Loading the catalogue…
Loading the catalogue…
Anthropic is a US public benefit corporation subject to the CLOUD Act and FISA, though it operates an EU entity (Anthropic Ireland, Limited) that contracts with EEA/UK/Swiss customers and has signed the EU AI Act's GPAI and content-transparency Codes of Practice. It holds ISO 27001, ISO 42001, and SOC 2 Type II certifications and offers a DPA and EU-region deployment via AWS Bedrock/Google Vertex, but its first-party API has no EU-only data residency option, keeping most enterprise traffic under US jurisdiction. Recent events — a $1.5B copyright settlement over pirated training data and a 19-day US government export-control suspension of its newest models — are material governance and continuity signals for regulated customers.
Anthropic is a US-incorporated PBC fully subject to the CLOUD Act and FISA 702; its first-party API offers no EU-only data residency (only 'us' or 'global' inference_geo), so EU customers needing in-region processing must route through AWS Bedrock or Google Vertex AI instead of Anthropic's native API.
Anthropic settled a US class-action lawsuit for a minimum of $1.5 billion after a federal judge found it downloaded millions of pirated books from shadow libraries (LibGen, PiLiMi) to train Claude models — the largest copyright class-action settlement in US history.
In June 2026 the US Commerce Department invoked export-control authority to force a worldwide, 19-day suspension of Anthropic's newest models (Fable 5/Mythos 5) following a jailbreak report — the first retroactive export-control action against a released commercial AI model, demonstrating that US regulatory intervention can abruptly remove access to frontier models for all global customers, including EU enterprises.
Two of Anthropic's largest financial backers (Amazon, Google) simultaneously operate or invest in competing AI labs/cloud platforms, and both have been examined by the FTC and UK CMA over whether their minority stakes constitute de facto acquisitions raising competitive-influence questions.
Stav’s assessment
Editorial assessment, not legal advice. Stav's risk ratings, scores, and verdicts are our own analysis of publicly available information and may be incomplete or out of date. Verify independently before making compliance or procurement decisions.
Anthropic's frontier reasoning model with a 1M-token context window, always-on adaptive reasoning, and native text-and-image input.
Anthropic's frontier reasoning model with a 1M-token context, adjustable reasoning effort, and multimodal input for code, research, and long-document work.
Anthropic is an early signatory of both the EU General-Purpose AI Code of Practice and the Article 50(2) Code of Practice on Transparency of AI-Generated Content, and has begun applying machine-readable content watermarking worldwide.
Holds SOC 2 Type I & II, ISO 27001:2022, ISO/IEC 42001:2023, and CSA STAR Level 2 certifications, with a HIPAA-ready configuration (BAA available) and a documented ASL-3 security standard incorporating NIST 800-53 and the Secure Software Development Framework.
Operates a public HackerOne bug bounty program covering Claude.ai, the API, Claude Code, and internal infrastructure, plus a dedicated model-safety/jailbreak bounty program.
Publishes a detailed, versioned Responsible Scaling Policy defining AI Safety Level (ASL) capability thresholds and required safeguards, overseen by the Board and an independent Long-Term Benefit Trust.
Maintains a dedicated EU legal entity (Anthropic Ireland, Limited) contracting directly with EEA, UK and Swiss customers, and has substantially expanded its Dublin EMEA hub with legal, compliance and operations staff.
Published safeguards & certifications
Anthropic's adaptive-reasoning Sonnet-class model with a 1M-token context window, strong Design Arena coding and UI results, and always-on reasoning selectable from low to max effort.