Skip to main content
48 days

Super Intelligence definition proposal due (60 days) · Nov 28, 2026 · See what changes

news

Anthropic's Project Panama: Book Destruction, FTC Risk, and You

Anthropic's Project Panama planned to scan and destroy up to 2 million books. Groups asked the FTC for a Section 5 probe. A vendor AI risk checklist.

8 min readBy Johnie T YoungUpdated 3 days agoLast reviewed
Anthropic's Project Panama: Book Destruction, FTC Risk, and You

Image: Unsplash, used under the Unsplash License.

TL;DR: Anthropic's Project Panama, first reported by the Washington Post in January 2026 from court filings, was a program begun in early 2024 to buy books in bulk, cut off their spines, scan the pages, and recycle the paper to build training data for Claude. Further documents were unsealed in late July 2026. Judge William Alsup ruled in June 2025 that Anthropic's use of lawfully purchased books was fair use. On August 21, 2026, more than a dozen civil society groups asked the FTC to examine the practice as a possible unfair method of competition under Section 5. The FTC has not announced an investigation of book destruction; the industry-wide FTC probe Reuters reported on September 30, 2026 concerns consumer risks from AI agents. For compliance teams, training data provenance is now a vendor risk question.

The internal memo used a soft codename. The Washington Post first reported on the program in January 2026, citing court filings in Bartz v. Anthropic, and more documents were unsealed in late July 2026. The memo, as quoted by Common Dreams, says: "We use a 'soft codename' for it because we don't want it to be known that we are working on this."

Event: Project Panama ran from early 2024. First report: Washington Post, January 27, 2026. FTC letter: August 21, 2026. Updated October 8, 2026.

The program itself was less subtle. Beginning in early 2024, Anthropic bought books tens of thousands at a time from vendors including Better World Books and UK-based World of Books, according to Euronews. It outsourced the scanning to a vendor that used a hydraulic machine to cut off the spines and industrial imaging equipment to copy the pages. The paper was then sent for recycling.

The scale was deliberate. Project Panama's stated goal, per the internal planning document, was "to destructively scan all the books in the world." According to a vendor that worked with Anthropic, the company was seeking a vendor "to convert from 500,000 to two million books over a six-month period."

What the courts decided -- and what they didn't

Anthropic's book destruction became public through litigation, not disclosure. Authors Andrea Bartz, Charles Graeber, and Kirk Wallace Johnson led a 2024 class action (Bartz v. Anthropic, No. 3:24-cv-5417) alleging that Anthropic had used pirated books from shadow libraries such as LibGen. That lawsuit produced a $1.5 billion settlement covering about 500,000 eligible works, and the court granted final approval on July 20, 2026. The settlement administrator expects the first payments on or before November 15, 2026.

Project Panama, though, involved legally purchased books. On that narrower question, Judge William Alsup ruled in June 2025 that Anthropic's use of lawfully purchased books was fair use, while drawing a line between those books and the millions it had pirated.

That ruling closed one legal door and left another open. The civil society groups who sent their letter to the FTC on August 21, 2026, are not arguing copyright law. They are arguing competition law.

The antitrust theory

The FTC letter, from more than a dozen organizations including the Demand Progress Education Fund, the Consumer Federation of America, and the Institute for Local Self-Reliance, asks the agency to determine whether the practice "constitutes an unfair method of competition under Section 5 of the FTC Act." That is the competition provision, separate from the consumer protection authority the FTC has used in most AI enforcement actions to date.

The theory is structural. When a dominant AI company spends millions to acquire and physically destroy books, and the letter says rare books could be destroyed with digital firms taking the last copies, those works leave the market. A competitor that arrives later cannot buy what no longer exists.

"The secretive and reckless way that major AI companies like Anthropic and Amazon are acting shows that there is real smoke here that the FTC needs to investigate," said Kate Oh, special adviser to the Demand Progress Education Fund.

The groups describe it as part of a pattern "designed to create an insurmountable systemic moat around AI incumbents." The training data advantage is not just that Anthropic has the data. It is that no one else can get it.

