All Vendors
platform

Anthropic

AI platform provider. Extreme liability exposure from comprehensive data capture including session recording, cross-domain tracking, and persistent identifiers without consent. Maximum revenue impact from training data and competitive intelligence leakage.

58 IOCs27 detections15% pre-consent25 sites
70
Vendor Risk Score

How This Briefing Works

This report opens with key findings, then maps the gaps between what Anthropic discloses and what BLACKOUT observed at runtime. From there: what it means for your organization, what to do about it, and the detection data and evidence underneath.

Key Findings

Key Findings

27 detections across 25 sites15% pre-consent activity
MEDIUM

Pre-Consent Activity

Anthropic was observed loading and executing before user consent was obtained on 15% of sites where it was detected.

GDPRePrivacy
Disclosure Gaps

Claims vs. Observed Behavior

1 gaps

pending

UNKNOWN
They Claim

Requires claims extraction via CDT

Observed Behavior

Live website analysis pending

Customer Impact

What This Means For You

For security teams: AI chat transcripts capture sensitive business logic, technical requirements, and strategic discussions exploitable for competitive intelligence. For legal: Every AI interaction is a GDPR data subject access request requiring complete conversation reconstruction with PII redaction. AI-generated advice may create liability if legally consequential decisions made based on biased or outdated training data. For marketing: AI usage patterns reveal product priorities, feature gaps, and strategic direction before public announcements. For sales: Chat transcripts about vendor evaluations, pricing negotiations, and competitive comparisons leaked to Anthropic training data accessible to competitors using Claude.
Recommended Actions

What To Do About It

Role-specific actions based on observed behavior

If You Use Anthropic

  • Immediate contract review for AI training data usage rights and opt-out provisions
  • Require Anthropic to execute telemetry post-consent only with explicit AI data collection disclosure
  • Implement conversation-level data deletion controls for sensitive discussions
  • Add AI interaction data disclosure to privacy policy with training data opt-out mechanism
  • Audit data sharing agreements to identify downstream AI training data usage
  • Assess GDPR Article 9 applicability to behavioral AI interaction patterns

If You're Evaluating Anthropic

  • Legal counsel review of joint controller liability for AI-generated content under GDPR Article 26
  • Data Protection Impact Assessment for AI behavioral pattern processing
  • Calculate competitive leakage cost: (Anthropic fee + training data value to competing AI users + strategic intelligence exposure)
  • Evaluate self-hosted AI alternatives vs. cloud API with training data sharing

Negotiation Leverage

  • AI interaction data without consent violates GDPR Article 6 and Article 9 (behavioral patterns as special category data) - require explicit opt-in for all telemetry
  • Chat transcript capture creates data breach liability - demand encryption at rest/transit with annual security audits and breach notification SLAs
  • Training data usage feeds competing AI customers - require complete opt-out from model training with contractual guarantees
  • Cross-domain sync extends liability across Anthropic ecosystem - demand technical isolation of customer-specific deployments
  • Tag manager deployment creates consent enforcement gaps - require first-party deployment with documented consent controls
  • Persistent tracking of AI conversations extends GDPR liability window - demand 30-day automatic deletion with user-controlled retention
Runtime Detections

Runtime Detections

6 BTI-C CODES

BLACKOUT observed this vendor's JavaScript executing in a live browser and classified each hostile behavior using our BTI-C (Behavioral Threat Intelligence — Capability) taxonomy. These are not theoretical risks — each code below was triggered by something we watched this vendor's code actually do.

BTI-C06Behavioral Biometrics

Keystroke/mouse tracking

Impact: Captures AI interaction patterns (query complexity, response engagement, conversation flow) for user profiling. Creates GDPR Article 9 special category data processing violations.

BTI-C07Session Recording

Full session replay

Impact: Records complete AI conversation transcripts including prompts and generated responses. Every chat creates GDPR data subject access request liability and breach notification obligations if storage compromised.

BTI-C08Cross-Domain Sync

Identity stitching

Impact: Synchronizes AI usage identities across Anthropic properties and customer deployments. Extends GDPR compliance scope to entire Anthropic ecosystem.

BTI-C09Consent Bypass

Ignoring CMP signals

Impact: Executes AI telemetry, session recording, and behavioral tracking before consent collection. Violates GDPR Article 6 and ePrivacy Directive.

BTI-C13Persistence Mechanisms

Long-lived identifiers

Impact: Maintains AI interaction history across sessions via persistent identifiers. Extends GDPR data retention and deletion obligations to all historical chat transcripts.

