A federal court has already ruled on the most legally contentious thing Anthropic did to build Claude, and it decided the company was allowed to do it. That is the part UK buyers should find uncomfortable. The exposure now attached to Anthropic’s name is not a legal defect that a procurement process would catch, because there is no finding of illegality to catch. It is a reputational and governance problem, and most AI vendor assessments have nowhere to put one of those.
The week the goodwill ran out
Writing on 29 July under the subtitle “His reputation is crashing”, Gary Marcus argued that most of the credit Dario Amodei had built up over the past year has now gone. Marcus is a long-standing critic of the frontier labs, so his conclusion is not a surprise. The interesting thing is the coalition he found himself in. He noted that he was “somewhat unusually” in agreement with David Sacks, the former White House AI czar, who criticises the company from the opposite direction. When a company’s sceptics on the safety side and its sceptics on the accelerationist side start making the same argument in the same week, something has shifted that is worth understanding.
Three things landed close together. Much of the industry signed an open letter, “Open Weights and American AI Leadership”, which by the following Monday carried more than 130 signatures including OpenAI, Nvidia, Microsoft and Google. Anthropic conspicuously did not sign. Amodei then published a position paper explaining the company’s stance, part of which called for a crackdown on industrial-scale distillation by competitors. And in the same few days, the Washington Post reported on an internal Anthropic operation called Project Panama, working from court filings running to several thousand pages that had recently been unsealed.
The credit Marcus says has been spent was earned in February, when Anthropic refused a Pentagon demand to strip safety restrictions from Claude, saying it could not in good conscience permit mass domestic surveillance or autonomous weapons without human oversight. It cost the company a £148 million contract and a “supply chain risk” designation. That episode is why Anthropic had a reputation worth losing.
Strategic Reality: A vendor’s credibility is an asset that gets spent, not a fixed attribute. Anthropic accumulated it by refusing the Pentagon in February and drew it down in July. Procurement frameworks that score a supplier once, at onboarding, will always read that balance a year out of date.
| The verified numbers | What they establish |
|---|---|
| More than 7 million pirated book copies | The figure Judge William Alsup put on the record when he ruled in Bartz v. Anthropic, June 2025 |
| $1.5 billion | What Anthropic paid in August 2025 to settle the piracy claims, admitting no wrongdoing |
| Early 2024 onwards | The period over which Project Panama destructively scanned purchased books |
| 500,000 to 2 million books | The range quoted in supplier proposals for a six-month conversion programme |
| Up to 1 million books per order | What the broker ISBNdb now handles for AI clients, non-disclosure agreements included |
| More than 130 signatories | The open-weights letter Anthropic declined to join |
What Anthropic actually said, and what people heard
Here the analysis has to part company with its own source, because Marcus’s characterisation is not quite what the document says. He describes Amodei as issuing “a statement explaining his resistance” to open-weight models. Anthropic’s paper is narrower than that. It states the company “has never advocated” for a ban on open-weight models, describes models without dangerous capabilities as “a public good” costing nothing beyond the compute to run them, and argues that restricting American firms from downloading Chinese weights would not touch the actual threat, since “bad actors are unlikely to be legitimate US businesses”. What it asks for instead is chip export controls, a crackdown on industrial-scale distillation, and pre-release safety testing applied to open and closed models alike, with academic and start-up models exempted.
That third proposal is close to what Britain’s AI Security Institute already does voluntarily, and the paper quotes AISI’s own finding that open-weight release of dangerous-capability models creates “a persistent and irreversible risk of misuse”. A UK reader assessing the argument on its merits would find a defensible position with a real safety case behind it.
It still did not land. Sacks’s response was that Anthropic “won’t stop until they kneecap open source”. Marcus read the paper as tone-deaf and self-serving. For buyers, the gap between the argument and its reception is the finding, not a distraction from it. A vendor that cannot get a nuanced policy position heard is a vendor whose regulatory positioning is unpredictable, and regulatory positioning is a thing you inherit when you build on someone’s platform.
Critical Context: Read the position paper before accepting anyone’s summary of it, including a critic you usually agree with. Anthropic’s actual proposals are testable and partly aligned with UK practice. The reputational damage came from timing and tone, not from the substance of what was proposed.
The provenance problem moves to the closed side
The Project Panama documents are the harder problem, and they invert an assumption that has organised a lot of UK procurement thinking.
