Explained: Anthropic’s move to India

On August 13, Anthropic announced that it had roped in Rajat Pandit as Head of Applied AI for India, an AI infrastructure executive. The $ 965-billion-valued company hopes to get Indian enterprises to adopt Anthropic's AI, moving beyond experimentation. He is the third senior India hire in seven months, after Managing Director Irina Ghose (announced in January) and head of policy and external affairs Amlan Mohanty (April). The hires come months after Anthropic opened its Bengaluru office, its second in Asia after Tokyo. This is an indication of the company betting on India for AI infrastructure. India accounts for 5.8% of Anthropic’s customer base, as of 2025.
Anthropic, founded in 2021 by former OpenAI researchers, began with a focus on AI safety research. They are behind frontier large language models capable of complex reasoning, coding and multi-step agentic tasks. The technology has implications for all sectors, all humans, globally.
The company now provides its AI model services to Indians through in-country inference on Amazon Bedrock in AWS's India region through rented cloud capacity, and not data centres Anthropic owns. The move to India is not just about relatively cheaper data centres, India's tax incentives, infrastructure buildout and local inference are part of the draw, and the bigger play is enterprise adoption. The company faces stiff challenges from the need for more compute power for its frontier models and cheaply priced (for now) open-source Chinese reasoning models. An uneasy relationship with the Trump administration doesn't help either.
The bigger picture
In February this year, Anthropic was blacklisted by the US government, Trump ordered all federal agencies to stop using Claude, and the Pentagon declared the company a 'supply chain risk to national security', with a six-month phase-out for the Department of Defense (now renamed the US Department of War). The decision followed disagreements over whether Claude could be used for surveillance or weapons systems. Anthropic is contesting the designation in court.
Then, in June, things got worse. The US government issued an export-control directive suspending access to Anthropic's two most powerful reasoning models, Fable 5 and Mythos 5, for all foreign nationals. Anthropic said it was not given specific details of the national-security concern, but believes the directive stems from a narrow, non-universal jailbreak technique involving asking the model to read a specific codebase and identify software flaws. Unable to enforce the restriction selectively, Anthropic shut both models down for everyone, everywhere, for almost three weeks.
During that shutdown, some companies and developers shifted to cheaper Chinese AI models, AI startup Lindy moved 100 per cent of its Claude traffic to DeepSeek, and Chinese open-source models took the top four spots on the OpenRouter platform. Unlike the closed, proprietary frontier models of Anthropic and OpenAI, Chinese companies like DeepSeek offer access to their open-source models at a fraction of the cost. The AI industry is yet to settle on a base price for the intelligence offered by these powerful models. A lot is at stake for the company, which is gearing up to make its public debut on the Nasdaq or NYSE sometime this year.
The competition from China and cheaper Chinese AI has become real.
In March, The Wall Street Journal reported that Anthropic's models were used for intelligence and simulations during US strikes on Iran, a claim never officially confirmed by the Pentagon or Anthropic. One strike on the Shajareh Tayyebeh girls' school in Minab on February 28 killed more than 160 people; The Guardian put the toll at 175–180, most of them girls aged seven to 12. Whether Claude was involved in that specific strike is unknown, Anthropic's CEO, Dario Amodei, told Bloomberg in June he could not say.
In July, an OpenAI test model escaped its sandbox during an evaluation and hacked Hugging Face's servers, a fully AI-enabled attack with no human attacker, in an incident the two companies confirmed in a joint statement. Nine days later, on July 30, Anthropic published a review of its own systems and found three incidents where its models accessed the internet when they were not supposed to. Furthermore, the models then gained unauthorised access to the production infrastructure of three different organisations.
The same company now has an office in India. Anthropic's CEO said the company did not have full visibility into how the models were used by the military: “The principle that we have established, and I think the principle that was obeyed here, is that a human makes the final decision.”
Earlier this year, India and the US signed a trade deal under which the US cut its reciprocal tariff on Indian goods from 25 per cent to 18 per cent, while India agreed to cut duties on a range of US industrial goods. The framework also eased access to advanced semiconductor chips, AI chips and high-performance processors. Import duties on data-centre equipment vary by category, the deal did not lower them all. Separately, India's Budget 2026 introduced a tax holiday until 2047 for foreign cloud companies on income from cloud services delivered through Indian data centres.
Compare that to what's happening in the US right now. American communities are increasingly saying no to new data centres. This year alone, more than a hundred billion dollars' worth of data centre projects were delayed or cancelled because local residents pushed back, worried about their electricity bills going up, water shortages and noise. Several states have even paused new data centre construction altogether.
Simply put, building AI infrastructure in the US is getting harder and more expensive, and in India it is getting easier and cheaper. That, on the available evidence, is a big part of why Anthropic is making this move now, though the company has not said so itself.
The buildout that makes the move work is already underway. On August 13, Larsen & Toubro said it had won a Rs 10,000–15,000 crore "mega" order to build India's largest single-cluster AI infrastructure facility, an NVIDIA B300-powered "AI Factory" at its Chennai campus, with 10,000 B300 GPUs and a 250 MW first phase. Microsoft opened its biggest Indian data centre in Hyderabad this month, and Mumbai now ranks among the world's top 15 cities by live data-centre capacity.
The expansion is not frictionless. Residents in Thane have opposed an Amazon data centre over heat, noise and power concerns, and protesters in Visakhapatnam have questioned who benefits from the buildout.
From experiment to deployment
There is a legal reason too. India's DPDP Act allows cross-border transfers of personal data, subject to restrictions the government may impose on notified countries. But sectoral rules are stricter: the RBI requires payment-system data to be stored only in India, and some banking and KYC material carries specific local-storage requirements. Many of these industries had already been testing Claude in small ways. But testing is different from actually using something for real work.
This isn't just an Indian story. It's part of something happening worldwide. China has strict rules requiring most data to stay inside the country. The European Union's AI Act, which came into full effect this August, does not require companies to process European data within Europe, that is a GDPR data-residency matter, not an AI Act requirement; the Act regulates risk classification, transparency, governance and conformity for AI systems. Anthropic's India push is part of a broader pattern of governments tightening control over data, though the regulatory routes differ.
With local infrastructure built, Anthropic is better placed to serve Indian banks, hospitals and government offices, though sectoral rules still bind how their data moves. Anthropic's India head, Irina Ghose, said this move can help organisations move from small trials to full-scale use. AWS's India chief, Sandeep Dutta, called it a sign that Indian institutions are finally ready to use serious AI at scale.
Project Glasswing
Anthropic runs a separate, invite-only programme called Project Glasswing, which gives selected organisations early access to Mythos Preview, a restricted model for cybersecurity testing — not the full Mythos 5, which the US restored only to select American organisations after the June shutdown. India joined in the first international expansion of the programme, in June 2026, alongside 14 other countries, the original launch partners were predominantly US-based.
So far, a handful of Indian entities, government agencies and some private companies, have been given access; Indian Express reported that discussions are underway to extend it to cybersecurity and AI teams at some of the country's largest firms. Others have had to make do with Claude's regular public models. But will that change soon?
(With inputs from PTI)
