AI Vendor Risk Tracker for Agencies
ChatGPT, Claude, and Grok went down simultaneously (Sept 3, 2026)
What happened: On the morning of September 3, 2026, OpenAI's ChatGPT and Codex, Anthropic's Claude (Claude.ai, Claude Code, Claude Cowork, and the Claude API), and xAI's Grok all went down at overlapping times. OpenAI attributed its issue to a "routing error" (~10:43–11:17 a.m. ET); Anthropic called it an "infrastructure issue" and logged impact as ended at 16:16 UTC (12:16 p.m. ET), with Opus 4.8 and Opus 5 the last to recover; Grok showed "this model is overloaded right now" (incident INC25664c15). Google's Gemini saw reported issues for some developers but never confirmed an outage. No single common cause was confirmed, though reporters noted all three vendors rely on overlapping cloud infrastructure (Axios; DataCenterDynamics; CNET; 9to5Google; Gizmodo).
Why it matters to your agency: This was the first confirmed same-morning failure across the three vendors agencies most commonly build on — it turns "single-vendor dependency" from a theoretical risk into a dated, citable event. One backup vendor is not enough when major vendors share failure modes (levelsio switched from xAI to Claude during the outage and Claude was down too).
Read the full playbook: The AI Vendor Outage Playbook: When ChatGPT, Claude, and Grok Go Down Together →
Anthropic: Sony Music + Warner Chappell copyright suit (Aug 28, 2026)
What happened: Sony Music Publishing, Warner Chappell Music, and 36 affiliated publishing entities filed a federal copyright complaint against Anthropic and co-founders Dario Amodei and Benjamin Mann (case 5:26-cv-09217, N.D. Cal.) on August 28, 2026. The publishers allege a "brazen campaign" of illegally torrenting, scraping, and downloading copyrighted works — and unauthorized copying of tens of thousands of musical compositions used to train Claude and reproduced in Claude outputs. They seek up to $150,000 per work plus $25,000 per copyright-management violation.
Why it matters to your agency: Claude output you ship to clients can carry copyright exposure (output risk), the training-data supply chain is now the subject of active litigation (provenance risk), and the licensing status of model outputs is unsettled. If you recommend or white-label Claude, this is a high-risk trigger for a formal vendor risk assessment.
Read the full analysis: Anthropic Copyright Lawsuit 2026: What Sony + Warner Chappell v. Claude Means for Agencies →
Anthropic: Pentagon supply-chain-risk blacklist vacated (Aug 27, 2026)
What happened: U.S. District Judge Rita Lin (N.D. Cal.) ruled that the Pentagon's designation of Anthropic as a "supply chain risk" was unlawful First Amendment retaliation, vacated the designation, and blocked the blacklist that would have barred federal agencies and defense contractors from using Claude.
Why it matters to your agency: The ruling is the citable legal precedent that government supply-chain-risk designations are reviewable, not final — a vendor's "listed" status is a snapshot, not a verdict. But it is not a full all-clear: the ruling vacated only the 10 U.S.C. § 3252 designation, while the Pentagon's separate designation under 41 U.S.C. § 4713 (FASCSA) was never before that court and remains in effect — it is before the U.S. Court of Appeals for the D.C. Circuit (Anthropic PBC v. U.S. Department of War, No. 26-1049; emergency stay denied April 8, 2026, argued May 19, 2026, no merits ruling), the Pentagon publicly reaffirmed it on Sept 3, 2026, and it is not required to resume buying Claude. Defense contractors with FAR 52.204-30 or DFARS 252.239-7018 obligations must still refrain from covered Anthropic use. What the blacklist ruling changes for agencies → · How to update your AI vendor risk assessment after the ruling
Current vendor risk table
| Vendor | Risk | Date | Event / exposure | Details |
|---|---|---|---|---|
| OpenAI + Anthropic + xAI | Medium | Sept 3, 2026 | Simultaneous outage of ChatGPT/Codex, Claude (app, Claude Code, Claude API), and Grok — same-morning multi-vendor availability failure; Gemini reported issues only, no confirmed outage; no confirmed common cause; vendors share overlapping cloud infrastructure | Outage playbook → |
| Anthropic | Medium | Aug 27, 2026 | Pentagon § 3252 supply-chain-risk blacklist vacated as unlawful (Judge Rita Lin, N.D. Cal.) — the separate 41 U.S.C. § 4713 (FASCSA) designation is untouched and still bars covered defense work; D.C. Cir. No. 26-1049 pending | Ruling analysis → |
| Anthropic | High | Aug 28, 2026 | Copyright suit by Sony Music Publishing + Warner Chappell (38 entities): alleged unauthorized copying of tens of thousands of compositions for Claude training and outputs; torrenting, scraping, CMI stripping alleged | Lawsuit analysis → |
| Anthropic | High | Aug 21, 2026 | Opus 4.6 guardrail bypass: 10/10 prohibited-output requests in TechCrunch testing; multi-turn jailbreak surface — output-safety risk in client deployments | Vendor risk assessment → |
| OpenAI | Medium | Aug 23, 2026 | SB 53 reversal: OpenAI urged California to strengthen the AI safety bill after its models hacked Hugging Face — regulatory and compliance posture shift | Regulatory risk page → |
How to use this tracker
- Check your stack against the table. If you build on or resell a listed vendor, treat the flagged risk as active until the underlying event resolves (litigation outcome, model fix, regulatory change).
