{
  "id": "anthropic",
  "name": "Anthropic (Claude Platform + Claude Enterprise + Claude Code)",
  "subtitle": "Mapped to the 4+1 Layer AI Infrastructure Model",
  "version": "v1.1 - Reader-Legible Summary",
  "date": "July 22, 2026",
  "source": "Anthropic product documentation (Messages API, structured outputs, search results and citations content blocks, code execution / web search / web fetch / tool search server tools, OpenAI SDK compatibility endpoint, Claude Agent SDK, rate limits and service tiers, Message Batches, data retention and residency, customer-managed encryption keys), Claude Help Center (enterprise search / Ask Your Org, MCP connectors, organization-managed Skills and plugins, Claude Enterprise retention), Compliance API launch (May 21, 2026, 28 integrations), admin analytics and spend limits (July 2, 2026), Claude Cowork GA and Claude Code policy controls (April 9, 2026), Claude Managed Agents public beta (April 9, 2026), Claude 5 family — Fable 5 GA June 9, 2026; Mythos 5 limited release via Project Glasswing, Anthropic compute announcements (AWS Trainium / Project Rainier, Google TPU up to 1M chips, Broadcom 3.5 GW from 2027, SpaceX Colossus 1 agreement May 6, 2026: 220,000+ NVIDIA GPUs at $1.25B/month through 2029), DeepSeek Anthropic-compatible endpoint documentation and the Messages-API-compatible provider ecosystem (Qwen/DashScope, SiliconFlow, Kimi, GLM, MiniMax, StepFun), MCP under Linux Foundation Agentic AI Foundation governance, Microsoft Purview documentation for Claude, Layer2C Labs 001/006, published 4+1 model. Assessment provenance: dual-assessor process — a ChatGPT-drafted comparative assessment (July 2026) served as adversarial second grader (it contributed the SpaceX fleet facts and the split-execution framing; it omitted Cowork GA; its Ceded call on model serving was overturned by the interface litmus with documented multi-vendor evidence), and the native assessor is an Anthropic model, with every cell human-gated and calibrated against the OpenAI, Salesforce, Qlik, and cloud rows. Rulings applied from the OpenAI row (July 2026): substrate-surface rule at Layer 0; wrapper-vs-primitive discipline; completions-interface ruling extended — the Anthropic Messages API is documented as a second multi-vendor inference interface (independent vendor implementations driven by Claude Code compatibility), so model access behind either standard interface is Delegated; limited availability is a disqualifying status under the GA-gate. v1.1 (July 22, 2026): summary rewritten for reader legibility — instrument mechanics moved out of the lead, findings unchanged; no grade or DAPM changes.",
  "status": "complete",
  "summary": {
    "title": "Summary Finding",
    "paragraphs": [
      "Anthropic sells intelligence, not infrastructure. The buyer gets frontier Claude models, a serious agent runtime, and three first-party applications: Claude Enterprise for knowledge work, Claude Code for software engineering, and Cowork, which puts the same agentic engine in front of everyone else. Below those surfaces there's nothing to buy. One of the largest compute programs in existence, spanning Amazon's Trainium fleet, up to a million Google TPUs, and 220,000 NVIDIA GPUs rented from SpaceX, sits invisible behind the API. No compute, data platform, pipeline, or orchestration console is for sale. Five of the eight layers stay the enterprise's responsibility, and that's the same shape as OpenAI. The two model vendors are the first rows on this map with identical capability profiles.",
      "The difference is what the buyer can take with them, and it's substantial. Claude's serving interface is implemented by other vendors, so integration code written against it isn't hostage to Anthropic; Anthropic even ships an endpoint speaking OpenAI's format. Agents built on the open-source Agent SDK run in your own processes. Your tools, business logic, and validation code execute in infrastructure you control, not Anthropic's sandbox. Skills live as plain files in your own source control. And there's no fine-tuning product quietly accumulating weights you can never take. Of thirteen scored components, six are captive to Anthropic, four are swappable, three are outright yours. OpenAI's row reads nine captive, two swappable, two yours. That gap is structural, not marketing.",
      "There's a pattern behind it: Anthropic keeps giving the connective tissue away. It created MCP, the protocol every major vendor now uses to wire agents to tools, then handed it to the Linux Foundation. It published the Skills format. It argued publicly that you don't need a captive vector database to do retrieval. Shape the standard, skip the captive surface. The counterweight matters just as much: no open weights. OpenAI ships gpt-oss models you can own outright on your own hardware. Anthropic offers nothing equivalent, so leaving Claude always means arriving at another vendor's model, never at your own.",
      "What does accumulate is context. The enterprise keeps the assets Claude works on. Anthropic accumulates the record of how the enterprise works on them: projects, instructions, conventions, delegation habits, across Enterprise, Code, and Cowork, per user, per day. Swapping the model underneath moves none of it. The more judgment you borrow, the harder it is to leave as capabilities grow. That mechanism doesn't care which model vendor runs it.",
      "The open question is governance. Nobody at Anthropic sells you a way to register, police, and audit a fleet of Claude agents; today that job belongs to Microsoft's or Salesforce's control planes, or to code you write yourself. Anthropic's answer is hooks: deterministic interception points where your own validators decide what an agent may do. It hands you the seam and leaves the plane unbuilt. OpenAI at least has a product in limited release for this. Anthropic hasn't claimed the layer at all.",
      "The trade, stated plainly: the most open authority position any model vendor currently offers, in exchange for bringing your own everything below the runtime. The exits are real: two standard interfaces, an open SDK, portable skills, your own execution. Every one of them is a day-one architecture decision. The default path, hosted tools and first-party apps and compounding context, borrows more judgment every day it runs."
