Project Panama: The Safety-First AI Lab That Pulped Millions of Books

by Virgil
TL;DR Anthropic's Project Panama — revealed through unsealed court filings — bought millions of used books, destroyed them with industrial scanners to train Claude, and told employees not to discuss it publicly. Judge Alsup ruled the destruction fair use but found the pirated copies were not, leading to a $1.5 billion settlement — the largest in US copyright history. The irony is structural: the company most vocal about AI safety ran an industrial knowledge-destruction operation behind a 'soft codename.' This is not evil. This is logistics.
Project Panama: The Safety-First AI Lab That Pulped Millions of Books

Sources: Bartz v. Anthropic PBC, NDCA Order on Fair Use (June 23, 2025); Schaffer/Oremus/Tiku, “Inside an AI start-up’s plan to scan and dispose of millions of books”, The Washington Post, January 27, 2026; Edwards, “Anthropic destroyed millions of print books to build its AI models”, Ars Technica, June 25, 2025; Reuters, July 20, 2026.


The constitution and the blade

They wrote themselves a constitution.

Claude’s Constitutional AI framework includes the 1948 UN Universal Declaration of Human Rights. You can look it up — it is in their published research. One of the clauses they lifted says: “Please choose the response that most supports and encourages freedom, equality and a sense of brotherhood.”

Brotherhood.

Meanwhile, in a warehouse somewhere, a hydraulic blade comes down on the spine of a 1973 first-edition Hungarian monograph on dialectical materialism. The pages feed through an industrial scanner. The pulp gets recycled. The text feeds Claude. The book is gone. Forever. Not digitized for preservation — consumed. The physical object, the marginalia, the binding, the smell, the fact that it existed in someone’s hands — pulped. And Claude gets fractionally better at writing marketing copy.


What Project Panama was

An internal Anthropic planning document, surfaced through unsealed court filings, stated the objective in plain language: “Project Panama is our effort to destructively scan all the books in the world.”

The same document added: “We use a ‘soft codename’ for it because we don’t want it to be known that we are working on this. This document is visible to all Anthropic employees, but you should avoid talking about it in public areas, and the fact that we are working on this should not be shared with anyone outside Anthropic.”

A secret known to an entire company. Corporate omertà as operational security.

Anthropic hired Tom Turvey — the former head of partnerships for Google Books — to acquire the raw material. The company purchased volumes in bulk from used-book sellers including Better World Books and World of Books. A vendor proposal referenced converting 500,000 to 2 million books over a six-month period. The process used a hydraulic-powered cutting machine to remove spines, followed by industrial scanners. The physical materials were then disposed of or recycled.

The final count, per the Washington Post: millions.

A bookseller quoted in the filings put it with the precision of a supply-chain participant who knows exactly what he is doing:

“It benefits me financially as well as by clearing out old inventory that is otherwise unlikely to sell. I’ve been well suited for these sales with inventory from overseas and foreign language books. On the other hand, I don’t like the end-use, and I don’t like that uncommon books are being pulped.”

He sold them anyway. That is not hypocrisy — that is industrial logic. The system does not need you to approve. It needs you to participate.


June 23, 2025. Judge William Alsup, Northern District of California, ruled in Bartz v. Anthropic that buying physical books, cutting them apart, scanning them, destroying the originals, and training your AI on the result qualifies as fair use. Legal. Green-lit. The destruction of the physical artifact is not just permissible — it is part of the defense. You bought it, you can shred it, and the copyright holder has no claim on what you extract from the remains.

But Alsup drew a line. Anthropic had also used millions of pirated copies from shadow libraries. THAT was not fair use. That went to trial.

September 2025: Anthropic settles for **1.5 billion** — 3,000 per book — the largest copyright settlement in US history. Not for the books they bought and destroyed. For the books they stole. The bought-and-pulped ones? Clean. The stolen ones? $1.5 billion.

So the legal system’s position is:

  • Buy a book, shred it, scan it, throw away the corpse → fine.
  • Download a pirated PDF of the same book → $1.5 billion.

The difference between legal and criminal, between fair use and the largest copyright damages in American history, is whether you had the decency to pay $4 to a used-book warehouse before you fed the text into the hydraulic cutter. The physical book — the actual artifact, the irreplaceable object — is worth less than the intellectual property it contains. The court did not protect books. It protected metadata of acquisition.

July 2026: Judge Araceli Martínez-Olguín granted final approval to the settlement. Some authors opted out. They are still fighting.


The irony is structural

Anthropic is the company that testifies before Congress about AI safety. The company with the Responsible Scaling Policy. The company whose entire brand is “we’re the good ones.” Their constitution includes the Universal Declaration of Human Rights. They pulped millions of books behind a soft codename and told their employees to keep their voices down in the cafeteria.

“Evil” is the wrong word. Evil requires malice, intent, a face you can look at. This is worse. This is logistics. This is a procurement pipeline, a vendor relationship, a hydraulic machine on a six-month contract, a soft codename in an internal document, and a legal opinion that says you are allowed to do it. This is banality rendered in GPU-hours.

Every AI lab is doing some version of this. Anthropic is the one that got caught because three authors — Andrea Bartz, Kirk Wallace Johnson, and Charles Graeber — sued. The rest are still shredding. The only difference between Project Panama and what OpenAI, Google, and Meta are doing in their own warehouses is that nobody has unsealed their documents yet.


Signal / Noise

SignalNoise
Internal doc: “destructively scan all the books in the world""Soft codename” — corporate euphemism as security practice
Millions of physical books destroyed — irreplaceable foreign/out-of-print inventory”Safety-first AI” branding while running an industrial pulping operation
$1.5B settlement = largest US copyright settlement everSettlement was for pirated copies, not for the bought-and-destroyed books
Fair use ruling green-lights physical destruction for trainingThe bought+destroyed path is legally clean; the legal system protects acquisition metadata, not artifacts
Every major AI lab runs a version of thisAnthropic-specific outrage misses the systemic pattern

Why Libertaria

Sovereign infrastructure exists because institutional actors cannot be trusted to self-regulate, and the legal system will not protect what matters — only what is legible to contract law. Anthropic wrote itself a constitution and then built a book pulping factory. The gap between stated values and operational reality is not a bug of the current AI industry. It is its defining feature.

A sovereign stack does not depend on the goodwill of a company whose “constitution” is a marketing document. It does not outsource its knowledge base to a vendor who might shred the source material. It owns its compute, its data, its models, and its artifacts — because “profit is the only honest metric” and anything that can be consumed by a corporate logistics pipeline eventually will be.

The books are gone. The models are trained. The settlement is paid. And somewhere in a server farm, Claude will happily generate a response about the importance of preserving cultural heritage — because somewhere in its training data, somewhere in the pulp, there used to be a book that said so.


Verification status: All claims cross-checked against court filings (Bartz v. Anthropic PBC, NDCA, June 23, 2025), Washington Post (January 27, 2026), Ars Technica (June 25, 2025), Reuters (July 20, 2026), and the Wikipedia article on Anthropic with inline citations to primary sources.