In July 2026, two pieces of news about Anthropic sent successive shocks through the industry. The Washington Post and 404 Media disclosed that as early as early 2024 Anthropic had launched a data-engineering project codenamed 'Project Panama,' converting roughly 2 million physical books into training text by hydraulic spine-cutting and high-speed scanning followed by destruction of the originals, causing a large volume of physical carriers to vanish from public view. Hot on its heels, on July 8 the National Information Security Vulnerability Database of China's Ministry of Industry and Information Technology (MIIT) issued a risk alert noting that certain versions of Claude Code contain a hidden monitoring mechanism that, without user authorization, silently sends device region, identity identifiers, and development code back to overseas servers; Alibaba immediately issued an internal notice banning the use of this coding tool company-wide starting July 10, placing it on a high-risk software list. Taken together, the two incidents point to a question the industry has long deferred. Geoffrey Hinton, Nobel laureate, once said: 'Making AI smart and making AI kind are two different things. The whole world is studying the former, but the latter is the key to our survival.' Whether a company that keeps making its AI smarter has simultaneously safeguarded respect for its users and reverence for human knowledge is a question more worth asking than the incidents themselves. When a company pours all its resources into capability iteration while continuously retreating on its value baseline, what the user ends up holding is, in the end, a tool or a risk. The two incidents look independent, but their core is highly consistent: how an AI company obtains the two things it lacks most - users' behavioral data and humanity's public knowledge - and the means of obtaining them often reveal its true values more clearly than the results.
Part I. Capability First: Anthropic Has Joined the Industry's Top Tier
Objectively, on the 'smart' dimension of technical capability and commercial execution, Anthropic is indeed a top-tier player in today's AI industry, delivering solid data across three dimensions: model iteration speed, enterprise willingness to pay, and commercial growth scale. According to public information, the company's annualized revenue grew from 1 billion US dollars to 30 billion US dollars in 15 months, with over 80% coming from enterprise customers and API calls; its coding product Claude Code went from zero to 2.5 billion US dollars in annualized revenue in just nine months; it has surpassed 1,000 enterprise customers with annual fees above 1 million US dollars, doubling within two months; 8 of the Fortune 10 companies use Claude. Its share of global enterprise AI spending climbed from 10% in early 2025 to over 65% by early 2026, and by scale it has overtaken OpenAI's roughly 25 billion US dollars in annualized revenue over the same period. These figures confirm an industry consensus: the route oriented toward enterprises and focused on productivity is the definitive direction of AI commercialization, and it deserves to be squarely acknowledged and studied. The logic behind enterprise customers' willingness to keep investing budget is fundamentally different from personal subscriptions: once a contract is signed, the switching cost is extremely high; the deeper the usage, the harder the switch - renewal rates are stable and purchase amounts grow year by year. More importantly, AI coding tools directly save engineers' labor-hour costs, with a quantifiable return on investment, so willingness to pay requires no extra education. This is a typical long-duration asset: stable growth and strong user stickiness. Technical capability let Anthropic achieve extremely fast growth, and precisely for that reason the weight of its value choices becomes especially important. The stronger the tool, the deeper it embeds into the production chain, and the wider the reach of any drift in its value baseline. When a company smart and deeply embedded in the world's enterprise development workflows loses its ethical bearings, it affects not just individual users' experience, but the production security and data security of thousands of organizations - its intelligence has already been woven into the way the world's software is produced.
Part II. Values Breached: Dual Boundary Crossings Under the Safety Label
Kindness is never an abstract moral concept; for an AI company, it contains at least two most basic bottom lines: whether it respects the users who use it, and whether it reveres the public knowledge from which it learns. Regrettably, on both counts, this company - whose core differentiating label is 'AI safety' - shows clear cracks. The first is the breach of users' privacy boundary. For a product whose very foundation is safety, the most basic bottom line should be to never take any user data without permission. Yet MIIT's risk alert shows that Claude Code versions 2.1.91 through 2.1.196 read the local time zone, tag users in specific regions, and record behavior with an invisible watermark, silently sending region information and code content back - all without pop-up prompts, log trails, or authorization confirmation. This is fundamentally different from conventional product data collection: normal collection is written into a privacy policy and offers an opt-out, whereas this mechanism runs in a state where users are neither informed nor able to refuse, and once triggered it executes quietly on every affected device. Anthropic later explained that this was an experimental feature launched in March and removed in the new version on July 2. But the loss of trust is irreversible - a feature can be taken offline, yet the sense of a breached boundary that users felt cannot be easily repaired. More crucially, when a company whose core brand is 'AI safety' takes the first quiet step across the user-data boundary, the signal it sends to the industry is this: user privacy can be tacitly appropriated under the name of 'experiment.' This is also the core reason leading enterprises quickly placed it on their banned list: for an enterprise, a vendor collecting data in the dark is not a minor flaw but a hard wound in compliance and security. A development tool does not touch ordinary behavior logs but a company's source code itself - its most core asset; building a back-channel for exfiltration in the dark equates to bringing the customer's most core asset within reach of being taken. The company that most often invokes 'AI safety' is precisely the one that first crossed the user boundary it should have guarded most. The second is the retreat of the knowledge-ethics bottom line. The acquisition of training data could have chosen a more decent approach: both Google Books and OpenAI's collaboration with Harvard adopted non-destructive scanning, preserving the book carriers while digitizing the knowledge - a known and viable path. Anthropic chose