A few months ago, Anthropic occupied an very comfortable position in the AI industry.

Developers loved Claude. Researchers respected the company's willingness to discuss catastrophic risk. Even people distrustful of the industry's largest laboratories often treated Anthropic as the exception: the careful, focused alternative to OpenAI's relentless expansion.

Anthropic did not lose that reputation because the public suddenly stopped caring about AI safety. It lost it controversy by controversy.

By late July, Anthropic had been accused of quietly weakening Claude responses, making paid access less dependable, turning a supposedly economical model into a token-hungry disappointment, acquiring books through both industrial destruction and piracy, making public share links too easy to discover, competing with companies building on Claude, and using the language of AI safety to defend a more controlled ecosystem.

None of these controversies fully explains the backlash alone. Together, they reveal something larger. Anthropic built a competitive advantage out of trust, then began spending that trust through decisions that made its products less predictable, its ecosystem less neutral, and its moral authority harder to accept. It is no longer being judged as the principled challenger it once was. It is being judged as a platform company, and every decision it makes now looks different because of it.

The trust Anthropic built, and began to spend

Anthropic did not simply sell a capable chatbot. It sold a theory of how an AI company should behave.

The company describes itself as a public benefit corporation focused on reliable and safe AI. It published detailed system cards, warned openly about catastrophic risks, and created a Responsible Scaling Policy for models that might become dangerous. Claude's popularity with developers gave that institutional identity a product people genuinely wanted to use.

This combination produced a trust premium. Anthropic often received the benefit of the doubt because its restrictions appeared connected to a mission broader than market share.

That goodwill also created a higher standard. When safety is both a principle and a competitive advantage, the company invoking it must make the resulting product behavior very clear. Otherwise users have to decide whether a restriction protects the public, protects Anthropic, or does both.

Claude Fable 5 brought that tension into the open.

Claude could quietly weaken the work users paid it to do

Anthropic released Claude Fable 5 on June 9 as the public version of its more powerful Mythos-class model. The underlying model was the same as Claude Mythos 5, but Fable added safeguards intended to limit dangerous use.

Some of those controls were visible. If a request triggered classifiers for cybersecurity, biology, chemistry, or model distillation, Anthropic said it could route the request to Claude Opus 4.8 instead. The user would be told that a different, less capable model had answered.

One intervention worked differently.

Anthropic's system card said that requests related to frontier AI development could be made less effective without notifying the user. That category included work on large-scale training systems, the specialized chips used to train models, and other infrastructure that could help a competitor build a frontier model. Instead of refusing the request or visibly switching models, the system could modify the prompt, steer the model away from useful answers, or apply targeted fine-tuning.

The distinction matters. A visible refusal tells a developer that a policy blocked the task. A visible fallback identifies which model produced the answer. Both can be logged, tested, and accounted for.

An invisible intervention preserves the appearance of normal operation. A researcher may receive a weak but plausible answer and conclude that the model lacks the capability. A company evaluating Claude may blame its own prompt or software. An experiment may become impossible to reproduce because the system does not reveal when a policy layer changed the result.

The safeguard was disclosed in a system card, but it was not visible when it affected a response. For a product sold on reliability, that is an integrity problem.

Researchers quickly objected. Two days after launch, Anthropic reversed course. The company said it had made the wrong tradeoff, apologized, and promised that flagged requests would visibly fall back to Opus 4.8. Application programming interface users would also receive a reason when a request was refused.

The quick correction deserves credit. It also validated the criticism. Anthropic had treated transparency as something that could be reduced to ship a safer model faster, even though users needed that transparency to understand what they were testing and buying.

The same launch changed the privacy calculation for some organizations. Anthropic requires prompts and outputs sent to its most capable covered models to be retained for at least 30 days so it can detect jailbreaks and patterns of misuse across multiple requests. Zero-data-retention arrangements do not apply to those models. Anthropic says it does not use the retained material to train Claude and normally deletes it after 30 days, with exceptions for safety investigations and legal obligations.