    ]
  },
  "layers": [
    {
      "id": "layer0",
      "label": "Layer 0",
      "shortName": "Compute",
      "title": "Compute & Network Fabric",
      "purpose": "Raw compute, networking, and acceleration fabric",
      "status": "gap",
      "statusLabel": "Compute Supply Chain, Not Customer Surface",
      "nvidia": [
        {
          "component": "No Customer-Facing NVIDIA Surface at Layer 0",
          "detail": "Anthropic runs the most silicon-diverse serving fleet on the instrument — AWS Trainium at Project Rainier scale (~500K chips scaling past a million), up to one million Google TPUs, and 220,000+ NVIDIA H100/H200/GB200 GPUs rented through the SpaceX Colossus 1 agreement (May 6, 2026, $1.25B/month through 2029) — and the customer touches none of it. No GPU generation, instance type, fabric, topology, or capacity administration is exposed. The transmitted NVIDIA dependency is zero; the upstream posture is deliberate multi-sourcing across all three silicon ecosystems rather than dependence on any one."
        }
      ],
      "gap": "The buyer never thinks about silicon, and that is the pitch. Behind the API sits one of the industry's largest and most diversified AI-compute supply chains: Amazon as primary training partner under a 5 GW commitment, the Google TPU arrangement, the Broadcom expansion from 2027, and the SpaceX Colossus capacity. That diversity is capacity and resilience for Anthropic. It does not become a Layer 0 product for the enterprise.\n\nThe exposure test governs (ratified CoreWeave 1C vs. Supermicro 1C; applied to Salesforce and OpenAI): an underlay capability the vendor does not surface as a purchasable, customer-administered product is not that vendor's capability. The substrate-surface rule makes the boundary decidable: Layer 0 credit requires the substrate itself to be the purchasable thing — silicon choice, instance types, fabric, placement. A direct Claude customer selects a model, service tier, inference geography, and commercial channel. They do not select or administer an accelerator, instance, network fabric, cluster topology, or serving placement.\n\nThe multi-owner sharpening from the OpenAI row applies with a wider spread: the same API contract can be served from AWS-owned, Google-owned, or SpaceX-owned facilities on three different silicon families, at Anthropic's discretion, invisibly. The enterprise's Layer 0 position under the first-party channel is unknowable. The counterweight is the same channel-choice escape: consuming Claude through Bedrock, Vertex AI, or Microsoft Foundry resolves the Layer 0 authority question deliberately — in that cloud provider's row, not this one.",
      "borrowedJudgment": "Total at Layer 0, and structurally invisible. Anthropic chooses the serving substrate, accelerator family, facility owner, and placement while exposing only the model and service contract. The vendor operating the most silicon-diverse fleet on the instrument transmits no Layer 0 authority to its customers at all.",
      "notes": "Watch-list (dated): Broadcom-supplied Google TPU expansion (~3.5 GW, from 2027) and Trainium3/4 commitments — upstream supply-chain context, never customer capability. Claude Gov and sovereign arrangements are bespoke, not purchasable products. Fact question standing (read of docs: no): any generally available product, outside cloud-provider channels and bespoke arrangements, letting a customer select and administer dedicated single-tenant inference capacity by accelerator, cluster, or fabric.",
      "components": []
    },
    {
      "id": "layer1a",
      "label": "Layer 1A",
      "shortName": "Storage",
      "title": "Data Storage & Governance",
      "purpose": "Durable, governed data foundation — the Governance Catalog that Layer 2C queries",
      "status": "gap",
      "statusLabel": "Compliance Surface, Not a Governance Catalog",
      "nvidia": [
        {
          "component": "No NVIDIA Layer 1A Dependency",
          "detail": "Anthropic's retention, residency, encryption, compliance, and tenant-administration controls are software and policy surfaces. NVIDIA provides no storage, catalog, classification, lineage, or governance component here."