BTI-C15Tag Manager

Container/loader (neutral)

Impact: Deploys AI embedding via tag management system enabling dynamic updates without change control. Creates consent governance gaps and prevents technical enforcement of privacy controls.

IOC Manifest

IOC Manifest

47 INDICATORS

Indicators of compromise across 4 categories. Use for detection rules, CSP policies, or Pi-hole blocklists.

TRACK
*www.anthropic.com/file/anthropic-privacy-banner*
Tracking script
TRACK
*www.anthropic.com/file/anthropic-custom-tracking*
Tracking script
TRACK
*a-cdn.anthropic.com/analytics.js/v1/LKJN8LsLERHEOXkw487o7qCTFOrGPimI/analytics.js*
Tracking script
TRACK
*a-cdn.anthropic.com/analytics-next/bundles/ajs-destination.bundle.*.js*
Tracking script
TRACK
*a-cdn.anthropic.com/analytics-next/bundles/schemaFilter.bundle.*.js*
Tracking script
TRACK
*a-cdn.anthropic.com/next-integrations/actions/reddit-plugins/*.js*
Tracking script
TRACK
*a-cdn.anthropic.com/next-integrations/actions/amplitude-plugins/*.js*
Tracking script
TRACK
*a-cdn.anthropic.com/next-integrations/actions/google-ec-plugins/*.js*
Tracking script
TRACK
*a-cdn.anthropic.com/next-integrations/actions/845/*.js*
Tracking script
TRACK
*a-cdn.anthropic.com/next-integrations/integrations/doubleclick-floodlight/1.5.4/doubleclick-floodlight.dynamic.js.gz*
Tracking script
TRACK
*a-cdn.anthropic.com/next-integrations/integrations/facebook-pixel/2.11.5/facebook-pixel.dynamic.js.gz*
Tracking script
TRACK
*a-cdn.anthropic.com/next-integrations/integrations/vendor/commons.*.js.gz*
Tracking script
TRACK
www.anthropic.com/file/anthropic-privacy-banner
Auto-extracted from scan
TRACK
www.anthropic.com/file/anthropic-custom-tracking
Auto-extracted from scan
TRACK
a-cdn.anthropic.com/analytics.js/v1/LKJN8LsLERHEOXkw487o7qCTFOrGPimI/analytics.min.js
Auto-extracted from scan
TRACK
a-cdn.anthropic.com/analytics-next/bundles/ajs-destination.bundle.8e6b895db75187c55313.js
Auto-extracted from scan
TRACK
a-cdn.anthropic.com/analytics-next/bundles/schemaFilter.bundle.1b218d13fed021531d4e.js
Auto-extracted from scan
TRACK
a-cdn.anthropic.com/next-integrations/actions/amplitude-plugins/01d0dcccc64ec8f9523a.js
Auto-extracted from scan
TRACK
a-cdn.anthropic.com/next-integrations/actions/google-ec-plugins/e79317965a25a2e9297f.js
Auto-extracted from scan
TRACK
a-cdn.anthropic.com/next-integrations/actions/reddit-plugins/1333c2e55a764a2e75e2.js
Auto-extracted from scan
TRACK
a-cdn.anthropic.com/next-integrations/actions/845/3e4ff40158b71395e929.js
Auto-extracted from scan
TRACK
a-cdn.anthropic.com/next-integrations/integrations/facebook-pixel/2.11.5/facebook-pixel.dynamic.js.gz
Auto-extracted from scan
TRACK
a-cdn.anthropic.com/next-integrations/integrations/doubleclick-floodlight/1.5.4/doubleclick-floodlight.dynamic.js.gz
Auto-extracted from scan
TRACK
a-cdn.anthropic.com/next-integrations/integrations/vendor/commons.59560acdd69ed701c941.js.gz
Auto-extracted from scan
Ecosystem

Ecosystem & Supply Chain

AI platform infrastructure connected to model training pipelines and enterprise AI deployments. Common co-deployments: Claude API (direct integration), AI workflow tools, chat analytics platforms. Interaction data feeds Anthropic model training benefiting all customers including competitors.
Loads (1)
Evidence

Evidence Artifacts

Artifacts collected during analysis, available with evidence-tier access.

HAR Capture

Complete network capture with all requests and responses

IOC Manifest

58 detection signatures across scripts, domains, cookies, and network endpoints

Vendor Details