The operation was named in an internal planning document that stated its purpose plainly: “Project Panama is our effort to destructively scan all the books in the world.” It also instructed staff to say nothing about it, noting “we don’t want it to be known that we are working on this”. Hydraulic cutters sliced the spines off purchased books, high-speed scanners digitised the pages, and the paper was recycled. Anthropic brought in Tom Turvey, formerly head of partnerships at Google Books, in February 2024, tasked with finding a route to what internal documents called “all the books in the world”. Before any of that, Alsup’s order records, co-founder Ben Mann had himself pulled millions of pirated titles off LibGen and Books3 back in 2021, and the judge found the company had lawful routes available but chose piracy to avoid what Amodei called “legal/practice/business slog”.
Judge Alsup then ruled that digitising books the company had lawfully purchased was fair use, on the reasoning that replacing a print copy with a searchable digital one is a format change rather than a new copy. The piracy was a separate matter, settled in August 2025 for $1.5 billion, with no admission of wrongdoing. So the destroy-after-scan model now has legal cover, and other labs are watching. Demand has not cooled: ISBNdb handles single orders reaching a million volumes, and markets pre-2022 stock specifically because it predates widespread AI-generated text, on the argument that “books represent curated, peer-reviewed, domain-specific human knowledge, structured in a way no web crawl can replicate”.
Now hold that against how the open-weights debate has been framed. In our analysis of Bill Gurley’s case for open models, one of the honest caveats was that downloadable weights carry provenance and licence risk that clever economics does not dissolve. That caveat still stands. What Project Panama shows is that it was never a property of open models. It is a property of the training-data economy, and the closed vendors are further into it, with more money and better lawyers.
Hidden Cost: If you rejected an open-weight model on training-data provenance grounds, apply the identical test to your closed vendor and see whether it passes. Most UK procurement teams have never asked a closed frontier lab where its books came from, because the question felt like it belonged to the other side of the argument.
Sacks put the asymmetry more sharply than we would: “Anthropic maintains that it is entitled to train for free on all the world’s output, even if the author objects. But if a competitor trains on Anthropic’s output after paying for it, that is IP theft. The hypocrisy is breathtaking.” Strip the temperature out of that and a useful predictive rule remains. This vendor’s position on intellectual property has tracked which side of the transaction it was standing on. That is not unusual corporate behaviour. It is, however, information about how the same vendor is likely to treat your data and your model outputs when your interests and its interests diverge. We made a related point about the limits of controlling what leaves a model; this is the governance half of it.
What this changes for buyers
| Stakeholder | What the July episode changes |
|---|---|
| UK enterprises | Vendor reputational risk becomes a live contract question, not a communications one; your customers may hear about your supplier before you do |
| Procurement and legal | Legal compliance and reputational acceptability have separated; a fair-use ruling protects the vendor, not your brand |
| Creative and publishing sectors | A supplier trained on destructively scanned books is a specific commercial and cultural problem for clients whose own business is authored work |
| Boards and audit committees | Concentration on two providers whose leadership is broadly distrusted is a governance exposure, distinct from the commercial lock-in already on the register |
| Public sector buyers | Provenance and transparency questions that already apply to open models must now be asked symmetrically of closed ones |
The concentration point deserves its own line, because it is the one Marcus ends on. Quoting the Wall Street Journal report he had cited earlier, he notes that “technologists and policymakers say they are also concerned about the AI race turning into a duopoly, with Anthropic and OpenAI essentially emerging as dominant players that control the market”. He closes by asking whether spending “a few trillion dollars to prop up a couple companies run by people hardly anyone trusts is bonkers”. He also ran an unscientific poll on X which, by his own account, showed respondents preferring Amodei to Sam Altman roughly two to one whilst mostly trusting neither.
Take the poll for what it is, which is nothing much. The structural observation underneath it holds regardless. We have argued before that the rivalry between these two labs is the operating context of your supply chain. The July episode adds a second dimension. Concentrating on a duopoly is a commercial risk. Concentrating on a duopoly whose principals are widely distrusted by the people who write the rules is a regulatory risk, because distrusted suppliers attract intervention, and intervention lands on their customers as migration work.
What to actually do
None of this argues for dropping Claude, which remains a very capable model, or for treating a Substack post as a procurement input. It argues for adding one question to a process that currently does not contain it.