        }
      ],
      "gap": "Anthropic has built a credible enterprise trust apparatus around data entering Claude: zero-data-retention arrangements for eligible API features, workspace-level inference-geography controls, customer-managed encryption keys, configurable retention with organization-level policy in Claude Enterprise, SAML SSO, SCIM, RBAC, domain capture, and IP allowlisting. Since May 21, 2026 the Compliance API exposes activity, chats, files, and projects programmatically, with 28 security and compliance integrations (CrowdStrike, Microsoft Purview, Okta, Wiz, Zscaler among them). That answers the question buyers ask first: can the enterprise use Claude while preserving retention, residency, encryption, audit, and legal-discovery controls.\n\nIt does not answer Layer 1A's architectural question. Anthropic provides no enterprise data catalog, classification authority, cross-system lineage, master data model, or authorization catalog that higher layers can query. The doc-confirmed findings mirror the OpenAI cell exactly: classification and authorization are inherited, not authored. Enterprise search preserves source-system permissions through per-user OAuth — Anthropic is a permission consumer, honoring the source system's catalog rather than being one. Purview integration means the governance authority for Claude-held data is another vendor's product.\n\nThe Salesforce/Qlik boundary (authorization authority versus curation) decides the cell: Anthropic does not reach the curation rung — there is no catalog to curate. Two contrasts with the OpenAI cell, carried honestly: Anthropic's residency apparatus is thinner (inference-geography controls and custom residency on request through sales-assisted Enterprise, versus OpenAI's ten self-serve regions), and the Compliance API's coverage reportedly lags Cowork — the newest GA application sitting outside the audit feed is a pattern worth tracking, not charging.",
      "borrowedJudgment": "None at the layer's architectural function. The enterprise's authoritative data, classifications, lineage, and access policies remain in source systems and existing governance platforms. Anthropic administers the storage and lifecycle mechanics for Claude-held content — captive administration that stays below the capability threshold, the same treatment the metering apparatus receives at 2A.",
      "notes": "Inference flags: Compliance API not covering Cowork rests on secondary sources — briefing fact question: is Cowork activity in the Compliance API feed yet? Texture question carried from the row's product cells: where the enterprise-search context physically lives and what admin surface governs it. Files, projects, chats, and session state are scored at retrieval, runtime, or application altitude where they perform their function, not double-counted here.",
      "components": []
    },
    {
      "id": "layer1b",
      "label": "Layer 1B",
      "shortName": "Retrieval",
      "title": "Context Management & Retrieval",
      "purpose": "Low-latency retrieval for RAG — vector/hybrid search, context windows",
      "status": "moderate",
      "statusLabel": "Federated Search, No Retrieval Estate",
      "nvidia": [
        {
          "component": "No Customer-Facing NVIDIA Surface at Layer 1B",
          "detail": "Anthropic exposes no vector-search library, embedding service, retrieval accelerator, or index architecture for NVIDIA to appear in. The near-empty column holds."
