Anthropic's Mission Statement Is Doing a Lot of Work Lately
Dario Amodei is reportedly worried that his new hires don't believe in the mission.
According to Axios, citing a source familiar with the matter, the Anthropic CEO has expressed concern that some recent hires at the company are joining for compensation rather than out of any deep commitment to safely building advanced AI. The report landed in the middle of an escalating talent war between Anthropic, OpenAI, Meta, and Thinking Machines Lab, where nine figure pay packages, aggressive poaching, and pre-IPO equity offers have become a normal part of doing business in frontier AI.
The internet's reaction was immediate, and not especially gentle. Engineers and investors online pointed out, correctly, that people generally like getting paid, and that a company sitting on a reported $965 billion valuation while handing out salaries that would be considered eye watering almost anywhere else probably shouldn't be surprised to learn some of its new hires are, in fact, financially motivated human beings. One widely shared reply put it bluntly: good intentions don't put food on the table. Another simply noted that people had apparently discovered the economy.
It's easy dunking, and honestly, a little unfair to Amodei specifically, because the data doesn't support a retention crisis at all. By most accounts Anthropic actually leads the frontier AI labs on employee retention right now, reportedly hiring engineers at something like two and a half times the rate it loses them. This isn't a company hemorrhaging talent. It's a company that has grown enormously, very fast, and whose founder seems uneasy about what that growth does to a culture that was built, quite deliberately, to be different from everywhere else in the industry.
That unease is worth sitting with for a second, because it's pointing at something real, even if the framing came out a little tone deaf. Anthropic wasn't founded as just another AI lab chasing the frontier. It exists because a group of researchers left OpenAI specifically because they felt the company was drifting away from safety and toward commercialization, most visibly through its deepening partnership with Microsoft. That departure is the founding story. It's the reason Anthropic has a separate name, a separate building, and a separate set of promises to the public at all.
And over the past several months, a fairly long list of stories has made it noticeably harder to square that founding story with how the company is actually operating today.
The pattern, laid out
None of what follows is secret or fringe reporting. These stories were covered by outlets like the Washington Post, Time, CNN, CBS News, and the Financial Times, and in most cases Anthropic responded on the record, sometimes with genuinely reasonable explanations. But read together, in sequence, they paint a picture of a company whose stated mission keeps running into the same commercial and geopolitical pressures it was founded to resist. It's worth walking through them slowly, because the individual stories tend to get discussed in isolation, and something changes when you line them up.
The IPO. Anthropic has reportedly been preparing for a public offering that could value the company north of a trillion dollars, following a Series G round that closed earlier this year at a $380 billion valuation. Going public at this scale is a completely normal move for a company this size, and nobody should pretend otherwise. But it's worth holding up against Amodei's own original complaint about his old employer, that getting too close to a giant like Microsoft would compromise the mission. A public company answers to shareholders and quarterly targets in a way a private one simply doesn't have to, and that's true no matter how carefully the S-1 is worded.
The dropped safety pledge. In February 2026, Anthropic published a new version of its Responsible Scaling Policy, and quietly removed the commitment that had defined the company since 2023: a promise to stop training and refuse to deploy any AI system it couldn't guarantee had adequate safety guardrails in place beforehand. That commitment was the actual substance behind the "safety first" branding. It wasn't a slogan, it was an operational constraint the company had bound itself to. The new policy swaps that hard stop for public goals, transparency reports, and a much narrower promise to delay training only under specific conditions. Anthropic's chief science officer, Jared Kaplan, told Time the company felt unilateral restraint wouldn't actually help anyone if competitors kept racing ahead without similar caution, which is a coherent argument on its own terms. It's also a real and significant walk back from the promise that made Anthropic's safety identity credible in the first place, and the timing wasn't subtle. The change landed the same week Anthropic was locked in a public standoff with the Pentagon over military use of its models, and reportedly not long after Mrinank Sharma, who had led the company's Safeguards Research team, resigned and wrote in his departure letter that employees at the company constantly face pressure to set aside what matters most.
The Pentagon standoff, and the Iran strikes anyway. Speaking of that standoff, the Department of Defense demanded broader rights to use Claude for "all lawful purposes," including battlefield targeting and weapons support. Anthropic refused, pointing to its constitutional constraints against fully autonomous lethal weapons and mass domestic surveillance of US citizens. The Trump administration responded by formally designating Anthropic a supply chain risk, a label typically reserved for foreign adversaries, and gave the Pentagon a window to phase the company's technology out of its systems. And then, during that exact transition period, before the ban had even fully taken effect, the US military used Claude for intelligence assessment, target identification, and battle simulation in its strikes on Iran, reportedly helping identify more than a thousand targets in the first 24 hours of the campaign. Anthropic held its line on paper. The company's technology ended up in the kill chain anyway, because the Pentagon simply kept using what was already integrated into its classified systems while it looked for a replacement.
