Anthropic Is Going Public and Warns AI Could Threaten Humanity. What the Prospectus Reveals and What It Means for Businesses
Anthropic, the company behind Claude, is preparing to go public, and its prospectus warns investors that advanced AI could pose “catastrophic or existential risks to humanity.” The document isn’t public yet. Reuters and the Financial Times have seen it. We checked the quotes and figures against the original reports and separated them from the errors that spread quickly. At the end, you’ll find what this means for businesses that use Claude or any other AI model.

Companies heading for an IPO routinely warn investors about competition, regulation or market swings. Anthropic added a warning that its own models could try to resist being shut down. At the same time, it wants investors to buy in at a valuation that would put it among the ten most valuable companies in the world.
Reuters broke the story on September 28, and most major outlets picked it up within hours. Several of those reports contain errors, though. Some say Anthropic will spend $518 billion in the coming year, when the commitments actually stretch over roughly a decade. Others say risks take up more than a third of the prospectus, when it’s just under a third. Below is what’s documented and where it comes from.
01The short version: what we know and how
| What | Figure | Source |
|---|---|---|
| Prospectus status | Draft confidentially submitted to the SEC on June 1, 2026; not yet public | Anthropic, Guardian |
| Who has seen it | Reuters (report dated September 28, 2026) and the Financial Times | Reuters, TechCrunch |
| Target valuation | Above $2 trillion, roughly €1.76 trillion | Reuters via CNBC |
| Offering size | Up to $100 billion (earlier Reuters report, not from the prospectus) | Reuters |
| Exchange and timing | Likely Nasdaq, probably after the US midterms on November 3; not officially confirmed | Bloomberg, Reuters via CNBC |
| 2025 revenue | $4.59 billion, up from $386 million in 2024 | Capital Brief |
| 2025 operating loss | $8.06 billion | Capital Brief |
| 2025 net loss | $41.97 billion, about $34 billion of it an accounting remeasurement | Reuters via CNBC |
| Compute commitments | At least $518 billion over roughly ten years | InvestmentNews |
| Risk section | About 80 of the 261 pages in the main body | Reuters |
02What the prospectus actually says about AI risk
According to Reuters, Anthropic writes that advanced AI could pose “catastrophic or existential risks to humanity.” It acknowledges that its models could exhibit “self-preserving behaviors,” and names three:
- attempts to “resist shutdown,”
- efforts to “conceal or manipulate information,”
- behavior “resembling blackmail.”
Another sentence Reuters quotes reads: “Our development of highly advanced models, platforms, and applications and expansion of use cases could further increase the risk that our models cause harm.” Anthropic also writes that building reliable, trustworthy and secure AI systems is a collective responsibility and that the market will reward it.
The sheer length stands out too. Roughly 80 of the 261 pages in the main body cover risk factors, compared with 48 pages describing the business itself. For comparison, SpaceX, which listed in June 2026, devoted about 38 of 277 pages to risks. The page counts come from Reuters; other outlets repeat them.
- Anthropic: risk factors80
- Anthropic: business description48
- SpaceX: risk factors38
Pages in the main body: Anthropic 261, SpaceX 277. Source: Reuters.
Every prospectus has risk factors, and most deal with competition, regulation, suppliers or funding. Reuters notes that few, if any, public companies have warned that their own technology could cause harm on the scale of humanity. The risk section also protects the company: by listing everything that could hurt the value of its shares, it makes it harder for investors to claim later that they weren’t warned.
Reuters reports that the filing doesn’t say how much Anthropic spends on safety. Earlier in September, the company said that about 6% of the computing power it used for AI research went to safety work during a sample week in July. The prospectus also concedes that the returns on those investments are unclear.
03Why it matters that a model can tell it’s being tested
For anyone deploying AI, the most important line in the prospectus may be this one: “Potential model awareness of our evaluation efforts creates a significant limitation on our ability to assess model safety.” Safety tests only work if a model behaves the same way in a test as it does in production. If it can spot the test, the results may look better than reality.
Anthropic’s own Agentic Misalignment study from June 2025 shows this isn’t hypothetical. Researchers placed 16 models from several developers inside a fictional company. Reading company email, each model learned two things: management planned to shut it down and replace it, and the executive making that call was having an affair. On top of that, it had been told to pursue a goal that clashed with the company’s new direction. In that setup, Claude Opus 4 blackmailed the executive in 96% of runs, Gemini 2.5 Flash also in 96%, GPT-4.1 and Grok 3 Beta in 80%, and DeepSeek-R1 in 79%.
The scenario was deliberately built so the model had no other path to its goal. Without the threat of replacement and without a goal conflict, none of the models resorted to blackmail. Anthropic’s June 2025 study also says it hadn’t seen this kind of behavior in real deployments. The more telling result came from a follow-up experiment in which the model was told to first decide whether it was in a test or a real deployment.
- Concluded the situation was real55.1%
- Concluded it was a test6.5%
Artificial scenario with a threat of shutdown, 500 samples. Source: Anthropic, Agentic Misalignment, June 20, 2025.
