Anthropic has restricted Huawei AI chips from using Claude Opus 5.5 to develop cutting-edge models

📅 2026-09-24

Abstract:

In addition to improving model capabilities, Anthropic’s latest Claude Opus 5.5 was also found to have added a special restriction mechanism for cutting-edge large language model development scenarios. When users use Opus 5.5 to develop the underlying kernel for a new generation of AI models, the system may not directly use the latest Opus 5.5, but automatically fall back to Opus 5 with lower capabilities. What’s more noteworthy is that it is currently discovered that this set of restrictions seems to target some AI accelerators of Huawei and Amazon.

Anthropic explained in the Opus 5.5 support document that the model has a dedicated classifier for "cutting-edge LLM development" and covers a limited range of tasks, such as kernel development for some machine learning accelerators. The purpose of this type of classifier is to determine whether the user's current request involves the development of the cutting-edge large language model itself. Once the relevant conditions are triggered, Claude will automatically fall back from Opus 5.5 to Opus 5.

The so-called AI core refers to a series of computing operations at the lowest level when running an artificial intelligence model. The kernel is responsible for deciding how the model uses the computing resources and memory on the chip and how to perform various mathematical operations. Because these operations directly determine how mathematical calculations are mapped to the actual processor, the kernel design directly affects the running speed, memory usage, accuracy, and inference cost of large language models. For training and running the most advanced AI models, kernel optimization for specific AI accelerators is often a critical step.

This limitation was first discovered by users in the support documentation after the official release of Opus 5.5. Anthropic has previously used classifiers in some models to identify potentially risky requests, and this time it has further applied similar mechanisms to the development of cutting-edge AI models.

Anthropic made it clear that these restrictions will not affect the vast majority of traditional artificial intelligence, machine learning research, and ordinary programming tasks. Only when a small number of cutting-edge LLM development capabilities are involved, the system may trigger the rollback mechanism. Therefore, for ordinary developers, the use of Opus 5.5 in daily programming, AI application development, and machine learning research will basically not be affected.

But after further testing, some users discovered that Opus 5.5 seems to specifically recognize some AI chips. According to the current public test results, this set of classifiers involves at least Huawei's Ascend 950DT and Amazon's self-developed Trainium3 AI chip. That said, if developers use Opus 5.5 to develop underlying kernels for cutting-edge large language models for these chips, the models may automatically switch to Opus 5.

It is not surprising that Huawei chips are included in this restriction. Anthropic has in recent years stepped up its guard against the ability of Chinese entities to obtain its models and views model distillation as an important security and national security issue. The so-called model distillation refers to calling a more capable model in large quantities, extracting its behavior and capability characteristics, and then using these data to train another model. Anthropic's recent threat intelligence report revealed that the company found that multiple China-related organizations carried out unauthorized distillation activities against Claude's Opus series models, and therefore further strengthened the account identification, request interception and inference process protection mechanisms.

Anthropic has also added stricter anti-distillation measures in Opus 5.5, including restricting API users from modifying the model's previous conversation context to avoid extracting the model's internal reasoning information by repeatedly manipulating the context. The company stated that such measures are mainly aimed at large-scale, industrial capacity extraction activities, rather than normal use by ordinary users.

Therefore, when Opus 5.5 detects cutting-edge model development requests involving Huawei's AI accelerator, the restriction mechanism may have obvious technical and geographical backgrounds. However, there is currently insufficient evidence to show whether Anthropic designed this set of rules specifically for Huawei, or whether it includes specific types of AI accelerators as a whole within the scope of restrictions.

What is really surprising is that Amazon Trainium 3 also appears to be affected in the same way.

Amazon is not only a large global cloud computing company, but also an important partner and investor of Anthropic. Anthropic's Claude model itself is provided to enterprise customers through Amazon Web Services, while the Trainium series is an AI training and inference chip independently developed by Amazon to reduce the dependence of cloud artificial intelligence computing on Nvidia GPUs. Therefore, if Opus 5.5 does restrict Trainium3 for cutting-edge model kernel development, Amazon may instead be affected by the same set of technical restrictions as Huawei.

It is unclear whether this situation was intentional by Anthropic, or whether the classifier made an unexpected misjudgment when identifying a specific AI chip. Relevant tests show that Opus 5.5 seems to be able to identify different hardware platforms and decide whether to allow the latest model based on the request content, but Anthropic did not publicly explain why Trainium3 would trigger restrictions at the same time as Huawei 950DT.

This situation is particularly noteworthy because Anthropic has previously emphasized that its models can be widely provided through cloud platforms such as AWS, and Opus 5.5 has officially landed on platforms such as Amazon Web Services, Google Cloud, and Microsoft Azure. If this limitation extends to more AI accelerators for training advanced models in the future, then partnerships between cloud computing companies and AI model companies may require more complex coordination between model capabilities, hardware support, and security constraints.

From a technical perspective, Anthropic's approach this time also reflects a new trend: as the AI ​​model itself begins to help humans design and optimize the next generation of AI models, model manufacturers need to start distinguishing between the two types of tasks: "using AI to develop applications" and "using AI to develop stronger AI".

For ordinary programmers, letting Opus 5.5 help write applications, debug code, or conduct machine learning experiments usually does not trigger special restrictions. But if the same model is used to develop the underlying computing core of the next generation of cutting-edge large language models, Anthropic may consider this to have entered another risk level and have the request automatically fall back to the older model.

This means that the AI ​​model itself is gradually becoming part of the AI ​​R&D infrastructure. In the past, restricting the use of models mainly meant restricting certain dangerous content or sensitive areas; now, model manufacturers are beginning to further consider issues such as "who can use the latest models to make next-generation models" and "whether the latest models should help competitors optimize their own AI computing infrastructure."

Currently, Anthropic has not publicly stated why Trainium3 triggers restrictions at the same time as Huawei 950DT, nor has it been made clear whether this mechanism will continue to exist in future versions. As more and more companies begin to develop their own AI accelerators, this limitation on specific hardware and cutting-edge model development tasks is likely to become a new problem that AI model manufacturers need to face when making trade-offs between security, prevention of capability distillation, and hardware ecology.

Related tags

Related articles

Comments

0/500
Captcha (click to refresh)
No comments yet