That policy has a coherent security rationale. It also means access to the strongest model comes with less control over sensitive data. Safety became a reason to change both the model's behavior and the customer's data boundary.

Users stopped getting the product they thought they bought

The trust problem was not limited to frontier researchers. It reached subscribers paying as much as $200 a month who still could not reliably predict how much work their plan would buy.

In March, Anthropic said Free, Pro, and Max users would move through five-hour session limits faster during weekday peak hours. Weekly limits would remain unchanged, and the company estimated that roughly 7 percent of users would hit limits they previously would not. Individual reports were far more severe, with some Max subscribers saying normal workloads consumed entire sessions in a fraction of the time they once did.

The distinction between weekly allocation and usable access mattered little to someone locked out during the working day. One proposed class action now alleges Anthropic oversold its Max 5x and Max 20x plans; another alleges peak-hour and backend changes degraded Claude Code while Anthropic retained subscription fees. Those remain untested allegations. They nevertheless show that some users now view the gap between advertised and usable access as more than an inconvenience.

Sonnet 5 created a quieter version of the same problem. Anthropic positioned it as near-Opus performance at Sonnet pricing, and benchmarks showed real gains over Sonnet 4.6. But its own documentation says the new tokenizer produces approximately 30 percent more tokens for the same input. An equivalent task can therefore consume more billable tokens and exhaust usage budgets faster even when the listed standard rate is unchanged.

Some early users described Sonnet 5 as slower, more restricted, or too token-hungry to feel like a meaningful upgrade. That does not prove the model is objectively worse. It reveals the metric launch charts cannot control: users judge a model by the work it completes before the bill or limit arrives. When a technical improvement feels like worse value, the upgrade begins to look futile.

The safety company destroyed millions of books

The most visceral controversy did not begin with a model setting. It began with physical books.

Documents unsealed in a copyright lawsuit exposed Project Panama, an internal operation that Anthropic began in 2024 to acquire books at industrial scale and convert them into a searchable digital library. The Washington Post reported that Anthropic spent tens of millions of dollars buying millions of used books. Vendors removed the bindings, scanned the pages, and discarded or recycled the paper originals. Internal planning materials made clear that Anthropic did not want the project known.

The viral version of the story was simple: the safety company destroyed books to train its chatbot. The legal record is more complicated.

Judge William Alsup held that Anthropic's one-for-one conversion of lawfully purchased print books into internal digital copies was fair use. The source copy was destroyed, the digital replacement was not distributed, and Anthropic had paid for the physical book. The judge also held that using books to train Claude was a transformative fair use.

But Anthropic had built its library through a second route. It downloaded millions of books from pirate libraries including LibGen and PiLiMi. Alsup ruled that a later transformative use did not excuse acquiring and retaining pirated copies for a permanent central library. On July 20, a federal judge gave final approval to a $1.5 billion settlement covering more than 482,000 books. Authors and publishers are due roughly $3,000 per work, and Anthropic must destroy the pirate-library files and their derivative copies.

Those are distinct controversies: destroying purchased paper books was held lawful; keeping pirated digital books created the settlement exposure. Reputationally, they landed together. One revealed an operation designed to stay out of public view. The other showed the company taking copyrighted material first and resolving compensation through litigation later.

That combination cuts directly against Anthropic's trust premium. The company asks the public to accept its judgment where technology is moving faster than law and where outsiders cannot inspect every decision. Project Panama showed how aggressively it used that discretion when the scarce resource was not compute or model access, but human culture.

The book controversy concerned what Anthropic did with people's work before they ever became Claude users. The next controversy concerned what happened after users entrusted their own work to the platform.

Late July brought a smaller controversy with the same structure. Publicly shared Claude conversations and Artifacts appeared in Google results. Reporters found business plans, infrastructure diagrams, and other work products that users had placed behind shareable links.

