Suspicious Signals: What Anthropic's Claude Bans Actually Reveal
This week, users of Claude opened their inboxes to find their accounts switched off. Not rate-limited. Not warned. Revoked. In Hong Kong, people who had used the service for months over a VPN read a message from Anthropic's Safeguards Team saying that an investigation of "suspicious signals" associated with their account indicated a violation of the Usage Policy. In Russia, the same template landed at a larger scale. Among those affected were an e-commerce lead at Yandex and a subscriber who had paid for the top tier for more than a year.
The company did not explain what a suspicious signal is. It did not name a clause. It did not give an example. It offered an appeal link, and it kept the money for the time already paid.

That is the news. What makes it worth more than a day of outrage is the system underneath it: a rule nobody can read, an enforcement layer that runs automatically, and an appeal that, on Anthropic's own published numbers, almost never changes the outcome.
What actually happened
The freeze is not a single event. It is a pattern with a long tail. In May, Anthropic blocked several hundred Russian accounts, according to the outlet Baza, with IT specialists and founders losing what one report called their "external memory": project architecture, analytics and chat history built up over months. In Hong Kong this month, users reported the same abrupt suspensions through X and Reddit, per the South China Morning Post, after routing their connections through supported markets such as Singapore and registering with foreign payment details.
The reason the company gives is always the same, and always says nothing: "an internal investigation of suspicious signals associated with your account indicates a violation of our Usage Policy." No clause. No example. No indication of which conversation, prompt or date tripped the flag. The wording repeats across cases on two continents, which is how you know it is a template, not a finding.
An account ban is not a support ticket. To the person on the other side, it is the loss of the tool they do their work with, and often the record of the work itself.
The rule, and the policy behind it
Anthropic's regional policy is real and documented. It publishes a list of supported countries and regions, and since September 2025 it has tightened restrictions on companies that are more than 50 percent owned by entities from unsupported regions, citing legal, regulatory and security risk. That is not arbitrary. A company selling AI into regulated markets has to draw a line somewhere, and adversarial access is a genuine problem rather than a talking point.
The difficulty is not that a line exists. It is how the line is enforced. The regional restriction is delivered by an automated classifier that also sweeps up paying individuals in supported markets, hands down an accusation it will not define, and, by the company's own reporting, almost never reverses itself.
The paying customer is the easy target
Forbes covered this in April under the phrase "AI deplatforming is the new debanking". One user had uploaded a three-week business travel itinerary and used the calendar integration to plan it. The tool worked exactly as sold. By the next morning the account was disabled for suspicious signals. "I was suspended for using the product exactly as advertised," he told Forbes.
The clearest case is documented in the open, on Claude's own GitHub tracker. A business customer in Singapore, twelve months in, with more than fifty payment transactions and no prior issues, upgraded to the highest tier and Team seats. Eleven hours later, every related account was suspended at once, with the same template line. Five suspension emails and two automatic refunds landed within four minutes. A refund does not return the data.
This is the shape that matters. If you are a company spending five figures a month, you have account managers and leverage. If you are an individual on a two hundred dollar plan, even after years of paying, you have a no-reply address and a reference number. The ban lands hardest on the person with the least ability to absorb it.
The numbers Anthropic publishes on itself
This is not speculation, and it is not unfair to Anthropic. The company publishes its own enforcement figures on its Transparency Hub. In the first half of 2026 it issued roughly 11.4 million bans. It received 398,000 appeals, and reversed 42,000 of them. That is about 0.37 percent of all bans walked back. In the previous half year: 1.45 million bans, 52,000 appeals, 1,700 reversed.
Read those numbers together and the policy is clear. Enforcement is automated and enormous. The correction rate is close to zero. If a signal fires by mistake, the odds say you will not get your account back, and there is no named clause to argue about, because suspicious signals is not a clause.
Why the appeal is the real problem
It would be easier to defend the bans if the appeal worked. It does not, in the way a person needs. One long-term customer wrote that the in-app data export returned a 235-byte file of account metadata, not the conversation history they expected. Another described about two months of silence after filing. The appeal form asks you to log back in, then drops you into a queue with no human to talk to.
Anthropic's own help centre lists defined categories for enforcement: repeated policy hits, unsupported location, terms breaches. Suspicious signals is not among them, and is not defined anywhere a customer can read. When the trigger is undefined and the reviewer is a form, appeal is a word for waiting.
If the rule cannot be named, it cannot be appealed. An undefined trigger is not a policy, it is a mood.
The honest counterpoint
There is a serious case for the other side, and it deserves stating plainly. Anthropic is under real legal obligations about where its models can be offered, and it faces genuine adversarial use: people and firms from restricted regions routing around the rules, and campaigns that try to extract a model's capabilities through its outputs. A company that ignored either would be criticised for the opposite failure. Safety and compliance are not invented excuses.
But a defensible line still has to be a legible one. The problem is not that Anthropic restricts access. It is that the restriction arrives as an undefined accusation, enforced against individual paying customers as readily as against adversaries, with a correction rate near zero and no human in the loop. A rule written for a hostile actor should not be the same rule that switches off a designer in Hong Kong who paid for a year.
This is the PewDiePie story, one layer down
In a recent piece I wrote about OpenAI banning PewDiePie for trying to train his own model, and the argument was that the ban is a symptom of who owns the pipeline. This story goes a layer deeper. PewDiePie lost the ability to train. These users lost the ability to work at all, in a product they paid for, because of where their connection said they were.
Whatever the intent, the effect carries the same message: if a company can switch off your access with one template email, you do not own your workflow. You are renting permission, and the rent can be cancelled by a signal you are not allowed to see.
What I would tell anyone who depends on a hosted model
I build local and on-prem AI for a living, so I will not pretend neutrality. But the lesson here is not "do not use Anthropic". It is the one I keep making, and this week sharpened it. Keep a second provider, so a single enforcement decision is an inconvenience rather than an outage. Keep your important conversations in a place you control, because the export may be metadata. And run the models you can run yourself for the work that cannot afford a gap.
Before you build a workflow on any hosted model, it is worth putting five questions to the vendor. Can you name the rule I would be banned under? Is enforcement automatic, or reviewed by a person? How many accounts did you ban last half, and how many did you reverse? What exactly does the data export contain? And what is my recourse if the decision is wrong? If the answers are vague, you have learned something about the layer you are standing on.
Readout: what is confirmed, and what is not
- Hong Kong and Russia users reported Claude account suspensions this week; SCMP and Baza report the waves (2 Oct 2026 / 8 May 2026).
- Anthropic's suspension email cites "suspicious signals" and a Usage Policy violation, per emails users have posted.
- Anthropic's Transparency Hub (23 Jul 2026): 11.4M bans, 398k appeals, 42k reversed in H1 2026, a reversal rate of about 0.37%.
- Documented long-term paying customers have been caught (Forbes, April 2026; GitHub issue, April 2026).
- Anthropic's supported-regions policy and the September 2025 ownership rule are official and published.
- Anthropic has not given a public statement on these specific suspensions, and has not defined "suspicious signals" publicly.
Anthropic built a company on being the careful ones, and much of its safety work is genuine. But careful is measured by the enforcement layer too, and right now that layer behaves like a black box that bills first and explains never. The people paying the bills deserve a named rule and a human to speak to. Until they get one, the safest AI is still the one running on your own machine.
If you are weighing up where your own models should run, and what it would take to keep your workflow yours, email brandon@kreostudio.co.uk.
Reader signal
Was this useful?
Work with KREO Studio
AI engineering, data science and design architecture, from Plymouth to the wider UK.
