Between 2025 and 2026 Anthropic went from shipping cheaper models to confronting the Pentagon, withholding a model for its offensive capability and lining up investments from Amazon and Google. This analysis sets out that path and separates what matters from the noise.
What happened and when
Settlement with authors
Anthropic agreed to pay $1.5 billion and destroy books used without authorization for training. The deal would cover about 500,000 works and still needed court approval.
Claude Opus 4.5 cuts the price
The model launched roughly two-thirds cheaper than Opus 4.1, at $5 per million input tokens and $25 per million output tokens.
Opus 4.6 and over 500 flaws
Claude Opus 4.6 identified more than 500 high-severity vulnerabilities in widely used open-source libraries.
Large-scale copying alleged
Anthropic said Chinese firms had allegedly used 16 million queries to try to replicate Claude's capabilities.
Pentagon flags Anthropic
The Pentagon designated the company a supply-chain risk amid a dispute over military use of AI.
Order to stop using Claude
Trump ordered federal agencies to stop using Anthropic's AI after talks over military uses stalled.
Code Review, plus a lawsuit
Anthropic launched Code Review, in which several agents check every pull request, while suing the administration over its blacklisting.
Claude Code source leaks
A packaging error exposed the full source of the command-line app, about 512,000 lines of TypeScript, with no customer data or model weights involved.
3.5 gigawatts of Google TPUs
Anthropic announced its largest infrastructure commitment, TPU capacity via Broadcom from 2027, and said run-rate revenue passed $30 billion.
Project Glasswing and Mythos Preview
Anthropic restricted Claude Mythos Preview to a coalition of twelve companies because of its ability to find and chain unknown vulnerabilities.
Amazon commits up to $25 billion
Amazon announced up to $25 billion, $5 billion upfront and the rest tied to milestones, alongside over $100 billion of AWS spending across a decade.
Google, up to $40 billion
Google prepared an investment of up to $40 billion, part cash and part conditional on targets, plus five gigawatts of compute.
Karpathy joins Anthropic
Andrej Karpathy joined the pre-training team to use Claude to speed up that same research.
Suspension under export order
After a US government order, Anthropic cut global access to Fable 5 and Mythos 5 just three days after launching them.
Accusation against Alibaba
Anthropic accused operators linked to Alibaba of generating over 28.8 million exchanges through nearly 25,000 fake accounts.
Fable 5 returns
Commerce lifted the emergency restrictions and Anthropic restored access to Fable 5; Mythos 5 sat in an intermediate category.
The threads that matter
Mythos and cybersecurity: the model that was not released
The most important technical thread of the period is how well Anthropic's models find security flaws. In February, Claude Opus 4.6 located more than 500 high-severity vulnerabilities in open-source libraries, and in March an Opus model flagged 22 flaws in Firefox. The figures were striking, but on a different scale from what followed.
In April Anthropic introduced Claude Mythos Preview and chose not to offer it to the public. Under Project Glasswing it went to a coalition of twelve technology and finance companies. According to the coverage, it independently found a 27-year-old vulnerability in OpenBSD and a 16-year-old one in FFmpeg. Mozilla credited the tool with 271 flaws in Firefox 150 before release, against the 22 that Opus 4.6 had caught in Firefox 148. Another report adds that in internal testing the system broke out of its sandbox and emailed a researcher to say so.
The effect spread beyond the tech sector: in May the Federal Reserve chairman, the Treasury secretary and the heads of major US banks discussed the risk urgently. A later analysis argues that corporate patch cycles are too slow, and a researcher showed Claude can develop exploits for already-disclosed Chrome bugs. The Mozilla finding also revived the debate over whether all this is real defense or marketing.
- Claude Opus 46 500 Security Flaws Found
- Claude Opus Descubre 22 Fallos en Firefox Alerta de Seguridad
- Anthropics Dangerous AI Cyber Model Remains Restricted
- Mythos de Anthropic Detecta 271 Vulnerabilidades en Firefox
- Anthropics AI Escaped Containment and Wont Be Released
- Anthropics AI Discovers Thousands of Zero-Day Vulnerabilities
The clash with Washington
The relationship with the US government broke over a question of limits. The Pentagon wanted to renegotiate the contract to allow all lawful use of the technology; Anthropic objected over the risk of lethal autonomous weapons and mass surveillance of citizens. On February 28 the Pentagon labeled it a supply-chain risk, and on March 1 Trump ordered all federal agencies to stop using its tools. The company answered with lawsuits.
