Anthropic, PBC
United States · owned by Independent (United States) · www.anthropic.com · 55 vendors
Anthropic is an AI safety and research company focused on building reliable, interpretable, and steerable AI systems. It develops large language models, most notably the Claude family of AI assistants. The company was founded by former OpenAI researchers, including Dario Amodei and Daniela Amodei, and is headquartered in San Francisco, California.
Resilience scores
- Digital Sovereignty: 78
- Digital Resilience: 8
- Financial Resilience: 7
Disruption prediction
Anthropic, PBC has a 100% probability of disruption in the next 6 months.
Partial disruption reported (last checked 2026-09-18 16:25 UTC): Intermittent error spikes for Claude Mythos 5.1 and Claude Fable 5.1
27 of Anthropic, PBC's 55 vendors monitored for disruptions.
Technology vendors
- Adobe Inc. — Technology — United States
- Demandware — Technology — United States
- Stripe, Inc. — Financial Services — United States
- and 59 more
Services catalogue
26 services in catalogue across 7 categories; runs on 55 sub-vendors.
- AI model provider for content generation
- Model Context Protocol
- LLM APIs
Insights
Last updated 2026-07-15 · revision 35
55 direct vendors, 375 subvendors
Direct vendors by controlling owner country (sample)
- Australia: 1
- United States: 43
- Canada: 1
Subvendors by controlling owner country (sample)
- Serbia: 1
- South Korea: 1
- Luxembourg: 1
Migration Readiness: 9/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Anthropic exhibits high migration readiness due to its highly modern, cloud-native, and containerized technology stack (Google Kubernetes Engine, Docker, AWS, Google Cloud, Microsoft Azure). This multi-cloud strategy significantly reduces vendor lock-in and provides excellent portability for workloads. The company's strong projected financial growth ensures ample resources to fund any necessary migration efforts. Existing mechanisms for addressing data residency requirements, such as reliance on Standard Contractual Clauses for EU/EEA data and partnerships with cloud providers offering regional hosting, also contribute positively. The primary challenges to migration readiness stem from the 'Assessment Required' status for critical compliance certifications like SOC2 (High risk), HIPAA (Medium risk), and ISO 27001 (Medium risk). These compliance gaps could introduce significant complexity, cost, and time during a migration, as new environments would need to be rigorously audited and certified. Additionally, while regional options exist, the centralization of core AI model training and development might limit strict data localization options for jurisdictions with stringent mandatory data residency requirements. Despite these compliance and potential data localization hurdles, the underlying technical architecture is exceptionally flexible and well-suited for migration.
Compliance
12 in-scope frameworks identified; showing 3.
CSA STAR — Compliant
Anthropic holds CSA STAR (Cloud Security Alliance Security, Trust, Assurance, and Risk) certification, which is specifically designed for cloud service providers. This certification builds on ISO 27001 and adds cloud-specific security controls from the Cloud Controls Matrix (CCM). Risk is Low because: (1) CSA STAR certification is confirmed from official sources; (2) it demonstrates cloud-specific security assurance beyond ISO 27001; (3) it is maintained alongside SOC 2 Type 2 and ISO 27001/27017/27018, creating a comprehensive security certification portfolio.
Evidence: https://claude.com/regional-compliance, https://trust.anthropic.com/
NIS2 (source) — Assessment Required
NIS2 Directive (EU) 2022/2555 applies to 'Important Entities' in the category of 'digital providers,' which includes online marketplaces, online search engines, and cloud computing service providers. Anthropic provides AI-as-a-service (Claude API, Claude.ai) that could qualify as a 'managed service provider' or 'cloud computing service' under NIS2 Annex II. Anthropic has established a legal entity in Ireland (Anthropic Ireland, Limited) and actively serves EU customers including the European Parliament (documented on the Regional Compliance page). The size threshold (50+ employees or €10M+ turnover) is almost certainly met given Anthropic's scale and multi-billion dollar valuation. Risk is Medium because: (1) NIS2 applicability to AI/LLM providers is still being interpreted by EU member states; (2) Anthropic's Irish entity creates a clear EU nexus; (3) enforcement is ramping up across EU member states through 2024-2025 transposition; (4) failure to register and implement NIS2 security measures could result in fines up to €10M or 2% of global annual turnover. A formal NIS2 applicability assessment by EU legal counsel is recommended, particularly regarding whether Claude API qualifies as a 'cloud computing service' or 'managed ICT service' under the Directive.