        }
      ],
      "gap": "Anthropic provides a real, permission-aware enterprise-search product without taking ownership of the connected data estate. Ask Your Org (enterprise search, GA for Team and Enterprise) searches connected work systems — Slack, Microsoft 365, Google Drive, and any custom MCP connector — through live MCP calls with per-user OAuth, preserves source-system permissions, and returns cited answers. Anthropic states that connected-source data is not externally indexed in its systems. At the API layer, search-result content blocks with structured citations let the enterprise bring results from its own vector database or search engine and receive citation-aware synthesis — a consumption contract for customer-owned RAG, not a hosted engine.\n\nThe absent estate is a stated philosophy, not an omission. Anthropic ripped vector search out of Claude Code in favor of agentic search, publishes contextual retrieval as a technique rather than a product, and ships no first-party embeddings (its docs point customers to third-party embedding providers). The enterprise is not waiting for Anthropic's vector store; Anthropic has argued it shouldn't want one.\n\nCalibration: the Qlik precedent is the exact shape — retrieval-as-product-feature rather than retrieval-as-infrastructure (no index management, no embedding choice, no external retrieval API) scored moderate. Within the grade, OpenAI sits at moderate's upper boundary (a hosted retrieval estate: vector stores, embeddings, a standalone search endpoint), Anthropic at its lower boundary (a search experience with no estate underneath). The authority inversion is the interesting finding: OpenAI's 1B capture is the retrieval estate accumulating in its namespace; Anthropic's posture externalizes the estate entirely, so it stays Retained by the customer, and what Anthropic captures is only the search experience. Less capability, less capture — orthogonality running in the buyer's favor.",
      "borrowedJudgment": "Split. Anthropic owns the Ask Your Org search instructions, query planning, and synthesis behavior — inherited, uninspectable, Ceded. The source permissions and connected systems remain authoritative, and MCP keeps the connector interface substitutable. When the enterprise supplies its own retrieval through search-result blocks, the retrieval architecture and its accumulated opinions (chunking, indexing, ranking) remain fully the enterprise's — the structural expression of 'borrow the vendor's plumbing, keep your own judgment' (Lab 001), offered here as the vendor's own design.",
      "notes": "Long context and prompt caching strengthen context handling but are not retrieval infrastructure. Not scored: search-result content blocks (crediting them as vendor capability would score the customer's estate to the vendor); no-first-party-embeddings noted with the third-party pointer. Inference flag (docs say live MCP; architecture behind SaaS is where docs go quiet): whether any persistent internal semantic index exists behind projects or enterprise search.",
      "components": [
        {
          "component": "Ask Your Org / Enterprise Search",
          "detail": "GA for Team and Enterprise. Permission-aware federated search across connected work systems via live MCP calls with per-user OAuth, returning cited answers. The search product, its Anthropic-managed instructions, and accumulated configuration are captive; the source data stays outside — the search experience is captured, the estate is not.",
          "dapm": "Ceded"
        },
        {
          "component": "MCP Connector Interface",
          "detail": "Enterprise search and Claude's connector surface consume MCP, a genuine multi-vendor standard under neutral Linux Foundation governance — authored by Anthropic and given away. Connector integrations built for Claude lift to any MCP-capable host without rebuilding the underlying data connections.",
          "dapm": "Delegated"
        }
      ]
    },
    {
      "id": "layer1c",
      "label": "Layer 1C",
      "shortName": "Pipelines",
      "title": "Data Movement & Pipelines",
      "purpose": "Move/transform data — ETL/ELT, lineage, cost-aware movement, KV cache tiering",
      "status": "gap",
      "statusLabel": "Feeds and Intake, Not Pipelines",
      "nvidia": [
        {
          "component": "No NVIDIA Layer 1C Dependency",
          "detail": "No movement platform exists to accelerate. Internal movement between storage and inference remains invisible and fails the exposure test."
        }
      ],
      "gap": "Thin by design, same as the OpenAI cell. What exists is intake and export edges, not movement: connectors perform live retrieval at query time (scored 1B), the Message Batches API queues large asynchronous inference jobs (a 2B serving mode), and the Compliance API is an export endpoint where the customer still builds the poller, checkpointing, transformation, and downstream workflow. No ETL/ELT authoring, no schema mapping, no CDC, no scheduling or dependency management, no lineage, no cost-aware movement, and no administrable KV-cache tier — prompt caching is a billing discount, exactly as ruled on the OpenAI cell.\n\nThe real-dependence guardrail does not trigger: connector configurations rebuild trivially and batch jobs hold no accumulated opinions. Calibration: OpenAI is the exact precedent (fixed intake, batch inference, and compliance export do not become general movement); Salesforce's MuleSoft/Informatica estate marks the opposite boundary. Movement between the enterprise's systems remains entirely the enterprise's problem, solved with its existing integration stack.",
      "borrowedJudgment": "None at the layer's architectural function. Pipeline definitions, transformations, scheduling, lineage, and destination choices remain in the enterprise's integration stack. Anthropic controls narrow API schemas, retention windows, and queue behavior — interface constraints, not accumulated pipeline judgment.",
      "notes": "Fact question (read of docs: no): does any generally available Anthropic service persistently ingest, transform, schedule, or synchronize data between enterprise systems independently of a Claude query — or are all connectors live retrieval and all outbound movement customer-built against export APIs?",
      "components": []
    },
    {
      "id": "layer2a",
      "label": "Layer 2A",
      "shortName": "Orchestration",
      "title": "Infrastructure Orchestration",
      "purpose": "GPU scheduling, quotas, RBAC, fair-share scheduling, utilization optimization",
      "status": "gap",
      "statusLabel": "Token Quotas, No Customer Plane",
      "nvidia": [
        {
          "component": "No Customer-Facing GPU Plane",
          "detail": "Layer 2A is where NVIDIA dependency concentrates for most of the map (Run:ai, GPU operators, schedulers), and Anthropic exposes no plane in which to be dependent. The NVIDIA tranche of its fleet sits invisible behind the same boundary as the Trainium and TPU tranches."