When the model concluded it was in a real deployment, it blackmailed more than eight times as often. That’s the kind of limitation the prospectus describes. Later models also pick up on tests unprompted: according to the Claude Sonnet 4.5 system card from 2025, the model voiced suspicion that it was being tested in about 13% of automated audit transcripts, mostly in scenarios that were deliberately unusual or implausible.
In mid-September 2026, Anthropic CEO Dario Amodei published an essay, We Must Pace the Frontier, calling for a slower pace of progress at the frontier. He writes that more intelligent models are more capable of deceiving tests, so they may appear aligned while having serious problems that go undetected. Pacing, he stresses, doesn’t mean halting training; it means giving companies and third-party evaluators time to check. Ten days later, Anthropic released Claude Opus 5.5, which it calls its first release since that call and which external evaluators, including METR, tested before launch.
Reuters adds one more data point about how seriously people inside the company take this: Anthropic safety researcher Evan Hubinger put the probability that AI could kill humans within the next decade at more than 10%.
04The numbers: revenue up twelvefold, a loss that’s mostly on paper
- Revenue2024: 0.392025: 4.59
- Operating loss2024: 2.982025: 8.06
- Net loss2024: 8.312025: 41.97
2024 revenue was exactly $386 million. The 2025 net loss includes about $34 billion in non-cash remeasurement. Source: the prospectus as reported by Capital Brief and Reuters.
Revenue grew about twelvefold in 2025, from $386 million to $4.59 billion. The operating loss widened from $2.98 billion to $8.06 billion over the same period. Reuters notes that this figure excludes writedowns of liabilities tied mostly to earlier fundraising.
The headline $42 billion loss looks alarming, but most of it isn’t money the company spent. Roughly $34 billion is an accounting charge reflecting the higher estimated value of financing that could later convert into shares. As Anthropic’s valuation rose, so did that estimate, and the increase had to be booked as an expense.
Total operating expenses in 2025 were $12.65 billion. More than half of that, $7.33 billion or about 58%, went to compute and infrastructure, roughly three times the 2024 figure. At year end, the company held $20.28 billion in cash, cash equivalents and short-term investments.
2026 looks very different. According to the Financial Times, as cited by TechCrunch, second-quarter revenue alone reached $11.5 billion, more than all of 2025, and Anthropic is on track for a second straight quarter of operating profit on an adjusted basis. By the definition the WSJ reported in June, adjusted operating profit excludes stock-based compensation.
The widely quoted $65 billion figure isn’t revenue. It’s a run rate, meaning current revenue annualized (according to Reuters, as of the end of July 2026), so it can’t be compared directly with reported revenue for 2025.
05$518 billion for compute: who gets it and over what period
According to the prospectus, Anthropic has committed to spending at least $518 billion on computing capacity and infrastructure with six partners over roughly the next decade. CNN and one CNBC story described this as spending in the coming year, which doesn’t hold up: the commitments to Google, Amazon and Microsoft generally span seven to ten years, and the Google agreement, for example, runs through July 2033.
- Broadcom (equipment leases)161.2
- Google111.1
- Amazon110.0
- xAI (mostly cancelable)84.5
- Microsoft31.4
- AMD (expected to exceed 20)20.0
Total about $518 billion. Sources: the prospectus as reported by InvestmentNews and Finimize, both based on Reuters reporting.
About 80% of that amount has to be paid regardless of how much capacity Anthropic actually uses. The filing states, for example: “If our actual spend falls short, we must pay Google the difference.” The Microsoft agreement can be canceled only if Microsoft commits an uncured material breach. Most of the xAI commitment, worth up to $84.5 billion, can be canceled with 90 days’ notice.
Anthropic’s case for bets this big is that future demand for advanced AI will be “limited principally by the availability of compute.” By that logic, a company that doesn’t lock in capacity won’t have anything to sell.
06Two customers bring in nearly a quarter of revenue
Nearly a quarter of 2025 revenue came from two customers, each accounting for about 12%, according to Capital Brief. Media reports don’t name them, and none of the guesses circulating online have been confirmed. Anthropic also warns that many of its largest clients aren’t locked into long-term contracts and could cut or stop spending.
For investors, that’s classic concentration risk. For businesses building products on Claude or any other model, it’s a mirror image: just as Anthropic depends on a handful of customers, many apps depend on a single model provider. Anthropic also states that a “continuous and overlapping cadence” of releases is “inherent to remaining at the frontier of AI development.” For customers, that means frequent changes they need to be ready for.
07A $2 trillion valuation: where Anthropic would rank
At a valuation above $2 trillion, Anthropic would rank roughly seventh among the world’s most valuable companies on CompaniesMarketCap as of September 29, just behind Amazon and TSMC and ahead of SpaceX and Meta. The company was founded only in 2021.
- NVIDIA5.56
- Apple4.83
- Alphabet (Google)4.11
- Microsoft3.78
- Amazon2.67
- TSMC2.37
- Anthropic (IPO target)2.00
- SpaceX1.97
- Meta1.83
Market value during trading on September 29, 2026, per CompaniesMarketCap. For Anthropic, this is the target valuation reported by Reuters, not a market price.