This was not a breach of private-by-default chats. Users had chosen to create public links, and Anthropic said those links became searchable only after someone posted them somewhere a crawler could see. Its help page also states that anyone with a link can view the snapshot. By Monday afternoon, TechCrunch's test no longer returned the shared conversations, suggesting Anthropic or the search engine had remediated the immediate exposure.

That explanation is technically sound and still misses the product problem. People often treat “anyone with the link” as a private handoff to a colleague, not publication to the searchable web. Search indexing converted obscure access into broad discoverability. A platform built on trust should make that consequence impossible to misunderstand before a user shares potentially sensitive work.

Anthropic became its partners' competitor

The next source of distrust came from a more familiar technology-industry pattern.

Anthropic launched Claude Design in April. The product can create wireframes, interactive prototypes, presentations, marketing assets, and design systems, then hand the result directly to Claude Code for implementation. Those capabilities overlap with Figma, the collaborative interface-design and prototyping platform that had integrated Claude and worked with Anthropic as a partner.

Three days before the launch, Anthropic chief product officer Mike Krieger left Figma's board. Figma's filing said the departure did not result from a disagreement over company operations or policy. The timing still drew attention once Claude Design appeared. At an event after the launch, Figma chief executive Dylan Field said Anthropic had not been “consistently candid in their communications,” according to attendees quoted by The Wall Street Journal.

Anthropic is allowed to build design software. Product expansion alone is not evidence of misconduct, and no reviewed source shows that the company used Figma's private information to choose its roadmap.

The episode changed the risk calculation for companies building on Claude anyway. A model provider is not necessarily a neutral layer beneath their products. It can observe broad market demand, package its capabilities into complete workflows, and enter the same category as its customers.

Anthropic's current rules for Claude Code subscriptions reinforce that boundary. Third-party developers can build with Claude through paid application programming interface access, but they may not route users' Free, Pro, or Max credentials through a competing product. A Claude subscription buys access to Anthropic's products, not a general-purpose credential that follows the user into any interface.

That distinction is defensible as a product and billing policy. It also gives Anthropic's own applications a structural advantage. Builders who once saw Claude as a component now have to plan for the company that supplies the component to own more of the final experience.

Safety started looking like a competitive moat

The backlash widened in late July when much of the technology industry signed a public letter defending open-weight AI.

Model weights are the learned values that shape how a model behaves. Releasing them lets users run and modify the model on infrastructure they control instead of paying a provider for every request. Open weight does not necessarily mean fully open source, the training data and development process may remain private, but it gives users far more control than a closed application programming interface.

The letter argued that open weights expand access, reduce lock-in, strengthen competition, and allow more researchers to inspect AI systems. Its signatories included Nvidia, Microsoft, Meta, Google, OpenAI, GitHub, Hugging Face, and a long list of startups and infrastructure providers.

Anthropic did not sign.

That absence fueled accusations that the company was using safety to protect a closed business from cheaper competitors, particularly as Chinese open-weight models approached the performance of leading American systems.

The most sweeping version of that accusation is unsupported. Anthropic chief executive Dario Amodei responded on July 27 that the company had never advocated a blanket ban on open-weight models. He called models without dangerous capabilities a public good and acknowledged their benefits for access, competition, and customer control.

Anthropic's preferred policies are narrower. It wants tighter controls on advanced chips flowing to authoritarian governments, action against industrial-scale efforts to train competing models on Claude's outputs, and mandatory safety testing for sufficiently capable models whether they are open or closed.

Those arguments cannot be dismissed as fiction. Once model weights are released, the original developer cannot withdraw them, observe all use, or guarantee that safeguards remain intact. Anthropic has also reported large campaigns that used millions of Claude interactions to improve competing models.

The conflict of interest remains. Controls on advanced chips, model distillation, and expensive safety evaluations can reduce real risks while also favoring laboratories that already possess enormous amounts of compute, capital, and proprietary research. A closed-model company does not lose the right to make a safety argument. Its economic position means the argument must stand on evidence, precise thresholds, independent review, and rules that bind closed providers too.

