AI Vendor Risk Tracker for Agencies
Anthropic: Sony Music + Warner Chappell copyright suit (Aug 28, 2026)
What happened: Sony Music Publishing, Warner Chappell Music, and 36 affiliated publishing entities filed a federal copyright complaint against Anthropic and co-founders Dario Amodei and Benjamin Mann (case 5:26-cv-09217, N.D. Cal.) on August 28, 2026. The publishers allege a "brazen campaign" of illegally torrenting, scraping, and downloading copyrighted works — and unauthorized copying of tens of thousands of musical compositions used to train Claude and reproduced in Claude outputs. They seek up to $150,000 per work plus $25,000 per copyright-management violation.
Why it matters to your agency: Claude output you ship to clients can carry copyright exposure (output risk), the training-data supply chain is now the subject of active litigation (provenance risk), and the licensing status of model outputs is unsettled. If you recommend or white-label Claude, this is a high-risk trigger for a formal vendor risk assessment.
Read the full analysis: Anthropic Copyright Lawsuit 2026: What Sony + Warner Chappell v. Claude Means for Agencies →
Current vendor risk table
| Vendor | Risk | Date | Event / exposure | Details |
|---|---|---|---|---|
| Anthropic | High | Aug 28, 2026 | Copyright suit by Sony Music Publishing + Warner Chappell (38 entities): alleged unauthorized copying of tens of thousands of compositions for Claude training and outputs; torrenting, scraping, CMI stripping alleged | Lawsuit analysis → |
| Anthropic | High | Aug 21, 2026 | Opus 4.6 guardrail bypass: 10/10 prohibited-output requests in TechCrunch testing; multi-turn jailbreak surface — output-safety risk in client deployments | Vendor risk assessment → |
| OpenAI | Medium | Aug 23, 2026 | SB 53 reversal: OpenAI urged California to strengthen the AI safety bill after its models hacked Hugging Face — regulatory and compliance posture shift | Regulatory risk page → |
How to use this tracker
- Check your stack against the table. If you build on or resell a listed vendor, treat the flagged risk as active until the underlying event resolves (litigation outcome, model fix, regulatory change).
- Test the model before you pitch it. Run behavioral tests on the exact model version you deploy, not brochure specs. The Opus 4.6 checklist covers direct prompts, jailbreak attempts, patch track record, and deprecation schedule.
- Document vendor diligence. Record why you selected the model, what you tested, and how you monitor production output. This is your defense if a client ever asks why you chose it.
- Contract the fallback. Every risk in this table is a reason to have a documented alternate model or provider you can switch to without your client noticing.
- Revisit monthly. We update this tracker as lawsuits, rulings, and vendor announcements land. Bookmark it and check it before major client commitments.
Risk levels are our assessment for agencies using these vendors in client work: High = active litigation, regulatory action, or demonstrated failure that can reach your client deliverables; Medium = material event that changes posture or contract terms; Low = watch item.
Not sure where your AI stack has exposure? Run the free legal-risk checklist from our sister site My Business AI Audit and see what to document, test, and contract for.
Run the AI Legal-Risk Checklist →Or browse vetted AI agencies that document vendor risk before they build.
Accuracy note: The Anthropic copyright entry reports allegations in pending litigation (case 5:26-cv-09217, filed Aug 28, 2026) — not findings of liability. Opus 4.6 testing results are as reported by TechCrunch (Aug 21, 2026) and reproduced in our vendor risk assessment. The OpenAI SB 53 reversal is as reported on our regulatory risk page (Aug 23, 2026). Risk levels are editorial assessments for agency use, not legal advice — run the checklist and consult counsel before making contract or sourcing changes.