When AI infrastructure providers start building their own applications, the question arises: will they continue selling their best models to rivals? Anthropic and OpenAI are accelerating their push into vertical industry applications, directly competing with their own API clients, leaving enterprise customers in an increasingly awkward position. Design platform Canva is the latest company caught in this predicament, as its core features now directly compete with Anthropic's in-house applications. According to a report on August 17, this "supplier-as-competitor" dynamic has prompted a growing number of developers relying on frontier models to reconsider their technology strategies.
Currently, API business remains the core revenue source for both Anthropic and OpenAI, worth billions of dollars. However, based on recent conversations with researchers at leading AI labs and application developers, whether this status quo can persist has become an open question within the industry.
Security concerns: The first pressure on API access
Restricting API access is not purely a commercial consideration; security factors are also driving this trend. The Trump administration has pressured Anthropic and OpenAI to adopt a "phased release" strategy for certain new models, citing concerns that these models could be exploited by cybercriminals or other malicious actors. During this period, customers must obtain individual approval before gaining access. The Trump administration has also recently signaled a pre-release testing process specifically for major AI companies. Even after models are publicly released, Anthropic and OpenAI may proactively degrade model performance on specific tasks for similar security reasons. This has already happened: Anthropic's Fable model has been deliberately weakened in cybersecurity-related tasks. Notably, when the two companies use these models to power their proprietary applications, they do not apply the same performance downgrades.
Both companies have publicly warned that future models could possess dangerous capabilities in areas such as hacking and biological weapons development. The report notes that if malicious actors breach defenses, the consequences would be severe, and at that point, completely cutting off external access to advanced models might be considered the safer option.
Distillation prevention: The second pressure on API access
Beyond security, the issue of "model distillation" is also a major concern for Anthropic and OpenAI. Distillation refers to the practice where competitors use the outputs of commercially available models to train new models with similar performance. This is essentially a low-cost way to "copy" advanced AI capabilities. In a report on potential catastrophic AI risks released last week, Anthropic explicitly stated: "If a distilled model inherits the risk-related capabilities of the original model but lacks adequate safety measures during deployment, it could pose downstream risks to the world, even if the original model has strict anti-abuse mechanisms."
However, a former Anthropic researcher told The Information that completely preventing distillation is "basically impossible." Open-source software advocates hold a different view, arguing that open-source models, including those distilled from Anthropic's models, actually help developers defend against cybersecurity attacks, citing the incident where Hugging Face was breached by an OpenAI agent as evidence.
Commercial interests: The most realistic motive for restriction
Apart from security, there is a more direct commercial logic. According to earlier reports, some investors have warned developers that Anthropic may retain its most advanced technology for its own competitive applications rather than continuing to offer it through APIs. Anthropic has even ventured into emerging fields such as AI-driven drug discovery. If Anthropic, as the absolute leader in the AI API market, chooses to restrict competitors in this way, it could face large-scale antitrust investigations.
From a financial perspective, the strategic value of the API business is undeniable. According to Bloomberg, Anthropic's second-quarter revenue was approximately $11.5 billion, a roughly 14-fold increase year-over-year (compared to $787 million in the same period last year and $4.73 billion in the first quarter), and it has achieved profitability at the adjusted operating profit level. Abandoning this revenue stream would come at an extremely high cost. But AI-driven vertical applications may offer even more lucrative returns, which is the fundamental reason both companies are accelerating their efforts in this direction.
Developers' self-rescue: Training proprietary models becomes a new trend
Facing uncertainty around API access, leading AI application developers have begun to act. Legal AI company Harvey and code editing tool Cursor have both started training their own in-house models to reduce dependence on Anthropic and OpenAI. The Information believes more developers will follow this path. The logic behind this trend is straightforward: when the provider of core infrastructure could become a competitor at any moment, or unilaterally change service terms, building autonomous and controllable technical capabilities becomes an inevitable choice for enterprises.