Breach of Contract Is Not Illegal: When a "Domestically Self-Reliant" Agent Framework Runs on a Banned American Toolchain

In September 2025, Anthropic barred any entity majority-owned by companies in unsupported regions from using Claude anywhere in the world. A year later, DeepSeek embedded Claude Code into the first commit of its open-source agent framework — a violation of contract and of narrative, but not of US or Chinese law.
Breach of Contract Is Not Illegal: When a "Domestically Self-Reliant" Agent Framework Runs on a Banned American Toolchain

In September 2025, Anthropic wrote an unusual clause into its terms of service: any entity majority-owned by a company in an unsupported region is barred from using Claude anywhere in the world — not even if it is incorporated in Singapore or Hong Kong. A year later, a Chinese company falling squarely within that line used Claude Code as a core development tool, written into the first commit of its open-source framework. This violates neither US law nor Chinese law. What it violates is a contract — and a narrative.

First, let's nail down the legal dimension, because it is the aspect most easily distorted — and the easiest target for rebuttal.

Anthropic's clause wording is highly specific: any entity directly or indirectly more than 50% owned by a company headquartered in an unsupported region may not use its services worldwide, with China, Russia, Iran, and North Korea explicitly named. DeepSeek is wholly owned by High-Flyer, so it falls within that line without dispute. Anthropic also stated directly in its distillation report that, for national security reasons, it currently does not provide Claude commercial access in China, nor to its subsidiaries abroad. Mainland China has never appeared on Anthropic's supported-regions list.

But being "banned by the terms" and being "illegal" are two different things. According to reporting by the UK's Financial Times, this kind of circumventing access violates neither US law nor Chinese law — what it violates is Anthropic's terms of service. It is a contractual matter, with the consequence being account termination, not any legal liability. The export-control dimension also needs to be stated clearly: as of this writing, US legislation bringing "the provision of closed-source AI model services to Chinese entities" into formally effective rules has not appeared in public reporting; relevant discussions remain largely at the proposal stage. Writing proposals as if they were already-effective regulations is the most common — and most fatal — error in this kind of coverage.

China's side similarly offers clear room for exemption. Article 2 of the "Interim Measures for the Management of Generative AI Services" stipulates that the Measures apply to the provision of services to the public within the territory of the People's Republic of China using generative AI technology; however, the Measures do not apply where industry organizations, enterprises, research institutions, and others research, develop, or apply generative AI technology without providing services to the domestic public. As long as an enterprise uses overseas tools for internal R&D and does not provide services to the domestic public, it falls outside the scope of these regulations.

So any attempt to frame this as "illegal" or "violating export controls" will be easily pierced on the facts. Only one landing point holds up: the fact of breach — and the tension between that breach and a narrative.

One escalation in the level of evidence deserves emphasis. If a lone engineer had quietly installed Claude Code on a personal machine, that would be at most an individual act. But in DeepSeek Harness's official CI/CD pipeline, the workflow pi-ai-provider-e2e.yml mounts Anthropic's production keys and runs live tests against claude-opus-4-8 by default. This means access to Claude is not a private convenience for a few individuals — it is written into the design of the company's infrastructure. From individual breach to organizational dependency, that is a difference in magnitude.

So does the "narrative" tension actually hold? It depends on a precondition: whether DeepSeek has publicly claimed a "pure domestic toolchain, self-reliant and controllable." If such words exist, then the contrast — its next-generation agent framework built with a rival's banned tool — is real and sharp; if those words cannot be found, then the "saying one thing, doing another" charge doesn't stick, and the story's hook should be downgraded from "gotcha" to "tension." This is a piece of evidence that must be nailed down before anything is written.

The counterargument also has to be presented — and it is a hard one: "everyone does it" is a fact. According to reports, Ant Group provides employees with enterprise Claude accounts through a Singapore entity over its internal network; ByteDance reimburses employees for personal subscriptions accessed via VPN; Alibaba, after being accused by Anthropic, turned around and disabled Claude internally. Circumventing restricted US AI is standard practice across the Chinese tech industry. DeepSeek is not an outlier — if anything, it is the one that left its integration traces most thoroughly exposed. This means that holding DeepSeek up as a poster child for "dishonesty" has limited persuasive force — a criticism with real weight should land on the gap with its own public narrative, not on "using a banned tool," a commonality shared across the industry.

Anthropic's motivations should also be presented faithfully — and with equal precision. Its CEO stated in a company announcement that, in order to cut off use of Claude by companies affiliated with the Chinese Communist Party, the company "forwent hundreds of millions of dollars in revenue" (forgo, i.e., voluntarily relinquishing, or future revenue — not "already lost"; get the word wrong and the fact is distorted). This is both Anthropic's position and the commercial and political backdrop against which it tightened its terms so severely.

At bottom, this is not a legal story; it is a narrative story. A Chinese company explicitly banned from a tool turned a rival's tool into its own means of production. Legally, it is beyond reproach; contractually, it is in black and white; narratively — if it did indeed invoke "self-reliance" — it forms a fissure worth pursuing. All the force of the reporting should be concentrated on that fissure, rather than overreaching into the "illegality" it does not constitute.

Evidence List

Confirmed (Official / First-Hand)

  • Anthropic, "Updating restrictions of sales to unsupported regions" (effective 2025-09-05): entities with >50% Chinese ownership banned globally; China/Russia/Iran/North Korea named.
  • Anthropic distillation report: explicitly states it currently does not provide Claude commercial access in China, nor to its overseas subsidiaries.
  • Official CI holds Anthropic production keys and runs claude-opus-4-8 by default (local forensics, evidence/03) — evidence of organizational-level dependency.
  • Article 2 of China's "Interim Measures for the Management of Generative AI Services": internal R&D/application by enterprises that do not provide services to the domestic public are not subject to the Measures.

Legal Characterization (First-Hand Media Reporting)

  • FT (via Investing.com): circumventing access violates neither US nor Chinese law, but violates Anthropic's terms of service.

Unilateral Positions

  • Amodei official statement on "forgoing hundreds of millions of dollars in revenue" to cut off CCP-affiliated companies (forgo, not "already lost").
  • The "self-reliance debunked" hook must first confirm that DeepSeek actually made corresponding public claims; otherwise, downgrade to "tension."