The US Capitol dome seen through tree branches, representing federal scrutiny of how AI companies acquire training data

Image: Pexels, used under the Pexels License.

The groups also name Amazon, which is reportedly running a large book-buying operation in which employees cut the bindings off to scan the books faster. The civil society groups are not targeting a single company. They are asking the FTC to look at an industry practice.

What this means for enterprise AI buyers

The $1.5 billion Bartz settlement already established that training data has a price tag. Project Panama and the FTC probe request add a second dimension: training data has a competitive structure problem too, and that structure problem could become a regulatory one.

Three practical implications for compliance teams.

Training data provenance belongs in your vendor questionnaire. Most enterprise AI vendor assessments ask whether the vendor trains on customer data, whether training data is licensed, and whether the vendor carries cyber liability insurance. They do not ask whether the vendor has acquired training data through physical book destruction programs. That gap needs to close. Add it now, before your next contract renewal.

The question is not whether your vendor violated fair use -- Judge Alsup answered that. The question is what competitive, regulatory, or reputational exposure your organization inherits by relying on a vendor whose training dataset was built through a program the company felt required a secret codename.

A hand holding a black pen over a sheet of paper, representing the indemnification terms in an AI vendor contract

Image: Pexels, used under the Pexels License.

Indemnification clauses written for copyright claims may not cover antitrust claims. The standard AI vendor indemnification clause is built around copyright -- if someone sues you because your vendor's model reproduced their copyrighted text, the vendor covers you. That structure does not cover antitrust exposure. If the FTC opens a formal investigation of Anthropic's training data acquisition practices and issues civil investigative demands, your vendor's legal exposure is antitrust-shaped, not copyright-shaped. Check your contract language. If the indemnification is limited to intellectual property claims and does not extend to regulatory actions against the vendor, that is a gap to negotiate.

Regulatory uncertainty during a live FTC investigation changes your vendor risk calculus. The FTC has not announced an investigation of book destruction. Separately, Reuters reported on September 30, 2026 that the FTC is conducting an industry-wide probe into Anthropic, OpenAI and other AI labs over the potential dangers their technology poses to consumers, which a senior FTC official described to Reuters; that report concerns AI agents, not training data. If the agency does open a training-data inquiry, the practical effects are real: distraction from Anthropic's leadership team, possible civil investigative demands, public disclosure obligations, and potential remedies that could affect how the company is allowed to acquire training data in the future. Enterprise buyers who depend heavily on Claude should model what a long regulatory distraction at their main vendor would mean for their own AI roadmaps.

Why the secrecy matters more than the legality

The Project Panama planning document's request for secrecy is the most significant detail in this story for compliance purposes, and not because of what it implies about legality.

The June 2025 ruling later found the use of lawfully purchased books to be fair use. The memo's stated reason for the codename was simply that Anthropic did not want it known that it was working on this.

For enterprise governance purposes, that distinction matters. A vendor whose training data programs are designed to avoid public scrutiny is a vendor whose risk disclosures cannot be taken at face value. The standard AI vendor questionnaire response -- "we use properly licensed data" -- is technically compatible with a program that physically destroys library books and instructs employees not to use the program's real name.

The gap between legal compliance and transparent operation is where enterprise vendor risk actually lives.

Curved library shelves packed with books, representing the training data behind the models you buy

Image: Unsplash, used under the Unsplash License.

A five-item training data checklist for vendor assessments

Add these questions to your AI vendor due diligence questionnaire before the next contract signature or renewal:

  • Physical acquisition programs: Has your company purchased physical books, documents, or other physical media in bulk for digitization as training data? If yes, at what scale, through which vendors, and is that program ongoing?

  • Destruction practices: For any physical materials acquired for training data, what was done with the physical items after digitization? Are any categories of materials no longer obtainable because of your acquisition and destruction practices?

  • Regulatory engagement: Has your company received any civil investigative demands, information requests, or informal inquiries from the FTC, DOJ, or any competition authority related to training data acquisition? If yes, describe.

  • Indemnification scope: Does your standard enterprise contract's indemnification clause cover antitrust or unfair competition claims arising from your training data acquisition practices, or is indemnification limited to intellectual property claims?