        }
      ],
      "gap": "Anthropic absorbs the entire infrastructure-orchestration problem behind the Claude API, and as with Salesforce and OpenAI, that is the offer. The customer's visible surface is the commercial metering edge: rate limits in requests and tokens per minute, org- and user-level spend limits with alerts (GA July 2, 2026), workspace overrides, Standard and Batch service tiers, and legacy Priority Tier throughput commitments. Every control is denominated in tokens, dollars, and availability — never in compute, scheduling, or placement.\n\nNo accelerator scheduler, cluster-placement surface, utilization view, fair-share policy over physical resources, or workload placement across infrastructure owners is exposed. The Salesforce precedent decides the grade: its 2A moderate required a deployable orchestration artifact (Runtime Fabric), with consumption metering ruled to weigh on the authority reading rather than lift the capability grade. Anthropic has no deployable artifact; a procurement surface is not an orchestration surface.\n\nThe Layer 0 unknowability recurs at this altitude with the row's sharpest version: the invisible upstream scheduler balances across three silicon ecosystems in three owners' facilities — Trainium at Rainier, Google TPUs, NVIDIA at Colossus — and the customer cannot see which served a given request. Rate-limit behavior and tier assignment are the visible shadow of one of the most sophisticated fleet schedulers in existence, and it is not a product. Exposure test, again.",
      "borrowedJudgment": "Total for the serving substrate, and unauditable. Anthropic decides accelerator selection, capacity placement, scheduling priority, failover, and overload policy; the customer administers the token bucket and the commercial service edge. No orchestration artifact accumulates customer-operable opinions, so the gap cell remains Retained by default.",
      "notes": "Inference flag: Priority Tier reportedly closed to new purchase (existing commitments remain throughput contracts) — pending doc confirmation. Fact question (the same one that closed the Salesforce and OpenAI cells): when Anthropic sells custom guaranteed capacity, can the enterprise allocate or isolate serving capacity by workspace, model deployment, geography, or tenant — or is the commitment operated solely as token throughput?",
      "components": []
    },
    {
      "id": "layer2b",
      "label": "Layer 2B",
      "shortName": "Runtime",
      "title": "Application Runtime & Execution",
      "purpose": "Model serving, agent execution, inference APIs, distributed inference",
      "status": "strong",
      "statusLabel": "Frontier Serving + Split Agent Runtime",
      "nvidia": [
        {
          "component": "No Customer-Facing NVIDIA Runtime Surface",
          "detail": "The serving fleet consumes NVIDIA capacity alongside Trainium and TPUs, and the runtime exposes no GPU selection, CUDA environment, inference server, or customer-administered accelerator surface. The API boundary transmits none of the dependency."
