The workarounds used to bypass Anthropic's security measures are quite illegal. They use stolen credit cards, API keys, and accounts. That is only possible in China because any other US/EU lab doing the same would get into massive legal trouble.
That's the moat. Mistral has the capability but not the legal protections.