- Ask your closed vendors the provenance question in writing. Where did the training data come from, what was licensed, what was litigated, and what is still contested. You are not looking for a clean answer, because nobody has one. You are looking for whether they will answer at all, and creating a record that you asked.
- Separate legal risk from reputational risk on the register. They now have different owners and different mitigations. A fair-use ruling closes the first and does nothing for the second.
- Test the vendor’s IP position against its own interests. Where a supplier’s stated principle on data and output ownership happens to align with its commercial position, assume the principle will move when the position does, and get the protection you need into the contract rather than relying on the stance.
- Price your exit before you need it. The recommendation from our open-models analysis has not changed: run one open-weight pilot on a real workload so the cost of leaving is a number you know rather than a number you discover.
For organisations at different levels of maturity, the sequencing differs. If AI is still in pilots, write the provenance question into your vendor assessment template now, whilst it costs nothing. If you have production workloads on a single closed provider, the priority is the migration estimate, because that figure is what converts this from anxiety into a decision. If you are a regulated or public body, the symmetry point is the urgent one: any due-diligence standard you apply to open weights and not to closed models is now indefensible.
Take Action: Add one line to your AI vendor assessment template this quarter, asking suppliers to describe the provenance of their training data and any related litigation. The answers will be unsatisfying. The record of having asked is what protects you.
Four things this reading understates
-
Reputational risk decays fast, and often deservedly. July’s outrage cycle may be entirely forgotten by October, and rebuilding a vendor strategy around a fortnight of bad coverage would be its own error. Mitigation: treat this as a trigger to add a durable diligence question, not as grounds for switching suppliers on sentiment.
-
Marcus is not a neutral narrator, and neither is Sacks. One has argued for years that the labs oversell, the other has a direct commercial and political interest in open weights winning. Their agreement is notable but it is not corroboration. Mitigation: the court documents and the position paper are the evidence; the commentary is the signal that the evidence is landing.
-
Anthropic’s competitors are not demonstrably better on provenance. Alsup’s ruling is being read across the industry as a roadmap, and demand for print stock is sector-wide. Switching vendors on this basis may move the exposure rather than reduce it. Mitigation: ask every vendor the same question and compare the quality of the answers, not the volume of the coverage.
-
The reputational question can crowd out the capability question. The reason organisations buy these models is that they work, and a diligence process that treats provenance as disqualifying rather than as a priced risk will simply push work into unsanctioned tools. Mitigation: keep this on the risk register, where it can be weighed, rather than in the approval gate, where it becomes binary.
The strategic takeaway
The useful residue of a bad fortnight for Anthropic is not a verdict on Dario Amodei. Marcus’s own conclusion, that “we need people we can fully trust, and I don’t think we have that”, is a statement about the industry rather than a procurement instruction. The instruction is narrower and more boring. Two of the assumptions UK buyers have been working with turn out to be wrong, and both are correctable this quarter.
The first is that legal compliance is a sufficient test of a supplier. Anthropic’s destructive scanning of purchased books was ruled fair use, and it is still a live reputational problem for anyone whose own business is authored work. The second is that training-data provenance is a question about open models. It is a question about the training-data economy, and the best-resourced closed labs are the deepest into it.
Three things to hold onto. Vendor credibility is a balance that gets spent, so score it on a cycle rather than at onboarding. Where a supplier’s principles align with its interests, plan for the principles to follow the interests, and put the protection in the contract. And read the reception of a policy position as well as the position itself, because a vendor that cannot be heard clearly is a vendor whose regulatory future you cannot forecast.
- Add a training-data provenance question to your vendor assessment template
- Split legal risk and reputational risk into separate register entries with named owners
- Produce a migration cost estimate for your largest single-vendor workload
- Apply the same provenance standard to closed models that you already apply to open weights
The court decided Anthropic was entitled to do what it did. It did not decide that you are comfortable buying the result, and that question is yours.
Source: Gary Marcus, “Dario takes it on the chin”, Marcus on AI, 29 July 2026. Project Panama details from “Inside Project Panama, Anthropic’s Secret Effort To Scan and Shred the World’s Books”, International Business Times UK, reporting on the Washington Post’s review of unsealed court documents in Bartz v. Anthropic. The duopoly quotation is from a Wall Street Journal report as quoted by Marcus.
Analysis by Resultsense — making sense of AI in the UK. For strategic guidance on AI vendor assessment and training-data due diligence, get in touch.