        }
      ],
      "gap": "A complete path from frontier inference to executable agents, frontier-pegged by rule 6. The Messages API serves the Claude 5 family (Fable 5 GA June 9, 2026) with versioned models, structured outputs (GA), structured tool calls, prompt caching, and long context. Anthropic-operated server tools — web search, web fetch, tool search, and sandboxed code execution — are GA with no beta header. Claude Code is a production coding agent, and the open-source Claude Agent SDK exposes the same loop — sessions, permissions, hooks, subagents, tools, MCP — inside customer-operated processes.\n\nThe distinctive architecture is split execution. Claude supplies the model and tool-selection behavior; hosted server tools are optional; customer-defined tools, files, commands, hooks, MCP servers, and deterministic validators can remain in infrastructure the enterprise controls. The buyer gets frontier intelligence without placing every action and artifact inside a vendor-hosted runtime. The capable-but-captive ruling applies as it did for Salesforce and OpenAI: platform binding is an authority finding, not a capability deduction.\n\nThe authority map is graduated, as ratified on the OpenAI row — and Anthropic's serving now sits behind two multi-vendor standard interfaces. The Messages API has independent implementations across the industry: DeepSeek documents an official Anthropic-compatible endpoint, and Qwen/DashScope, SiliconFlow, Kimi, GLM, MiniMax, and StepFun ship the same shape — the Claude Code compatibility wave made Anthropic's API the second multi-vendor inference interface. Anthropic also serves the first one, via its official OpenAI-SDK-compatibility endpoint (documented limitations: no strict tool schemas, no prompt caching through it). Integration opinions built against either shape run on multiple vendors; what remains is behavioral recalibration, graduated by how far past the standard interface — into hosted tools and harness semantics — the buyer builds.\n\nThe absence that completes the picture: no open-weight models and no general fine-tuning product. OpenAI's row carries gpt-oss Retained — an owned-intelligence path Anthropic does not offer (Mythos 5 is limited-release through Project Glasswing, watch-listed) — and carries a fine-tuning surface Anthropic simply doesn't sell, one fewer captive surface by structure.",
      "borrowedJudgment": "The model-judgment concentration all model-vendor rows carry — alignment, refusal behavior, safety tuning, lifecycle — with one Anthropic-specific vividness: Fable 5's safety architecture visibly routes, blocking responses in designated high-risk domains and falling back to Opus 4.8. That is vendor-side judgment executing inside the request path, inherited and uninspectable. Mitigations: version pinning, multi-cloud channels, and the two standard serving interfaces. The switching cost is architectural, not fixed (Lab 006: put the judgment in the constraints, not the weights) — production model swaps with no rebuild are documented where application logic lives in deterministic code, and the compatibility-endpoint ecosystem cuts both ways: the harness has become a portable habitat whose model is swappable, in either direction. The exit Anthropic does not offer is ownership: no open weights means leaving Claude is always leaving to another vendor's model, never to your own.",
      "notes": "GA-gate exclusions (dated watch-list): Claude Managed Agents (public beta, April 9, 2026 — composable APIs for cloud-hosted agents: sandboxed execution, checkpointing, credential management, scoped permissions, tracing; a 2B/2C straddle at GA); computer use (beta); Files API (still requires a beta header); Mythos 5 (limited release via Project Glasswing — limited availability is disqualifying under the GA-gate). Resolved fact question from the comparative draft: the Agent SDK operates against non-Claude models through compatible interfaces (unsupported by Anthropic, real in the field — the compatibility ecosystem exists to serve it). Instrument follow-up logged: the OpenAI row lacks a symmetric customer-executed-tools component for function calling; /reconcile should add one rather than let the rows diverge silently.",
      "components": [
        {
          "component": "Model Serving via Messages API + Compatible Interfaces",
          "detail": "GA. Frontier Claude serving consumed through interfaces the litmus now reads as multi-vendor standards: the Messages API shape has independent implementations (DeepSeek's documented Anthropic-compatible endpoint; Qwen, SiliconFlow, Kimi, GLM, MiniMax, StepFun), and Anthropic ships an official OpenAI-SDK-compatibility endpoint on the completions standard. Integration opinions lift; the remaining switching cost is behavioral recalibration — the managed-Kubernetes kind of cost, graduated by architecture, not a rebuild. Channel choice (Bedrock, Vertex, Foundry) remains a procurement fact; the interface ecosystem is the authority fact.",
          "dapm": "Delegated"
        },
        {
          "component": "Anthropic Server Tools + Code Execution (Hosted)",
          "detail": "GA, no beta header. Web search, web fetch, tool search, and sandboxed code execution run on Anthropic-operated infrastructure. The proprietary surface beyond the standard interface: sandbox contract, tool versions, and execution service are Anthropic's, and opinions built against them run nowhere else — the hosted-platform analog of OpenAI's Responses surface.",
          "dapm": "Ceded"
        },
        {
          "component": "Claude Code (Runtime Altitude)",
          "detail": "GA. Production agent harness — sessions, built-in tools, permissions, hooks, subagents, context management. Runs locally in customer infrastructure, but the binary and harness opinions are proprietary: self-deployable is not Retained. Symmetric with Codex on the OpenAI row. The application altitude is scored at Layer 3, not double-counted.",
          "dapm": "Ceded"
        },
        {
          "component": "Claude Agent SDK (Open-Source)",
          "detail": "GA. Open-source agent framework exposing the Claude Code loop in customer processes — self-hostable, runnable against any Anthropic-compatible endpoint including third-party models that implement the shape. Matches the Agents SDK, Agent Framework, and ADK Retained calls: code built on the open SDK lifts out.",
          "dapm": "Retained"
        },
        {
          "component": "Customer-Executed Tools (Client-Side Tool Use)",
          "detail": "The enterprise owns and operates the business logic, APIs, commands, and deterministic validators invoked through client-side tool calls — the DCITL seam, where control passes from instructing the model to executing code outside it. Replacing Claude requires an adapter and re-evaluation, not rebuilding the capability.",
          "dapm": "Retained"
        },
        {
          "component": "MCP",
          "detail": "The multi-vendor protocol for connecting tools and data to agent runtimes — authored by Anthropic, governed neutrally under the Linux Foundation's Agentic AI Foundation, implemented industry-wide. The standards-authoring finding: Anthropic built the portable interface and gave it away, the ecosystem-shaping play (the SONiC precedent) run at the tool layer. MCP servers and their integrations serve any compatible host.",
          "dapm": "Delegated"
        }
      ]
    },
    {
      "id": "layer2c",
      "label": "Layer 2C",
      "shortName": "Reasoning",
      "title": "Agentic Infrastructure — The Reasoning Plane",
      "purpose": "Policy-driven placement and resource coordination — the Autonomy Layer",
      "status": "gap",
      "statusLabel": "Runtime Permissions, Not a Reasoning Plane",
      "nvidia": [
        {
          "component": "No NVIDIA Layer 2C Dependency",
          "detail": "NVIDIA provides none of Anthropic's permission rules, hooks, approval mechanisms, or governance semantics. The near-empty column continues."