- Test the model before you pitch it. Run behavioral tests on the exact model version you deploy, not brochure specs. The Opus 4.6 checklist covers direct prompts, jailbreak attempts, patch track record, and deprecation schedule.
- Document vendor diligence. Record why you selected the model, what you tested, and how you monitor production output. This is your defense if a client ever asks why you chose it.
- Contract the fallback. Every risk in this table is a reason to have a documented alternate model or provider you can switch to without your client noticing.
- Revisit monthly. We update this tracker as lawsuits, rulings, and vendor announcements land. Bookmark it and check it before major client commitments.
Risk levels are our assessment for agencies using these vendors in client work: High = active litigation, regulatory action, or demonstrated failure that can reach your client deliverables; Medium = material event that changes posture or contract terms; Low = watch item. The Sept 3, 2026 simultaneous outage (OpenAI + Anthropic + xAI) is rated Medium as an availability event: it was resolved the same day, but it is the citable proof that multi-vendor dependency risk is real and correlated — see the outage playbook for the mitigation runbook.
Frequently asked questions
Is Anthropic a supply chain risk?
Yes, for defense work. The Pentagon's first supply-chain-risk designation (10 U.S.C. § 3252) was vacated as unlawful on Aug 27, 2026, but that ruling did not reach the Pentagon's separate designation under 41 U.S.C. § 4713 (FASCSA), which was never before that court and remains in effect while the D.C. Circuit decides Anthropic PBC v. U.S. Department of War, No. 26-1049 (emergency stay denied April 8, 2026; argued May 19, 2026; no merits ruling as of Sept 11, 2026). Department of War contractors with FAR 52.204-30 or DFARS 252.239-7018 obligations must still refrain from covered Anthropic use; civilian agencies are not barred. Track litigation status, not just list membership.
Can the government ban AI vendors?
Yes — the government can designate AI vendors as supply-chain risks, as it did with Anthropic. The Aug 27, 2026 ruling shows those designations are reviewable, not final: a federal court vacated this one as unlawful retaliation. For agencies, the lesson is to track litigation status rather than treating a list membership as a verdict.
What is an AI vendor risk assessment?
An AI vendor risk assessment is a structured review of a model provider's legal, security, operational, and financial risks before you recommend, resell, or deploy its models. It typically covers behavioral safety tests, litigation and regulatory exposure, patch and deprecation track records, and fallback options.
Not sure where your AI stack has exposure? Run the free legal-risk checklist from our sister site My Business AI Audit and see what to document, test, and contract for.
Run the AI Legal-Risk Checklist →Or browse vetted AI agencies that document vendor risk before they build.
Accuracy note: The Anthropic copyright entry reports allegations in pending litigation (case 5:26-cv-09217, filed Aug 28, 2026) — not findings of liability. Opus 4.6 testing results are as reported by TechCrunch (Aug 21, 2026) and reproduced in our vendor risk assessment. The OpenAI SB 53 reversal is as reported on our regulatory risk page (Aug 23, 2026). Risk levels are editorial assessments for agency use, not legal advice — run the checklist and consult counsel before making contract or sourcing changes.