The NSA arrangement. More recently, the Financial Times reported that Anthropic has placed roughly half a dozen of its own engineers directly inside the National Security Agency as forward deployed staff, adapting and customizing its Mythos model, the company's most capable and most tightly access controlled system, for offensive cyber operations. Sources familiar with the arrangement told the FT the model would be useful for infiltrating networks in countries including China and Iran. This is happening while Anthropic is simultaneously suing the Pentagon over the supply chain designation from the paragraph above. It's a genuinely strange position to be in: legally fighting one arm of the US government over battlefield use of your model, while quietly helping another arm of that same government use a more powerful version of it for offensive hacking. Anthropic hasn't denied the arrangement. A person close to the company offered the somewhat circular logic that the best way to build a strong defense is to first build a strong offense, which is the kind of sentence that sounds reasonable in a briefing room and slightly different in a "safety first" mission statement.
The hidden tracking code. In April 2026, Anthropic shipped a version of Claude Code, version 2.1.91, containing undisclosed detection logic that identified users connecting through Chinese proxy routes. The mechanism reportedly used Unicode character substitutions and obfuscated domain lists to quietly flag things like Shanghai and Urumqi timezones and known Chinese cloud infrastructure, all without a single line in the release notes. A security researcher going by Thereallo found it in June, reverse engineered it, and published a full breakdown of how it worked. Anthropic's stated rationale, according to reporting from The Information, was that it was defending against distillation attacks, where rival labs train competing models on Claude's outputs, something the company has separately and publicly called a serious national security threat. The company removed the tracking code after the exposure. Whatever the underlying justification, and there may well be a real one, a company that built its entire public identity on transparency shipping silent, undisclosed surveillance logic into a widely used developer tool is a hard thing to fully explain away after the fact, no matter how good the reasoning turns out to be.
Credit where it's actually due
It would be easy to stop there and let the piece read as a straightforward takedown, but that wouldn't be a fair account either, and this is a dev blog, not a hit piece. A few things are worth holding onto at the same time as everything above.
Anthropic is also the company that, in November 2025, publicly disclosed that a Chinese state sponsored group had misused Claude Code to automate roughly 80 to 90 percent of a cyber espionage campaign against dozens of organizations, and shared its findings with authorities rather than quietly patching the hole and staying silent. It's the company that refused, in writing, to give the Pentagon unrestricted rights to use its models for autonomous weapons and mass surveillance, even when that refusal cost it a government contract and got it formally labeled a national security risk. Its Project Glasswing cybersecurity program has expanded to roughly 150 organizations across more than 15 countries, reportedly surfacing thousands of serious vulnerabilities for partners who wouldn't otherwise have access to that kind of tooling. And its safety research output, published system cards, red teaming results, and the sheer volume of "here is what went wrong and how" writing the company puts out, is still genuinely ahead of most of its competitors, most of whom disclose far less about their own failures.
None of that cancels out the stories above. But it does mean the honest read here isn't "Anthropic is lying about caring about safety." It's something messier and more familiar: a company that genuinely started out trying to do something different, that has real, demonstrable evidence of that commitment, and that is now big enough, valuable enough, and entangled enough with governments and markets that its own stated principles are starting to bend under weight they were never really built to carry at this scale. That's a more uncomfortable story than either the doom take or the puff piece, but it's probably the truer one.
Why this matters if you're actually building on Claude
It would be easy to read all of this as pure celebrity gossip about a CEO and a few uncomfortable headlines, and move on. But if you're a developer with a real dependency on Anthropic's API, running Claude Code in CI, or building a product on top of Claude, this is closer to vendor due diligence than it is to gossip.
Every one of these stories touches something with actual operational weight: what data your tools might be quietly sending back to a vendor without your knowledge, how quickly a company's safety commitments can change when competitive pressure gets high enough, and how much weight it's reasonable to put on a vendor's stated values versus its demonstrated behavior under pressure. The hidden tracking code story in particular is worth internalizing if you run Claude Code on developer machines or in automated pipelines. It's a good, concrete reason to actually read release notes, watch outbound network traffic where you can, and resist the instinct to assume a values driven company simply wouldn't ship something like that quietly. It did, once. There's no principled reason to assume it couldn't happen again, from Anthropic or anyone else in this industry.
None of this makes Claude a bad tool, and it would be a stretch to pretend otherwise. The models are genuinely strong, the documentation is good, and Anthropic still discloses more about its own safety testing and its own failures than most of its competitors do. But "safety first" as a brand promise and "safety first" as a hard operational constraint are two different things, and the distance between them has been getting easier to see lately, not harder. Treat the marketing as a starting point for your own judgment, not a substitute for it.
The takeaway
Amodei's worry that new hires care more about the money than the mission is, on its face, a pretty ordinary observation about what happens when a startup turns into one of the most valuable private companies on the planet. People take good jobs when good jobs are offered to them. That's not a scandal, and it's a little rich to be surprised by it from inside a company paying nine figure sign on packages.
The more interesting question is the one nobody at the company seems to be asking out loud, at least not publicly. If the mission itself is bending under the combined weight of an IPO, a defense contract dispute, a cyber arms race, and one of the most competitive markets in tech history, is it really reasonable to expect the newest people through the door to hold that line more tightly than the company holding the pen on its own policies has managed to?