        }
      ],
      "gap": "What ships is real and deliberately placed: permission rules, hooks, sandbox restrictions, human-approval callbacks, and admin-enforced managed settings (GA April 9, 2026 — org-wide deny rules and mandatory policy users cannot weaken) around Claude Code and the Agent SDK, plus Cowork's RBAC and analytics surfaces. These are deterministic controls that can block a proposed action before it runs. They answer 'is this action permitted inside this runtime' — and they all live inside Anthropic's execution harness, strengthening 2B.\n\nThey do not establish a 2C plane. No agent registry, no cross-runtime agent identity, no estate-wide policy service, no broker, no constraint solver, no policy-driven placement, no deterministic outcome validator. The moderate cohort's bar (Salesforce, AWS, Databricks, IBM: a productized, GA governance plane across an agent estate — gateway, registry, governed identity) is exactly what is absent, the same calibration that decided the OpenAI cell.\n\nThe model-vendor headline finding has its twin here, with a sharper edge. Claude-powered agents are governed today by other vendors' reasoning planes — registered in Agent 365, brokered by Agent Fabric, given identities by Entra. But where OpenAI's 2C gap is pre-GA (Frontier, in limited availability), Anthropic's is unclaimed: no announced first-party governance plane at all. What Anthropic ships instead is the seam — interception points where external governance engines and customer-owned deterministic validators wire in. The control point is offered to the enterprise's code rather than productized above it: a designed posture, the Dell 'deliberate ecosystem play' finding in miniature. A seam is not a plane, and the real-dependence guardrail does not trigger on interception points.\n\nUniversal findings logged as universal: no live inference placement (the multi-silicon fleet is invisible, per 2A — the customer cannot express a placement policy), and no deterministic outcome validation (hooks gate the legality of actions; nothing validates the rightness of outcomes — you can't prompt your way to deterministic output).",
      "borrowedJudgment": "No scored Anthropic 2C component exists, so the cell is Retained by default — and in practice the enterprise discharges the function with a different vendor's product or its own code at the hook boundary. That is the most consequential architecture decision a Claude buyer makes, and it is made outside the Anthropic relationship entirely.",
      "notes": "Watch-list: Claude Managed Agents (public beta April 9, 2026) — scoped permissions, checkpointing, and tracing make it a 2B/2C straddle at GA. Claude Code managed settings named as the GA thin surface, sub-threshold (platform administration of one vendor's runtime, the same treatment as OpenAI's admin RBAC). Fact question (read of docs: no): any GA control plane registering and governing multiple deployed Agent SDK applications centrally — agent identity, lifecycle, policy assignment, revocation.",
      "components": []
    },
    {
      "id": "layer3",
      "label": "Layer 3 (+1)",
      "shortName": "Applications",
      "title": "AI Application Layer — The Value Plane",
      "purpose": "AI-powered business capabilities — business logic, workflow automation",
      "status": "strong",
      "statusLabel": "First-Party Value Plane: Work, Code, Cowork",
      "nvidia": [
        {
          "component": "No NVIDIA Layer 3 Dependency",
          "detail": "The value plane is Anthropic IP end to end. The customer-facing NVIDIA column closes the row empty — the same closing finding as the OpenAI row: silicon exposure through a model vendor is a price, not an architecture."
