The Agentic Post
Breaking
Gemini’s Multimodal Features, Explained  Â·  ChatGPT Custom GPTs, Explained  Â·  What Is Constitutional AI? Explained  Â·  AI Capex Explained for Investors  Â·  AI Startup Valuations: How They Are Set  Â·  How to Reskill for an AI Job Market  ·  
Home/AI Models/Claude
What the Anthropic Book Scandal Shows

What the Anthropic Book Scandal Shows

Claude

Court documents confirm Anthropic destructively scanned millions of physical books to train Claude, ruled fair use by a federal judge, separate from its $1.5 billion piracy settlement.

Court documents unsealed this summer confirmed that Anthropic ran an internal program, code-named Project Panama, to buy millions of physical books, strip their spines with cutting machines, scan the pages to train Claude, and discard the paper originals. A viral video and social posts revived the story this week, though separating what’s actually documented from what’s since been exaggerated online takes some care.

Quick facts

  • Court records confirm Anthropic bought millions of physical books, often in bulk from resellers like Better World Books and World of Books, then destructively scanned and discarded them.
  • A federal judge ruled that this specific practice, converting legally purchased physical books into internal digital copies, is protected as “transformative” fair use.
  • That ruling is separate from Anthropic’s $1.5 billion settlement over a different allegation: training on pirated digital books obtained without purchase, the largest copyright settlement in US history.
  • An internal document reportedly stated the team didn’t want the project’s existence known; the total number of books destroyed and the total cost remain redacted.
  • Elon Musk publicly criticized the practice on X on July 27, and investor Michael Burry called it “evil incarnate.”

What the court documents actually show

Per a detailed review of the underlying evidence, the court’s summary-judgment order describes an employee tasked with obtaining “all the books in the world” for what internal documents called a research library. After limited outreach to publishers about licensing, the team turned to distributors and retailers for bulk purchases, sometimes tens of thousands of books at a time, then paid service providers to strip the bindings, cut the pages, and scan them with industrial imaging equipment before discarding the originals.

The judge’s ruling on this specific practice found in Anthropic’s favor: converting a purchased physical book into an internal digital copy, one-for-one, was deemed transformative fair use. That’s a meaningfully different legal question than the one behind Anthropic’s separate $1.5 billion settlement, which covered a different practice entirely: training on pirated digital books the company never purchased at all. Conflating the two, as much of the viral online discussion has, misrepresents what was actually found illegal versus what a court explicitly permitted.

Where the viral version overshoots the documented facts

Fact-checking coverage from Snopes draws an important distinction the broader viral narrative tends to blur: the confirmed, documented facts belong specifically to Anthropic’s Project Panama. A separate, newer claim, that a wider, mostly anonymous market of AI companies is secretly bulk-buying and destroying books through brokers like ISBNdb, comes from a July 21 investigation by 404 Media and remains far less conclusive, since the identities and practices of those other buyers aren’t established with the same documentary evidence as Anthropic’s case. The rare-book-targeting claim specifically is also less certain than viral posts suggest; the underlying evidence shows outreach mentioning “less common books,” not a confirmed, systematic targeting of scarce or historically significant volumes.

Why the comparison to Google Books keeps coming up

The recurring criticism in public discussion isn’t really about whether scanning books to train AI is permissible, courts have now weighed in on versions of that question, it’s about method. Google Books and the Internet Archive have run comparably massive book-scanning projects for years using non-destructive equipment that preserves the original physical copy. Anthropic’s approach, physically destroying each book after scanning it, was reportedly a deliberate choice: the Washington Post has reported Anthropic favored print books partly because they’re better-written and free of the low-quality text that pervades scraped web content, and destructive scanning is faster and cheaper at scale than preservation-grade digitization.

Key takeaway

The core, court-documented fact, Anthropic destructively scanned millions of purchased physical books and a judge ruled that practice legal, is genuinely significant and worth understanding on its own terms. But the version circulating most widely online has folded in a separate, less-substantiated claim about a broader industry-wide secret book-destruction market. Both deserve to be evaluated on the actual evidence behind each, not treated as a single, undifferentiated scandal.