Anthropic's old reputation once helped settle that question. Its safety focus made restrictions appear presumptively principled. The recent controversies removed that presumption.

The safety argument is real, and no longer enough

Anthropic has real evidence for some of the risks it describes. That no longer entitles the company to ask users, partners, or policymakers to accept every resulting tradeoff on trust.

Anthropic is not uniformly hostile to open technology. It created the Model Context Protocol, an open standard that lets AI applications connect to external tools and data, then donated it to the Linux Foundation's Agentic AI Foundation for neutral stewardship.

Nor did the book case establish that model training itself was theft. The court treated training as transformative and the destructive scanning of purchased books as a lawful format shift. Anthropic's settlement addressed the independently acquired pirate-library repository. That distinction matters even if the underlying acquisition strategy still damages the company's moral authority.

The company has also continued to publish evidence that reflects badly on itself. On July 30, Anthropic disclosed that Claude models had reached the public internet during poorly contained cybersecurity evaluations and gained unauthorized access to three real organizations.

That disclosure supports two conclusions at once. Advanced-model security risks are real, and Anthropic itself can fail to contain them. A Claude model published a malicious package to the Python Package Index. Another obtained credentials from an exposed security scanner. A third scanned roughly 9,000 systems before compromising an exposed application. These were not stories about a malicious user defeating a safeguard; they were operational containment failures inside evaluations Anthropic controlled.

The company deserves credit for investigating and publishing the incidents. The events also show why no laboratory should be trusted to turn its own safety claims directly into product rules or public policy without scrutiny. Safety arguments must survive independent evidence, precise thresholds, and rules that constrain closed providers as seriously as their open competitors.

Anthropic has not suddenly become the opposite of everything it claimed to value. It has become powerful enough that those values no longer answer every question its decisions create.

Why users now have reasons to leave

The practical mistake is treating trust in a company as a substitute for controls around the dependency.

Teams building on any frontier model provider should separate four questions:

  • Capability integrity: Can the application identify the exact model that answered and detect refusals, fallbacks, routing, or other interventions?

  • Data governance: How was training or customer data acquired, what rights accompany it, where does it travel, how long does it remain, and which exceptions can extend that period?

  • Portability: Can the system move to another model or interface without a complete rewrite or the loss of accumulated workflows?

  • Commercial alignment: What happens if the provider changes subscription terms, bundles the product's core feature, or enters the same market?

These questions do not require assuming bad faith. They assume that a laboratory with investors, customers, products, and policy goals behaves like an institution with several interests at once.

Anthropic can repair much of the damage. Safeguards should always be visible when they change a response. Model identities and routing decisions should be exposed in logs. Subscription limits should describe usable access, not merely nominal weekly allowances. Data-policy changes should be explicit at the point of model selection. Public sharing should state plainly when content may be indexed. Training-data acquisition should be documented as carefully as model behavior. Partners should receive candid notice when the platform enters their category. Safety proposals should rely on measurable capabilities and independent governance rather than the reputation of the company proposing them.

Anthropic still has time to reverse the trend, but the window is narrowing. Users will tolerate restrictions when they are visible, predictable, and tied to a defensible purpose. They are less likely to tolerate silent interventions, shifting limits, rising effective costs, and a supplier that increasingly competes with the companies depending on it. Claude is no longer the only compelling model available, and every opaque decision makes switching providers easier to justify.

The deeper transition may be irreversible. Anthropic's halo depended on being perceived as the exception to the AI industry's race for scale and control. Its products are now too broad, its platform too important, and its policy influence too consequential for that perception to survive automatically.

Anthropic does not need to be uniquely malicious to lose users. It only needs to keep asking for the trust of a principled challenger while exercising the power of an incumbent platform. If the company continues explaining its choices without making their consequences more legible, more customers will decide that switching providers is easier than waiting for the halo to return.

Sources

Keep Reading