That makes VPN use more than a technical workaround. It can create a compliance problem for the customer and increase the risk that an enterprise account will be interrupted. OKX’s response suggests the company chose a hard location-based control rather than relying on employees to interpret the provider’s rules themselves.
The restriction was especially significant because OKX reportedly spends between $6 million and $8 million each month across large-language-model services.
That figure underscores the scale at which AI tools have become part of corporate operations. Even for a company with a substantial AI budget, access to a particular frontier model is not guaranteed everywhere its employees work or travel.
OKX’s plan to route affected requests to alternative providers also shows why multi-model infrastructure is becoming an operational safeguard. A company may prefer one model for coding, analysis or internal agents, but it still needs a fallback when a provider’s regional policy, contract terms or account controls make that model unavailable.
Goldman Sachs reached a similar outcome in Hong Kong through a different process. The bank reportedly reviewed its agreement with Anthropic and adopted a strict interpretation under which Hong Kong employees should not use Claude. The location-based restriction also applied to overseas staff visiting Hong Kong.
Available reporting does not describe Goldman’s decision as the result of a temporary corporate-account suspension. Instead, it followed a contract review and consultation over the scope of the agreement.
The comparison matters because the result can look identical to employees—a model disappears from an approved internal platform—while the underlying risk is different:
Both cases show that enterprise AI governance must account for provider terms as well as conventional cybersecurity and data-protection controls.
The dispute over advanced AI is no longer confined to chips, export controls or national strategy. It is also shaping which tools employees can use during an ordinary workday.
For multinational companies, the relevant controls now include:
These constraints can make AI deployment more fragmented. A company may build a workflow around a preferred model in one market, then need a different provider—or a different architecture—elsewhere.
Hong Kong is simultaneously promoting broader AI adoption and developing a local AI ecosystem. Government policy identifies AI as a priority industry and emphasizes wider use of AI across sectors.
At the same time, access restrictions from major U.S. model providers can limit the tools available to multinational employers in the city. That tension may encourage companies to diversify across providers or consider local and non-U.S. alternatives, although the supplied reporting does not establish how widespread those choices will become.
The result is a more complicated enterprise market: Hong Kong can promote AI adoption while companies still have to design around the availability decisions of individual model developers.
OKX’s decision was not simply a ban on a popular chatbot. It was a response to the operational risk of relying on a model whose availability changes with geography and whose terms apply to both the organization and its users.
For companies deploying AI across borders, the durable checklist is straightforward: verify supported regions before rollout, map employee travel scenarios, prohibit informal workarounds, review contract language with legal and compliance teams, and maintain tested alternatives for critical workflows.
OKX’s restored account shows that access can return. Its continuing regional restriction shows why restoration alone does not remove the underlying risk.