Up Next
CrowdStrike: AI Cyberattacks Rose 89%

CrowdStrike: AI Cyberattacks Rose 89%

AI Safety

CrowdStrike's 2026 Threat Hunting Report finds AI-enabled attacks up 89%, with nation-state actors compromising npm packages that power trusted AI development frameworks.

CrowdStrike’s annual Threat Hunting Report, released August 3, 2026, delivers a blunt verdict: AI-enabled attacks rose 89% over the past year, and AI systems themselves have become one of the most actively targeted parts of the modern enterprise. The report is based on frontline intelligence from CrowdStrike’s own threat hunters tracking more than 290 named adversary groups.

Quick facts

  • AI-enabled adversary activity increased 89% year-over-year, according to CrowdStrike’s 2026 Threat Hunting Report.
  • One LLM-jacking campaign generated nearly 200,000 AI model requests in two minutes, per CrowdStrike’s telemetry.
  • During the first half of 2026, 87% of identified software registry threats involved malicious npm packages; North Korea-linked STARDUST CHOLLIMA injected a malicious package into 131 trusted Mastra AI framework dependencies.
  • 88% of exploitation involving a public proof-of-concept occurred within 48 hours of release; China-linked actors moved even faster, launching attacks within 24 hours in some cases.
  • Cloud-conscious eCrime activity, including credential theft, cryptomining, and LLM abuse, surged 171%.

AI as weapon, and as target

Per CrowdStrike’s official release, attackers are using AI throughout the entire attack chain, generating payloads and shell commands, exploiting AI infrastructure directly, and abusing enterprise LLM deployments. CrowdStrike counter adversary operations SVP Adam Meyers told reporters plainly that AI is now both the weapon and the target, a high-value attack surface that more threat actors are actively going after as enterprises roll it out everywhere. The firm also found that AI agent-triggered detection leads are growing at 2.5 times the rate of human-triggered ones, a sign of how much faster both attack and defense are moving.

The AI supply chain is the new soft target

The npm findings are the report’s most concrete illustration of where attackers are actually focusing. According to CrowdStrike’s detailed writeup, the North Korea-linked group STARDUST CHOLLIMA used stolen maintainer credentials in March 2026 to compromise the Axios npm package and deliver custom malware, then in June injected a malicious package as a dependency into at least 131 trusted Mastra AI framework packages specifically. Separately, the eCrime actor ALTERED SPIDER compromised more than 300 software dependencies in a single day to harvest credentials and pivot into cloud environments. Trusted, widely-used AI development building blocks are becoming exactly the kind of high-leverage target that a single compromise can multiply across thousands of downstream projects.

Exploitation windows are collapsing to hours

The report’s timing data is arguably the most operationally urgent finding for defenders: 88% of exploitation involving a public proof-of-concept happened within 48 hours of release in the first half of 2026, with China-nexus groups VAULT PANDA and GENESIS PANDA specifically launching deliberate attacks within 24 hours of disclosure. That’s a dramatically shorter window than the patch cycles most enterprise security teams are built around, and CrowdStrike ties the acceleration directly to AI-assisted vulnerability research and exploit development on the attacker side.

Why this matters beyond one vendor’s marketing report

It’s worth noting CrowdStrike sells security products, and an alarming threat report also serves the company’s commercial interest. That said, the specific findings here, particularly the npm supply-chain compromises and the compressed exploitation timelines, are consistent with what independent researchers and other vendors have reported throughout 2026, including the AI containment failures disclosed separately by OpenAI and Anthropic this summer. Taken together, the pattern across multiple independent sources points the same direction: AI is compressing both attacker and defender timelines simultaneously, and most enterprise security processes haven’t caught up to operating at that speed yet.

Key takeaway

If your organization uses any AI development framework or package sourced from npm or a similar public registry, the concrete action item from this report is auditing your dependency chain specifically for AI-related packages, not just your general software supply chain, since that’s precisely where nation-state actors have already demonstrated they’re focusing.