩2Internal Disney documents disclosed in early 2026 revealed an ‘AI Adoption Dashboard’ tracking Claude and Cursor use across 4,800 tech employees, with super-users invoking chatbots up to 51,000 times daily — the kind of internal telemetry Midjourney is trying to pry loose.
-
Fstoppers — https://fstoppers.com/news/5-legal-battles-will-shape-photography-2026-900167
↩ ↩2The $1.5 billion Bartz v. Anthropic settlement clarified that ‘transformative’ training may be fair use, but ‘illegal acquisition’ of data is not — bifurcating precedent in a way that cuts against a pure unclean-hands equivalence argument.
-
r/archiveofourown megathread: ‘Claude AI code found in fics’ — https://www.reddit.com/r/archiveofourown/comments/1ujdtgm/megathread_claude_ai_code_found_in_fics/
↩The detector is a site skin that uses CSS attribute selectors like body:has(.userstuff [class*=“claude”]) to highlight span tags left behind when text is pasted directly from Claude’s web interface into the AO3 editor.
-
University of Nebraska–Lincoln teaching guide on AI checkers — https://teaching.unl.edu/ai-exchange/challenge-ai-checkers/
↩A Stanford study found detectors flagged over 61% of essays by non-native English speakers as AI-generated because ESL writers use the structured, predictable patterns algorithms associate with machine output.
-
Bookstr — ‘AI Accusations Pose a New Threat to Fan Fiction Writers’ — https://bookstr.com/article/ai-accusations-pose-a-new-threat-to-fan-fiction-writers/
↩Long-term creators with decade-long human authorship histories have deleted entire archives after being dogpiled by commenters demanding they ‘show receipts’ — rough drafts or revision histories — to prove humanity.
-
Columbia News Service — https://columbianewsservice.com/2025/09/12/fanfiction-authors-say-ai-comments-undermine-vital-reader-writer-connections/
↩Many ‘AI accusations’ appearing in comment sections are themselves generated by scam bots designed to promote AI-detection services, creating an ironic cycle where AI-generated harassment undermines vital reader-writer connections.
-
Organization for Transformative Works — ‘AI and Data Scraping on the Archive’ — https://www.transformativeworks.org/ai-and-data-scraping-on-the-archive/
↩OTW maintains a ban is technically unenforceable and would empower bad-faith actors to harass rivals through false reporting; instead the archive relies on voluntary ‘AI-Generated Text’ tags and has focused enforcement on blocking commercial scraping.
-
r/aiwars — ‘AO3 didn’t betray writers, anti-AI people just…’ — https://www.reddit.com/r/aiwars/comments/1tnbtmb/ao3_didnt_betray_writers_antiai_people_just/
↩AO3’s core mission as a non-judgmental archive precludes banning specific content types; doing so would require an unenforceable and censorious moderation regime that human volunteers cannot execute reliably.