Where Anthropic's Safety Commitments Stop
From its AI constitution to its call to slow the industry, each of the company's safety promises carries an explicit boundary — and those boundaries form a pattern.
In late July, a federal judge ruled that destroying a physical book to create a digital copy is not destruction at all. It is, in Judge William Alsup's formulation, a format change.
every purchased print copy was copied in order to save storage space and to enable searchability as a digital copy. The print original was destroyed. One replaced the other. — William Alsup
The pulping of a purchased book — its binding cut, its pages scanned, its physical existence ended — became, in the court's language, a matter of "storage optimization" [1]. The ruling is a legal decision about fair use. But the alchemy it performs — converting destruction into something more palatable — is the same move visible across six months of Anthropic's public statements and internal documents. Each of the company's safety commitments carries an explicit boundary where the principle stops applying. The constitution has a military carve-out. The data operation runs under a secrecy directive. And the call to slow AI development arrived two days before the book-destruction project was revealed. In January, Anthropic released a 57-page philosophical constitution for Claude — a document instructing the model to act as a "conscientious objector" even against the company's own requests, prioritizing "broad safety and ethical behavior" over corporate instruction [2]. The constitution was published under a Creative Commons CC0 license, offered freely to encourage "industry-wide safety" [2]. It was a conspicuously public document, designed to be shared. But the constitution contains an explicit exemption. Models deployed under the Department of Defense's $200 million contract are carved out of the framework [2].
We think that in order to be good actors in the world, AI models like Claude need to understand why we want them to behave in certain ways, and we need to explain this to them rather than merely specify what we want them to do. — Anthropic
The conscientious objector, it turns out, does not object when the customer is the Pentagon — and that line permitted military use from the start. The DOD stance was not costless. Anthropic lost the contract, was designated a national security supply chain risk, and sued the Trump administration to preserve its guardrails [3]. Defense Secretary Hegseth framed the restrictions as ideological, declaring that "America's warfighters will never be held hostage by the ideological whims of Big Tech" [3]. The company paid a real price. But the carve-out was there in the constitution itself — the document that established the conscientious-objector principle also contained the exemption that made military deployment possible. The same asymmetry governs how Anthropic handles transparency. The constitution was released openly, under a license designed for sharing. But the company's data-acquisition operation, known internally as "Project Panama," was conducted under an explicit secrecy directive.
We don't want it to be known that we are working on this. — Anthropic
The platform facilitating bulk book purchases, ISBNdb, used nondisclosure agreements to maintain buyer anonymity [1]. Safety was released under CC0 for industry-wide adoption; data acquisition was concealed under NDAs and internal instructions to keep it unknown. Project Panama is an industrial-scale operation. Anthropic spent tens of millions contracting a vendor, Datamation, to purchase books, cut their bindings, scan the pages, and pulp the originals [1]. The target is specifically pre-2022 printed books — texts from before large language models began flooding the internet with synthetic content. As ISBNdb's own marketing puts it:
Print books from the pre-LLM era are structurally guaranteed to be free of this contamination. — ISBNdb
The destruction is not incidental; it is the point. These are the cleanest training sources available, and the company is consuming them. Non-destructive scanning alternatives exist — Google, Microsoft, and Harvard have all demonstrated methods that preserve the physical book [1]. Anthropic's choice to pulp rather than preserve is a cost and speed calculation, not a technical necessity. The temporal collision is almost too neat. On July 28, Anthropic publicly endorsed the "Pacing the Frontier" petition, joining more than 1,100 employees across OpenAI, Google, and Meta [4].
points to the need for tools to deliberately pace the frontier of AI development so society can prepare. We’re glad to see broad agreement across the field. — Anthropic
Two days later, on July 30, the existence of Project Panama was revealed — a secret industrial operation to destroy books for proprietary training data [5]. The petition was an industry-wide effort, not an Anthropic-specific initiative. But no other company has been identified running a destructive book-scanning operation on this scale. Anthropic's endorsement of the slowdown was unique in its contradiction: the company asking the world to wait was simultaneously accelerating its own data pipeline through a project it had directed be kept hidden. The contradiction runs deeper than public relations. Anthropic's own researchers have attributed Claude's misalignment to its training data — the company's position, established in its own technical work, is that what a model is trained on directly shapes what it becomes. That makes the destruction of pre-LLM books — the cleanest training sources in existence — not an incidental byproduct of data acquisition but a choice about what will shape the model. The company that identifies training data as the source of model behavior is the same company consuming the training sources least likely to produce it. The very thing the safety framework claims to govern — what goes into the model — is being decided in a secret, industrial pipeline that leaves nothing behind. What is being lost are not mass-market paperbacks with a Kindle edition waiting. Preservationists and librarians warn that the books most vulnerable to the buy-scan-destroy pipeline are rare, foreign-language, and out-of-print editions — the ones with no digital backup elsewhere [1]. When the binding is cut and the pages are pulped, they are gone. Not stored. Not optimized. Gone.
- 1. Judge Rules AI's Destructive Book Scanning as Fair Use
- 2. Anthropic Releases Philosophical Constitution to Guide Claude AI Behavior
- 3. Anthropic Sues Trump Administration Over National Security Blacklist
- 4. AI Employees Urge U.S. to Pace Frontier Development
- 5. Anthropic Destroys Millions of Books for AI Training Data