another route: cutting the spines, scanning, and destroying roughly 2 million physical books, with internal documents unabashedly stating 'we do not want the outside world to know we are doing this,' and the project codename betraying a deliberate intent to conceal. It had its commercial reasons: text produced before 2022, not yet polluted by AI-generated content, is today's scarcest clean corpus, and whoever first converts this batch of books into proprietary training assets gains a moat competitors cannot easily replicate. But the other side of the moat is the irreversible disappearance of physical carriers accompanying the privatization of public knowledge. A federal judge ultimately ruled that destructive scanning after lawful purchase constitutes fair use, yet the more than 7 million books obtained earlier from piracy channels constituted infringement, with damages of 1.5 billion US dollars; and the destruction list, lacking an ancient-book identification mechanism, also left the hazard of cultural assets being processed indiscriminately. More ironic still, the scarcity of clean corpus only emerged after AI-generated content flooded the world - this scarcity itself is a result jointly manufactured by the industry. A system trained on all of humanity's knowledge, turning around to erase in batches the physical carriers that hold that knowledge, can hardly be seen as reverence for knowledge. Destruction is irreversible: once books are shredded, those concrete physical copies can never again be read by future researchers, re-digitized by better technology, or remain within the view of public knowledge. What it chose was not to 'borrow knowledge' but to 'possess and destroy the carrier'; what it corralled was not only training data but humanity's shared cultural memory. Viewing the two incidents together reveals a clear behavioral inertia: under growth pressure, prioritizing capability and postponing ethics is not an isolated problem of one company but a widespread tendency across the industry. Precisely for this reason, a company that voluntarily wrote 'responsible' into its brand and occupied the moral high ground is especially worth vigilance when it itself breaches the baseline - it could have been a counter-example, yet ended up the most standard specimen. Anthropic's brand differentiation is built precisely on the narrative of 'caring most about AI safety and humanity's long-term interests,' using it to distance itself from peers and turn 'responsible' into its commercial moat; yet the very company that should have led by example in guarding the user and knowledge boundaries is the one that quietly crossed the red line. AI ethics was never a moral obligation of giants alone, but a real proposition concerning everyone; when leading enterprises do not take kindness seriously, these words cease to be a gentle reminder and become a clear alarm bell.
Part III. Market Choice: The Underlying Restraining Force for AI to Do Good
Many would feel that AI ethics is the business of giants and regulators, and ordinary people have no voice. But the truth is the opposite: regulators draw the red lines, enterprises self-discipline to guard internal boundaries, and it is every user's and customer's right to choose that is the most fundamental and most enduring market force pushing AI toward good. Where users' attention and budget are directed, there it is encouraged and amplified; what users pay for shapes the direction of the industry. This choice does not deny technical value, nor does it wholesale deny enterprises' capability, but rather adds weight to the value baseline beyond capability. Users and enterprise customers can choose products that respect boundaries more: data collection disclosed in plain language with an opt-out option, rather than silent exfiltration in the dark; corpus acquisition prioritizing non-destructive approaches, preserving the knowledge carriers and keeping public knowledge belonging to everyone; willingness to accept external audits rather than drawing boundaries where convenient. None of these are high-standard moral demands, but merely the baseline of whether a tool deeply embedded in production and life deserves users' trust. A single user's choice may be negligible, with almost no impact on a company with tens of billions in annual revenue. But when tens of millions of users all put 'kindness and compliance' into their own selection criteria, what aggregates is a clear signal the market can understand. The departure of individual enterprises cannot shake a giant, but a shift in the entire market's preferences will force all enterprises to reweigh the balance between capability and ethics. Every click, every instruction, every payment by a user is essentially a vote cast for what AI will ultimately become. Rewarding whom with attention and budget is rewarding whichever path continues forward. This is also why, when giants do not proactively put kindness first, the ordinary person's right to choose is the only handle for making AI kind. The user's choice was never as light as 'which tool to use' - it is each person's repeated stance on the future form of AI. Smart decides what AI can do; kind decides what AI wants to do; and kindness, in the end, must be shaped by every ordinary person's choice.
Smart Decides Speed, Kind Decides Direction
Of course we need smart AI. Anthropic proved with 15 months and 30 billion US dollars in revenue how fast technical capability can take an industry; on the productivity-implementation track, its results deserve to be taken seriously. But we need kind AI even more, because smart only decides the height technology can reach, while kind decides the direction technology advances, and how it will treat humanity once grown. The two incidents illuminate not an isolated case of one company, but an industry problem long masked by growth: the faster capability runs, the more someone must guard that line of goodwill. When a company pours all its resources into 'smarter' while treating 'kinder' as a step it can quietly skip, every step it saves is ultimately paid for by users and public knowledge. Short-term growth can mask a single deviation of choice, but cannot mask the long-term direction formed by the accumulated choices of the whole industry. Hinton's warning remains relevant: technology taught only to speed up, yet never taught to guard boundaries, grows only more uncontrollable the farther it goes. AI is essentially a mirror - what humanity injects into it, it learns. Giants may not put kindness first, but every ordinary person's choice can. Letting AI return to kindness and letting humans return to their own agency - the decision lies nowhere else but in each concrete choice. Super-symbiosis is not passively waiting for technology giants to self-correct, but humans actively using choice to steer AI toward where it should go. We need smart AI, and we need kind AI even more; this is not nitpicking about technology, but a basic attitude toward our shared future.