Despite geoblocking, credit card checks, and even biometric verification for some users, a gray market for Anthropic's AI models is thriving in China. So-called "transfer stations" are undermining access restrictions and basic assumptions about AI safety.

Anthropic runs what are probably the strictest access controls of any major AI provider when it comes to China. The company checks phone numbers, foreign credit cards, and billing addresses. It bans companies that are more than 50 percent owned, directly or indirectly, by entities based in unsupported regions like China. For select users, it even requires ID verification with a live selfie. Yet Chinese developers can still buy Claude tokens for about 10 percent of the official price, according to a detailed analysis by Zilan Qian, a researcher at the Oxford China Policy Lab, published by ChinaTalk.

"Transfer stations" give developers a backdoor

The trick is what the Chinese developer community calls "transfer stations," which are API proxies hosted on servers outside China. They accept API requests, forward them as if they came from a legitimate location, and relay the response back. Users pay in Chinese yuan through WeChat or Alipay. No VPN, no foreign credit card needed. Popular transfer stations are cataloged in community directories and ranked by price and availability.