By Qaiser Nawab
On September 12, Anthropic chief executive Dario Amodei called for slowing the development of increasingly powerful artificial intelligence systems. His proposal included closer coordination among leading AI companies and permanent access for independent safety evaluators. The announcement attracted attention because it came from the head of one of the companies actively developing the technology whose advancement he wanted to manage more carefully.
The timing merits examination. Just two days earlier, Anthropic had published a detailed threat-intelligence report documenting its investigations into the misuse of Claude. The company had also introduced new data-retention requirements for certain advanced models earlier in the year. On September 22, it released Claude Opus 5.5, promoting improvements in performance, efficiency and safety.
Together, these developments illustrate a significant transformation within the American AI industry. Companies that initially attracted customers through technological innovation are expanding their activities into threat intelligence, security monitoring and the development of standards that could influence the industry’s future.
Anthropic offers a particularly revealing example of how these activities are becoming interconnected.
The expansion of data collection
One important development occurred on June 9, when Anthropic introduced new data-retention requirements for designated advanced models.
Under these arrangements, prompts and outputs associated with covered models must be retained for 30 days to support security monitoring. The change affects certain enterprise customers and developers that previously operated under zero-data-retention agreements.
Anthropic maintains that sophisticated misuse can become apparent only when activity is examined across multiple interactions. It has consequently established requirements that alter the data-handling arrangements available to organisations seeking access to its most capable systems.
The commercial implications deserve attention.
Businesses increasingly use AI to process proprietary information, develop software, conduct research and manage confidential operations. For customers with strict data-handling requirements, mandatory retention can influence procurement decisions and the selection of available models.
Anthropic has introduced additional safeguards, including restricted human review, access logging and arrangements under which certain customers can retain monitoring data within infrastructure they control. Its requirements also differ across products, with existing arrangements remaining available for models outside the covered category.
Nevertheless, the policy demonstrates how AI providers can determine the conditions under which customers access their most advanced technology.
These conditions extend beyond price and technical performance. They increasingly include mandatory security arrangements, monitoring requirements and restrictions on how customers manage their information.
The distinction between retaining data for security purposes and using customer information for commercial model training is important. The two activities are governed by different arrangements and should not be confused.
Equally important is the distinction between collecting information and disclosing it to government authorities. Anthropic’s published policy states that government requests for customer information generally require valid legal process, with a limited exception for emergencies involving imminent physical harm.
The substantive issue is therefore not an unverified allegation of unrestricted government access. It is the documented expansion of the security-monitoring arrangements accompanying access to some of the industry’s most powerful commercial products.
From model developer to threat-intelligence provider
Anthropic’s activities now extend considerably beyond developing and selling AI models.
Its threat-intelligence operation investigates suspected malicious activity involving Claude and produces reports describing emerging security threats. Its September report examined incidents identified between December 2025 and August 2026, covering cyber operations, surveillance, influence operations, fraud and other activities.
Anthropic reported disrupting the activities it investigated and sharing relevant intelligence with authorities and industry partners where appropriate.
This represents an important development in the American AI industry’s business and security operations.
The information available to major AI providers allows them to identify patterns across numerous interactions, investigate suspected misuse and develop technical indicators that may assist other organisations.
Anthropic’s investigations into unauthorised model distillation illustrate this capability. The company has documented large-scale attempts to extract Claude’s capabilities, identified suspected operators and developed measures intended to detect and prevent similar activity.
Its reports distinguish legitimate distillation, an established machine-learning technique, from activity that Anthropic considers unauthorised. These classifications inform the company’s enforcement measures and its published security assessments.
Such investigations demonstrate the considerable amount of technical and operational information available to companies operating advanced AI platforms.
They also create a new relationship between commercial technology development and security intelligence.
AI providers are increasingly positioned to collect evidence of suspicious activity, analyse potential threats and distribute selected findings to external institutions.
Anthropic’s published reports provide valuable information about its investigations. However, the evidence available to the public is necessarily different from the internal information available to the company. Independent verification therefore becomes particularly relevant when corporate findings inform broader security assessments or regulatory discussions.
The question extends beyond Anthropic. As other American AI companies develop comparable monitoring and threat-detection capabilities, the industry is acquiring a larger role in the production and distribution of security intelligence.
Understanding that expanding role requires attention to the information companies collect, their investigative procedures and the institutional arrangements governing their cooperation with external authorities.
When industry security becomes industry policy
Anthropic’s September proposal adds another dimension to these developments.
Amodei proposed embedding independent evaluators within frontier AI companies and increasing coordination among major developers. His proposals also raised questions about how competitors might cooperate on safety measures within existing competition-law frameworks.
These proposals would give industry participants a substantial role in shaping the procedures governing advanced AI development.
The issue is commercially significant because compliance requirements can affect the costs, resources and institutional capabilities needed to develop and release new models.
Established companies possess considerable computing infrastructure, specialist personnel and established safety departments. Smaller developers may operate with considerably fewer resources.
The implications of coordinated industry standards therefore extend beyond safety. They include market access, compliance costs and the conditions under which new companies can compete.
These concerns have already appeared in international industry discussions. Following Amodei’s announcement, European AI companies and technology executives questioned aspects of the proposed slowdown. Some argued that arrangements designed around established American developers could reinforce existing market advantages. These remain competing interpretations of the proposals rather than established evidence of Anthropic’s intentions.
Anthropic, meanwhile, has continued developing and releasing new technology.
Its September 22 launch of Claude Opus 5.5 followed its call for a more measured pace of development. The company reported that the new model had undergone external evaluation and incorporated additional safeguards. It also promoted lower operating costs and improved performance.
The release demonstrates that Anthropic’s proposal concerns the conditions and pace of advancement rather than a complete suspension of innovation.
This distinction is central to understanding the American industry’s emerging approach. Major developers are seeking to advance their products while simultaneously participating in the creation of security requirements intended to govern increasingly capable systems.
Whether these arrangements develop primarily through corporate agreements, independent technical institutions or public regulation will have considerable consequences for the structure of the AI market.
Anthropic’s experience highlights how closely technological development, commercial strategy, security monitoring and regulatory proposals have become connected.
The American AI industry is no longer operating solely as a supplier of digital products. Its leading companies are increasingly participating in decisions about how advanced systems are monitored, investigated, evaluated and released.
These decisions will influence developers, businesses and institutions well beyond the United States.
For that reason, the expansion of corporate security functions deserves examination alongside the industry’s technological achievements. Anthropic’s evolving business practices provide a concrete opportunity to understand this emerging structure and its implications for the global AI market.

The writer is Chairman of the Belt and Road Initiative for Sustainable Development (BRISD). He can be reached at qaisernawab098@gmail.com