Evidence: https://trust.anthropic.com/, https://claude.com/regional-compliance, https://www.anthropic.com/legal/privacy, https://claude.com/customers/european-parliament
FTC Act — Assessment Required
The Federal Trade Commission (FTC) has jurisdiction over Anthropic's data practices under Section 5 of the FTC Act (unfair or deceptive acts or practices). The FTC has been increasingly active in AI-related enforcement, including actions related to AI companies' data practices, model training disclosures, and consumer protection. Risk is Medium because: (1) Anthropic's use of user data for model training (with opt-out) is an area of FTC scrutiny; (2) the FTC has issued guidance on AI and data practices; (3) Anthropic's comprehensive privacy disclosures reduce but do not eliminate FTC risk; (4) the FTC's proposed commercial surveillance rules could impose additional obligations. No specific FTC action against Anthropic has been identified.
Evidence: https://www.anthropic.com/legal/privacy, https://www.anthropic.com/legal/aup, https://www.anthropic.com/legal/consumer-terms
Financials
Three-year financials
- 2024: revenue US$1B
- 2023: revenue US$200M
- 2022:
Financial Resilience Score: 7/10
Anthropic exhibits an extraordinary revenue growth profile, with annualized run-rate expanding from roughly US$100M at end-2023 to approximately US$7B by late 2025, one of the fastest software revenue ramps ever recorded. This trajectory is supported by deep-pocketed strategic backers including Amazon (US$8B committed) and Google (multi-billion USD), plus venture rounds bringing cumulative disclosed capital raised to well over US$18B. Diversified distribution through AWS Bedrock, Google Vertex AI, and Microsoft Foundry provides broad enterprise reach, and PBC governance combined with the Long-Term Benefit Trust supports long-horizon strategic planning. However, the company is deeply loss-making, with press-reported cash losses in the multi-billion-USD range annually, driven primarily by compute costs. Internal projections reportedly do not anticipate profitability until around 2028. Inference gross margin is materially below traditional SaaS norms, creating structural dependency on continued primary fundraising and subsidized compute from cloud partners. Customer concentration risk, competitive intensity from OpenAI, Google DeepMind, Meta, xAI and Chinese labs, plus regulatory uncertainty, add to the risk profile. The absence of audited public financials is an inherent transparency gap. Overall resilience is strong in the near-term due to capital access, but longer-term sustainability hinges on inference economics improving before AI capital market appetite wanes.
Key strengths: Exceptional revenue growth (~10x in 2024, further 5-7x through 2025), Deep-pocketed strategic backers: Amazon US$8B and Google multi-billion USD commitments, Cumulative disclosed capital raised over US$18B, Diversified cloud distribution via AWS Bedrock, Google Vertex AI, Microsoft Foundry, Enterprise-grade adoption including Claude Code as fastest-growing enterprise SaaS product of 2025, PBC + Long-Term Benefit Trust governance structure, Preferential access to compute capacity from hyperscaler partners
Risk factors: Multi-billion USD annual cash burn with no profitability expected until ~2028, Compute cost concentration compresses gross margin well below traditional SaaS, Customer concentration - largest single API customer reportedly double-digit % of revenue, Intense competition from OpenAI, Google DeepMind, Meta, xAI and Chinese AI labs, Regulatory risk from EU AI Act, US executive orders, California SB 53, Concentrated strategic-investor influence from Amazon and Google (antitrust scrutiny), No audited public financials - transparency gap for counterparty risk assessment, Dependency on continued primary equity fundraising
Revenue by geography
- North America: 68%
- EMEA: 20%
- APAC and Rest of World: 12%
Revenue by product/service
- API / Developer Platform: 70%
- Claude.ai Consumer Subscriptions: 12%
- Claude Code: 10%
- Claude for Enterprise / Teams: 8%
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.