If you focus only on DeepSeek, you'll miss the bigger picture. A Chinese company explicitly prohibited under the terms of service of leading American AI labs is using those same labs' tools — at a pace of eight thousand commits per month — to build its own next-generation agent framework. And it is not an outlier: a fintech giant routes access through a Singapore subsidiary, a short-video giant reimburses employees for personal subscriptions used over VPN, and another cloud provider was accused of distillation one day and turned around to ban the same tool internally the next. The walls stand, yet people pass through every crack. The question is no longer who climbed over — it's whether the wall stops anything at all.
Start with the facts of the DeepSeek case, because it is the clearest reflection in this mirror. The public repository for DeepSeek Harness shows that its official continuous integration pipeline holds live Anthropic production API keys and runs real-model tests against claude-opus-4-8 by default. The commit history contains 1,760 branch merges with a codex/ prefix — the branch-naming convention associated with OpenAI Codex. In July alone, the repository produced 8,273 commits. DeepSeek does not even attempt to conceal this interoperability: its official API documentation provides a step-by-step guide for pointing Claude Code at its own models, instructing users to set the ANTHROPIC_BASE_URL environment variable to map claude-opus to deepseek-v4-pro. Being banned by Anthropic on one hand while openly teaching others how to use Claude Code on the other — that brazenness is itself a signal.
Pan the camera back, and DeepSeek's approach is not unusual across the industry — it is simply the most transparent. According to the Financial Times, Ant Group provides enterprise Claude accounts to employees at its Chinese headquarters through its Singapore entity via an internal network. ByteDance does not provide direct access but runs a reimbursement scheme that allows engineers to expense personal subscriptions and use them over VPN. Some companies route access through Microsoft Azure via overseas subsidiaries, making the trail harder to follow. Alibaba's posture is perhaps the most telling: after being accused by Anthropic of conducting large-scale model distillation, it turned around and banned Claude internally. Using and being banned, prohibiting and being prohibited — all within the same company, simultaneously.
Taken together, the nature of the problem shifts. It is no longer a question of whether any particular Chinese company is "playing by the rules." It becomes a structural question: is this system of containment — built on a foundation of terms of service — an effective line of defense, or an expensive exercise whose symbolic weight far exceeds its practical effect?
The case for calling it theater is made, in part, by the actions of those doing the containing. If the terms were sufficient, there would be no need to continuously reinforce them. Yet Anthropic keeps patching: starting in April 2026, it began requiring flagged accounts to submit government-issued identification and a live selfie for identity verification; in July, it moved to shut down so-called relay services, monitoring account operating-system time zones and usage patterns to identify accounts forwarding traffic on behalf of Chinese entities. A boundary that must be maintained by checking time zones and behavioral patterns is itself an admission that the gaps were always there — every new patch is a confirmation that the previous one was circumvented.
But an equally valid counterargument must be given its due, or "theater" becomes a cheap dismissal. Containment does not need to be airtight to be meaningful. Terms of service, identity verification, and export controls together constitute a layered deterrence system: they raise the cost and friction of access, turning "use it freely" into "navigate several workarounds and risk getting banned at any moment." For a significant share of smaller actors, that friction is a genuine and material barrier. Anthropic's escalating measures can equally be read as a tightening perimeter rather than a failing one — the more frequently patches are applied, the more it may signal an unwillingness to abandon the boundary. Which interpretation is closer to the truth depends on whether you weight "someone will always find a way through" more heavily than "the cost of finding a way through keeps rising." That is a contestable judgment, not a settled fact.
What this mirror reflects, then, is not the verdict that "containment is theater." It is a condition the entire industry would do well to confront honestly. When the most advanced capabilities are concentrated in a handful of American laboratories, and geopolitics demands that those capabilities be kept from certain actors, a boundary built on contractual terms is structurally porous by design — it can stop casual access, but it cannot stop an organized, well-resourced adversary willing to leave its footprints in a public repository. The reason DeepSeek Harness's development pipeline deserves attention is not that it proves DeepSeek is acting in bad faith. It is that it acts as a mirror, revealing the inherent limits of the containment regime itself: you can prohibit a rival from using your tools, but when that rival uses your tools to build the next generation of products that compete directly with yours — and lays the entire process bare in a public repository — what is exposed is not necessarily their vulnerability. It may be the wall's.
Evidence Summary:
Confirmed (Direct Repository Evidence / Official Documentation)
- DeepSeek Pipeline: Official CI holds live Anthropic production API keys, defaults to
claude-opus-4-8; 1,760 codex-prefixed branch commits; 8,273 commits in July; dependencies include@anthropic-ai/sdkand@anthropic-ai/claude-agent-sdk. - DeepSeek's official API documentation provides a Claude Code integration guide (
ANTHROPIC_BASE_URL=https://api.deepseek.com/anthropic, mapping claude-opus to deepseek-v4-pro) — publicly and openly instructing users on the setup.
Confirmed (Independent Media Reporting)
- Financial Times (as reported): Ant Group provides enterprise Claude accounts via its Singapore entity over an internal network; ByteDance reimburses personal subscriptions used over VPN; some companies access the service through Azure via overseas subsidiaries. Both companies typically decline to comment.
- Anthropic's containment measures continue to escalate: from April 2026, flagged accounts are required to submit government-issued ID and a live selfie; from July 2026, relay services are being shut down, with OS time zones and usage patterns monitored to identify accounts relaying traffic.
© 2026 Winzheng.com 赢政天下 | 转载请注明来源并附原文链接