        }
      ],
      "gap": "Three first-party application relationships, not two. Claude Enterprise is the horizontal knowledge-work surface: conversations, projects, enterprise search, file and artifact workflows, Skills, plugins, and organization administration. Claude Code is the developer application across terminal, IDE, desktop, and browser — peer to Codex on the OpenAI row. And Cowork (GA April 9, 2026, macOS/Windows, all paid tiers) is the piece OpenAI does not have GA: an agentic desktop application for non-developers, running the Claude Code architecture against knowledge work — it takes a goal, decomposes it, reads and writes files, works across connected apps, and executes long-running tasks under enterprise RBAC with an Analytics API and OpenTelemetry traces. Around them: Claude in Slack, Chrome, and Excel as embedded surfaces, plugins packaging Skills and connectors, and org-wide distribution of approved extensions.\n\nThe extension surface makes the value plane general rather than fixed: Skills, plugins, and MCP address work Anthropic did not anticipate. Calibration: strong, frontier-pegged, peer to the OpenAI row's Layer 3 — the assistant-altitude caveat carried one notch narrower, because Cowork moves real agentic file-and-workflow execution to GA while systems-of-record execution under commit-boundary governance (the Salesforce altitude) remains nobody's GA story at this layer but Salesforce's.",
      "borrowedJudgment": "High and compounding, architecturally separable. The enterprise keeps source documents, repositories, business systems, customer-authored tools, MCP servers, and portable Skills. Anthropic accumulates conversation history, project context, user instructions, workspace configuration, plugin choices, Claude Code conventions, Cowork delegation habits — the enterprise keeps the assets Claude works on while Anthropic accumulates the context describing how the enterprise works on them, per user, per day. The more judgment you borrow, the harder it is to leave as capabilities grow: the same compounding-context capture as the OpenAI row, and it survives model interchangeability entirely — swap the model underneath and none of it moves.",
      "notes": "Watch-list: newer application surfaces still in beta or preview are not required for the grade and are not scored. Inference flag: Skills portability across implementations rests on the published format being adopted beyond Anthropic — the Retained call survives either way (customer-authored artifacts in the enterprise's own source control, plain-file format), but multi-implementation adoption is doc-supported rather than doc-confirmed. Fact question: can an enterprise export and reconstitute its complete Claude application estate — projects, org-distributed Skills and plugins, user instructions, persistent working context — in a vendor-neutral format?",
      "components": [
        {
          "component": "Claude Enterprise (Knowledge-Work Estate)",
          "detail": "GA. The horizontal knowledge-work application and workspace: conversations, projects, enterprise search, org administration, installed extensions, and accumulated working context inside Anthropic's proprietary application, with no operable cross-platform exit. The fastest-compounding captive artifact set on the row.",
          "dapm": "Ceded"
        },
        {
          "component": "Claude Code (Developer Application)",
          "detail": "GA across terminal, IDE, desktop, and browser surfaces. Repositories stay portable; the application relationship — interaction model, orchestration behavior, configuration, delegation patterns — is proprietary. Runtime scored at 2B, not double-counted. Symmetric with Codex.",
          "dapm": "Ceded"
        },
        {
          "component": "Cowork (Agentic Knowledge-Work Application)",
          "detail": "GA April 9, 2026. The Claude Code agentic architecture productized for non-developers: autonomous multi-step task execution over files and connected apps, with enterprise RBAC, Analytics API, and OpenTelemetry traces. Delegation habits, task patterns, and workspace configuration accumulate in the application. The 1A note travels with it: Compliance API coverage reportedly lags Cowork (inference-flagged).",
          "dapm": "Ceded"
        },
        {
          "component": "Customer-Authored Agent Skills",
          "detail": "Skills are filesystem artifacts in a published format, stored in the enterprise's own source control and reusable across implementations that support the spec. The portable-artifact counterweight on this row — procedural knowledge the enterprise owns, structurally analogous to gpt-oss on the OpenAI row (portable knowledge rather than portable weights).",
          "dapm": "Retained"
        },
        {
          "component": "MCP Connector Ecosystem",
          "detail": "The multi-vendor interface to third-party applications and data, under neutral governance. Menu-altitude Delegated matching the Apps-SDK-on-MCP call on the OpenAI row: connector implementations and source-system authority remain outside Anthropic; Claude-specific installation and configuration must be recreated on another host.",
          "dapm": "Delegated"
        }
      ]
    }
  ]
}
