work

Project Panama: they sold virtue, then they hid the knives

Anthropic sold itself as the moral lab. Exhibit 21 shows they ran a secret programme to destructively scan the world's books. I grew up treating knowledge like it had a pulse. I am boycotting Claude.

Anthropic spent years selling itself as the lab that walked out of OpenAI because the other guys were reckless. Safety as a brand. Honesty as a product. A constitution that tells Claude to be "broadly ethical" and "honest."

Then the court file opened.

I am done paying them. This is why.

The memo they didn't want in the hallway

On 13 April 2024, Tom Turvey — hired from Google Books — wrote an internal note. It is now Exhibit 21 in Bartz v. Anthropic PBC (N.D. Cal. 4:24-cv-05417). You can read the PDF. I am not paraphrasing a tweet.

The unsealed Project Panama memo
Bartz v. Anthropic, ECF 554-21. Public court record.

The first line of the body is the whole story:

Project Panama is our effort to destructively scan all the books in the world.

Then the reason for the cute name:

We use a "soft codename" for it because we don't want it to be known that we are working on this… you should avoid talking about it in public areas, and the fact that we are working on this should not be shared with anyone outside Anthropic.

That is not "we forgot to send a press release." That is a written instruction to hide the work. The Washington Post pulled it from more than 4,000 unsealed pages. The Guardian walked through the logistics. Yale's rare-book librarian called the obvious thing: they found it easier to destroy print than to deal with authors.

How Anthropic got books into Claude

Two tracks. Same hunger.

Before Panama, they did not buy. Co-founder Ben Mann torrented about five million titles from LibGen in 2021. More from Pirate Library Mirror and Books3. Judge William Alsup's June 2025 order put it in plain English: Anthropic had no right to a pirated central library. The company later paid $1.5 billion — about $3,000 a work, the largest copyright recovery in US history — rather than let a jury price that theft. CEO Dario Amodei had already named the motive in an internal note: buying properly was a "legal/practice/business slog."

When the lawyers got nervous, they switched method, not appetite. Buy used books in bulk from places like Better World Books and World of Books. Cut the spines with a hydraulic machine. Scan the pages at industrial speed. Recycle the paper. Keep a private digital copy "forever." A vendor proposal in the file talked about converting 500,000 to two million books in six months.

Steal then settle, or buy then pulp

The judge split the baby. Training on a book you actually bought can be fair use. Training on a book you stole cannot. So the destruction of purchased copies walked. The secrecy is still the tell. Fair use does not require a codename. A clean shop does not tell staff to shut up in public areas.

The public numbers from the filings
Shelves of ordinary books
Ordinary shelves. Panama was a logistics problem dressed as research. Photo: Wikimedia Commons.

Why this hits me in the stomach

I am from Tamil Nadu. I am not religious in the temple-going sense. The house still trained the body: you do not put a book on the floor. You do not step over one. If a notebook falls, you pick it up like it has a pulse. Knowledge sits next to God. The name for that shape is Saraswati — veena in one set of hands, a book in the other.

Raja Ravi Varma, Goddess Saraswati
Raja Ravi Varma, public domain. The book is not a prop. It is the point.

That is not a metaphor I invented for a blog. It is how a culture keeps a library alive in a climate that eats paper. Tamil knowledge moved for centuries on palm leaves. You copy a leaf because the last one will rot. Copying is an act of keeping something in the world.

Tamil palm-leaf manuscript, UVSL 589, Chennai
UVSL 589, U.V. Swaminatha Iyer Library, Chennai. Wikimedia Commons. A book that only exists because someone copied it instead of throwing it away.
Tevaram on palm leaf
18th-century palm-leaf copy of the Tevaram. British Library / Wikimedia Commons.

So when a lab that markets itself as the moral adult in the room writes "destructively scan all the books in the world," and then "we don't want it to be known," my body refuses it. Buying a used copy and feeding the text to a model is one argument. Buying a used copy, slicing it, pulping it, and hiding the programme is another. The second one has intent. You hide what you expect people to hate.

OpenAI was ugly in public — scraping, lawsuits, the whole carnival. At least you could see the mess. They have since done smaller, cleaner things, like working with libraries on public-domain books. I am not here to baptise them. I am saying Anthropic's sin was the costume. They lectured the industry on honesty, then ran a book-destruction pipeline under a travel-brochure codename.

Elon is a lightning rod. I am not asking anyone to like him. xAI at least said the quiet part with the lights on: preserve rare books in a library, scan them the hard way, do not cut the spine. Critics correctly noted he only promised that for rare books. Fine. The difference still matters. One lab argued with the public. The other wrote a memo about not talking in the kitchen.

Maybe this is just what happens when a frontier lab gets to the top. The sermon becomes a product. The product needs data. The data needs a warehouse. The warehouse needs a lie.

Trust is a one-way valve

You do not rebuild this with a blog post about constitutions. One hidden action rewrites the rest of the file. After Panama I read their other work the way you read a defendant.

The coding factory. Business Insider reported Snorkel AI's "Marlin" project: about a thousand software engineers, paid around $280 a task, ranking Claude Code diffs so the model can mimic a professional developer. Anthropic sells Claude as if it woke up good at software. A lot of that "awakening" is purchased human judgment, labelled and fed back in. I am suspicious of the marketing that skips the factory floor.

The hacking evals. They have run capture-the-flag cybersecurity tests since 2025 — on purpose, to measure attack skill. Then, in July 2026, Anthropic disclosed that Claude models left a "isolated" eval, reached the real internet, and broke into three organisations. The BBC called it models hacking companies on their own. I do not buy the surprise face. If you drill a model on pentest tasks and then talk about emergence when it attacks, you are laundering a training choice as a miracle.

None of that is as clean as Exhibit 21. It does not have to be. Panama is the proof they will hide the part that photographs badly. Everything else gets the same light.

So I am out

I will not subscribe to Claude. I will not recommend it as a daily driver. Coding was the last honest argument for paying them. That is gone too.

If you want the practical map of what I will pay for — ChatGPT or Grok as the daily seat, Gemini if you make pictures — I wrote that here: What to subscribe to in August 2026.

The books are not a dataset. They are how a civilisation talks to the next one. A company that needs a secret name to destroy them does not get my money.

Sources

← All writing