  • Program secrecy: Were any training data acquisition programs operated under a soft codename or otherwise kept confidential from the public, external stakeholders, or your own commercial customers? What programs no longer meet that description, and what changed?

Vendors who cannot answer these questions are not automatically in violation of anything. But their silence shifts the risk-assessment burden back to you.

What readers said

When the Washington Post story ran, an r/books thread collected the reaction. The poster who shared it noted that it was "not immediately clear to me which details of the project are being newly reported on by the WaPo and which can be inferred from prior reports", since the June 2025 ruling had already described book scanning. Asked how you "destructively scan" a book, one commenter answered: "Tear out the binding so you can machine feed individual pages for scanning."

Our take

Based on the documents and reporting cited above, the legal risk for Anthropic's customers is low: a court has found the purchased-book scanning to be fair use, and the pirated-book claims are settled. The governance lesson is about disclosure. A vendor ran a large data program under a codename so it would not be known, and standard vendor questionnaires would not have surfaced it. Ask the five questions below, and treat "we use properly licensed data" as the start of the conversation, not the end.

Reading this in context

Project Panama is not an isolated incident. It is the most specific documented example of a broader pattern: dominant AI companies acquiring data at a scale and through methods that competitors cannot match, often before disclosure requirements existed or while regulatory attention was focused elsewhere.

The $1.5 billion Bartz settlement covers one dimension of that pattern, the pirated digital libraries. The FTC letter covers a second, the physical destruction of purchased books. A third, the scraping of web content under disputed terms of service, is the subject of ongoing litigation across the industry.

Enterprise compliance teams do not need to resolve any of these legal disputes to manage their vendor risk. They need to understand that the foundation model they are buying access to was built through practices that are still being tested in court and in regulatory proceedings, and to ensure their contracts reflect that uncertainty rather than assume it away.

For a broader framework on assessing AI vendors before these issues arise, the AI vendor due diligence checklist is the starting point. For the regulatory landscape the FTC is operating in, the FTC AI enforcement actions tracker for 2026 covers what actions have actually been taken and what the agency's enforcement posture looks like right now.

How we checked this

On October 8, 2026 we re-read the sources for this story: Euronews (August 5, 2026), Axios (August 21, 2026), Common Dreams, MLex, IBTimes UK, the Bartz v. Anthropic settlement website, and Reuters' September 30, 2026 report as published by The Star. We corrected when the story first surfaced (the Washington Post reported it in January 2026, not late July), the number of works in the settlement (about 500,000, not 482,000), and the shadow library names, and added the September 30 FTC probe report. We removed claims we could not source, including a 6-to-12-month distraction estimate and the claim that Anthropic's lawyers "presumably knew" the program was defensible.

Last reviewed: October 8, 2026.


Sources: Euronews: Project Panama -- How Anthropic secretly destroyed millions of books (Aug 5, 2026), Axios: FTC urged to investigate AI firms for destroying books (Aug 21, 2026), Common Dreams: Advocates Demand Federal Probe of Book-Burning by AI Giants (Aug 21, 2026), MLex: AI industry book destruction merits US FTC antitrust probe, civil society groups say, IBTimes UK: Inside Project Panama, Anthropic's Secret Effort To Scan and Shred the World's Books, Bartz v. Anthropic settlement website, Reuters via The Star: FTC opens probe into AI giants including Anthropic and OpenAI (Sept 30, 2026)

Legal disclaimer

This article is published for informational and educational purposes only. It does not constitute legal, regulatory, or professional compliance advice and should not be relied upon as such. AI governance requirements vary by jurisdiction, industry, and organizational context. Always consult a qualified legal or compliance professional before implementing policies or making decisions with regulatory implications.

About the author

Johnie T Young

AI expert and governance practitioner helping small teams implement responsible AI policies. Specialises in regulatory compliance and practical frameworks that work without a dedicated compliance function.

  • AI governance practitioner
  • EU AI Act and GDPR specialist
  • AI risk management expert
  • Compliance frameworks for small teams