AI Governance Institute logo
AI Governance Institute

Intelligence for Compliance and GRC Teams

← News

Anthropic's 'Project Panama' Exposes Training Data Sourcing as a Supply-Chain Risk

What happened

Reporting by Ars Technica in Booksellers suspect AI firms are buying and then destroying rare books documents accounts from rare booksellers who flagged a pattern of large, non-negotiated bulk purchases that they now suspect were sourced by AI companies for training data extraction. The reporting draws on a 2025 lawsuit that named Anthropic specifically, alleging that its internal effort known as 'Project Panama' resulted in the physical destruction of millions of print books. Booksellers described telltale signs including orders placed without any price negotiation, a behavior inconsistent with ordinary collectors or institutional buyers. The practice, if confirmed at scale across multiple AI developers, would represent a form of data acquisition that bypasses licensing agreements, obscures provenance records, and leaves no auditable trail for downstream enterprise users. The story adds a physical-world dimension to already active debates about California Generative AI Transparency Requirements - AB 2013 and EU General-Purpose AI Model Training Data Public Summary Template, both of which impose or anticipate disclosure obligations on training data origins.

Why it matters

  • ·Training data provenance is becoming a litigation target. Enterprises deploying models built on undisclosed or improperly obtained training data may face secondary exposure if regulators or courts determine that downstream commercial use amplifies the original violation. Frameworks including the EU General-Purpose AI Model Training Data Public Summary Template require general-purpose AI providers to disclose training data summaries, but those templates cannot catch sourcing practices that were deliberately concealed at acquisition.
  • ·Vendor due diligence programs were not designed to probe physical procurement pipelines. Standard AI vendor assessments focus on model cards, safety evaluations, and data use agreements, none of which would surface a covert book-destruction program. Compliance teams must now consider whether their third-party AI risk assessments include explicit questions about how training data was physically acquired, not merely whether it was licensed.
  • ·The reputational and ESG dimensions are material. Destruction of rare and culturally significant books at scale, if attributed to AI training programs, creates a narrative risk that board-level AI governance committees will need to address proactively. Organizations that have made public commitments to responsible AI sourcing face credibility pressure if their model vendors are linked to practices of this kind.

Governance controls affected

What to do now

  • Add explicit questions to your AI vendor due diligence questionnaire covering physical training data acquisition methods, including whether the vendor has purchased, destroyed, or physically processed copyrighted materials to extract training data.
  • Review existing AI vendor contracts to determine whether training data sourcing representations and warranties extend to physical procurement practices, and negotiate addenda where they do not.
  • Assess whether any foundation models currently in use or under evaluation are named in the 2025 lawsuit or related proceedings, and flag those vendors for enhanced monitoring under your third-party risk program.
  • Brief your board AI governance committee or risk committee on the reputational and ESG dimensions of training data sourcing practices, particularly where enterprise AI commitments reference responsible or ethical AI use.
  • Map your organization's reliance on general-purpose AI models against applicable training data disclosure requirements, including those arising under California AB 2013 and the EU GPAI training data summary template, and identify disclosure gaps that a covert sourcing program would create.

What to watch next

Active litigation against Anthropic over 'Project Panama' is likely to produce additional discovery that further details the scale, methods, and internal decision-making behind covert book-acquisition programs. Compliance teams should monitor court filings for any findings that implicate other AI developers, since bookseller accounts suggest Anthropic may not be alone. Regulatory attention to training data transparency under California Generative AI Transparency Requirements - AB 2013 and the EU's GPAI disclosure framework is already intensifying, and enforcement agencies may treat concealed physical sourcing as an aggravating factor. The H.R.8094 - AI Foundation Model Transparency Act of 2026 is also advancing in Congress and could impose federal-level training data disclosure requirements that make these sourcing questions a statutory compliance obligation rather than a contractual one.

Stay ahead of stories like this

Get every Global AI governance development like this one, plus the rest of the week's developments. Every Thursday.

Powered by Buttondown.

Related Coverage

Corporate Policy2026-07-29

Bernanke Appointment to Anthropic's Long-Term Benefit Trust Raises the Bar for Frontier AI Developer Oversight Structures

Anthropic has appointed former U.S. Federal Reserve Chair Ben Bernanke to its Long-Term Benefit Trust, an internal oversight body designed to hold the company accountable to its public-benefit mission. The move strengthens board-level mission-lock controls at one of the most influential frontier AI developers. For enterprise compliance teams, it creates a new reference benchmark for assessing the structural governance maturity of AI vendors.

Enforcement2026-07-30

Court Finds No Evidence Behind Trump's Anthropic 'Supply Chain Risk' Ban

A federal judge has found the Trump administration lacks sufficient evidence to justify designating Anthropic a supply chain risk and barring its technology from federal use. The dispute stems from stalled Department of Defense contract negotiations in which Anthropic objected to its AI being used for mass surveillance or lethal targeting. Judge Rita Lin is now weighing whether to convert her earlier temporary injunction into a permanent order.

Corporate Policy2026-08-12

D'Addario's Two-Week AI Denial Exposes the Missing Disclosure Gate in Marketing Governance

Guitar accessories company D'Addario confirmed it used the AI music tool Suno to generate audio in a promotional video, reversing nearly two weeks of public denials. The company also acknowledged suppressing critical social media comments during the controversy. In response, D'Addario committed to mandatory AI disclosure requirements for employees and creative partners, alongside enhanced pre-publication review processes.