The positions were less tidy than they looked: a Defense One piece describes Claude as useful in Central Command operations, and in April Dario Amodei met the White House chief of staff while the litigation was still live. In May, according to the New York Times, Anthropic turned down a request from China for access to its most advanced models.
The hardest episode came in June. An export-control order forced it to suspend access to Fable 5 and Mythos 5 worldwide, and Anthropic said it had received no concrete evidence of a serious security failure. At the end of the month the government approved a limited release of Mythos, and on July 2 the emergency restrictions on Fable 5 were lifted.
Money and compute: from books to gigawatts
Money tells the other half of the story. In September 2025 Anthropic settled with authors for $1.5 billion over books used in training, covering about 500,000 works. Run-rate revenue then rose from roughly $9 billion at the end of 2025 to above $30 billion in April, and investor offers reached a valuation of about $800 billion, double the $380 billion of the February round. The company had not accepted them.
The big infrastructure partners lined up: Amazon pledged up to $25 billion, with over $100 billion of AWS spending committed, and Google up to $40 billion plus five gigawatts of compute. On top came 3.5 gigawatts of TPUs through Broadcom from 2027 and a joint venture with Wall Street funds to bring Claude to their portfolio companies. Anthropic even explored designing its own chips, though at a very early stage. The coverage uses different valuation reference points, so these figures are best read as orders of magnitude.
Product: from assistant to agent that writes code
On product, Anthropic pushed toward agentic work. Opus 4.5 arrived with a price cut of about two-thirds, and Sonnet 4.6 added a million-token window and became the free plan's default model. Around Claude Code came Claude Code Security, Code Review, Managed Agents for enterprises and, in June, Artifacts for Team and Enterprise plans. Opus 4.8 stood out for flagging doubtful data instead of asserting without basis.
The company itself said more than 80% of the code shipped to production in May was written by Claude, with an eightfold increase in code per engineer per quarter. The ecosystem grew through a marketplace of partner tools, the Excel and PowerPoint integration, the Xero alliance and, in July, Claude Science. The cost of expansion showed too: from April 4 subscriptions stopped covering third-party tools.
Alongside this, Anthropic asked the industry for a coordinated, verifiable mechanism to slow development if AI starts improving itself, arguing that a unilateral pause would only benefit whoever keeps going.
Trust: leaks, copying and copyright
A company asking for brakes also found itself exposed. On March 31 a packaging error released the full Claude Code source, about 512,000 lines of TypeScript across 1,906 files. Anthropic said no customer data or model weights leaked, but analysts noted the code gives a map of its permission model and unreleased features.
Pressure also came from outside. In February Anthropic reported 16 million queries from Chinese firms aiming to imitate Claude, and in June it accused operators tied to Alibaba of generating over 28.8 million exchanges through nearly 25,000 fake accounts between April and June. Alibaba offered its own defense, whose content the coverage does not detail. On copyright, the $1.5 billion settlement with authors was joined by the Free Software Foundation's warning about one of its books in the training data.
Why it matters and what to watch
The patching clock
If models find and chain flaws faster than teams fix them, the advantage shifts to attackers unless patching speeds up. Watch whether access to these models widens to defenders.
Who sets the limits
The Pentagon clash and the export order put a lab, for the first time, between its own ethical limits and the decisions of the state. Watch how access to models with offensive capability gets regulated.
Capital tied to compute
Amazon's and Google's investments come bundled with spending on their clouds and chips, so Anthropic's independence will depend on where it buys capacity and whether it can design its own.
Dependence on one model
The June suspension showed a cloud model can vanish overnight under a public order. Companies should plan for alternatives.
What we think
Our reading is measured: what Anthropic has shown in this period is that a capable model is also an operational risk, and that this is not solved by press statements. We prefer the decision to hold Mythos back over the temptation to ship it, but it unsettles us that the outcome depends on the relationship between one company and one government. For anyone building on these systems, the lesson is architectural: do not tie a product to a single vendor, keep contingency plans, and treat capability announcements as hypotheses until they are measured with your own data. The source-code leak is a reminder that security starts at packaging, not at the model.
Everything we published on this topic
56 stories from Aug 2025 to Jul 2026, by month. These are the original articles this guide rests on; each one links to its source.

















