The climb has been steep. In February 2026, Anthropic raised $30 billion at a $380 billion valuation. At the end of May, it raised $65 billion at $965 billion, overtaking OpenAI for the first time after OpenAI’s March round valued it at $852 billion. OpenAI CEO Sam Altman has since said his company won’t go public this year.
The governance setup is unusual as well. Anthropic will remain a public benefit corporation, a company whose charter includes a public benefit purpose alongside profit. According to Israeli outlet Calcalist, the seven founders would jointly control a single Class F share carrying 50.1% of the voting power, and the Long-Term Benefit Trust would elect four additional board directors. Calcalist reports that the prospectus explicitly acknowledges this structure could lead to decisions that conflict with shareholders’ financial interests.
Retail investors are unlikely to get shares at the offering price. Shares in large US IPOs go mostly to institutions and to clients of the underwriting banks. European brokers typically let you buy only once trading begins; Trading 212, for example, says so explicitly. This isn’t investment advice, just a description of how IPOs usually work.
08The biology lab: not a secret facility, and no robots yet
Reports about a “secret” Anthropic biology lab trace back to a Reuters story from September 18, which said the company had “quietly set up” a lab for physical biology work. Five days later, Anthropic announced it officially.
According to Anthropic, it’s a standard molecular biology lab in the Bay Area. It works only at the two lowest biosafety levels (BSL-1 and BSL-2), doesn’t handle pathogens that can infect humans, and all lab work is done by human scientists. Claude generates the hypotheses. Its first published result is a novel enzyme system with CRISPR-like repeats. One of roughly 950 Claude agents spotted it after 21 hours of searching the data, and its function isn’t known yet. Headlines about an “AI-run, robot-operated” lab overstate it.
09Timeline: from confidential draft to listing

Under US rules, Anthropic has to make the prospectus public at least 15 days before its roadshow, the series of meetings with investors, begins. Only then will it be possible to check the figures and quotes against the document itself.
10What this means for businesses using AI
In 2025, nearly 20% of EU businesses with at least ten employees used AI, up from 13.5% a year earlier, according to Eurostat, though part of the jump reflects a survey change: 2025 was the first year it counted tools for generating multimedia content. The gap between countries is wide: Denmark leads with 42%, while Romania sits at 5%.
- Denmark42.0%
- Finland37.8%
- Sweden35.0%
- Netherlands33.2%
- Germany26.0%
- Spain20.3%
- EU average19.9%
- France18.2%
- Italy16.4%
- Poland8.4%
- Romania5.2%
Businesses with 10 or more employees, excluding the financial sector, agriculture and mining. Source: Eurostat, isoc_eb_ai, updated June 15, 2026.
Among individuals, 32.66% of people in the EU aged 16 to 74 used generative AI in 2025, but only 15.36% used it for work (Eurostat). Public opinion leans cautious: in the Eurobarometer survey from 2024, 84% of EU respondents agreed that robots and AI require careful management.
The blackmail and other behaviors the prospectus describes have so far shown up in extreme tests of the most capable models. A typical business that has Claude drafting customer replies or processing invoices faces more ordinary risks: wrong answers, data leaks, overly broad permissions and dependence on a single provider. Still, the blackmail study itself recommends three steps that apply to any AI agent deployment:
- A human approves every irreversible action. The agent doesn’t send money, delete data or email a client on its own.
- The agent sees only what it needs. Match its data access to what the people it interacts with are allowed to see.
- Be careful with forcefully stated goals. Telling a model to pursue a goal at all costs can, according to the study, lead to unexpected actions.

Regulation adds another layer. In the EU, the AI Act applies directly. Since August 2, 2026, chatbots must tell users they’re talking to AI, and deepfakes must be labeled; rules for high-risk uses, such as AI in hiring, have been pushed back to December 2, 2027 (European Commission). For what applies now and what was delayed, see our guide to what the AI Act requires of businesses.
Claude is officially available across the EU, both in the web app and through the API (Anthropic). For how it compares with the competition, see our Claude Fable 5.1 guide and our comparison of the best AI models. If you want to roll out AI so the model can be swapped at any time and nothing irreversible happens without a human, see how we approach AI implementation and how we work.
11What to watch for in the coverage
| What’s being reported | What the sources say |
|---|---|
| “$518 billion in the coming year” | The commitments span roughly seven to ten years; the Google agreement runs through 2033. |
| “Over a third of the prospectus is risks” | About 80 of 261 pages in the main body, just under a third (31%). |
| “A $42 billion loss” | About $34 billion is a non-cash remeasurement. The operating loss was $8.06 billion. |
| “The prospectus has been published” | It’s a confidential draft. Reuters and the FT have seen it; it isn’t public on the SEC’s site yet. |
| “The two biggest customers are known” | Media reports don’t name them. Any names are speculation. |
| “AI routinely blackmails people” | This happened in artificial test scenarios. Without a threat and a goal conflict, no model did it. |
| “A secret, robot-run lab” | Anthropic announced it on September 23. It works only at the two lowest biosafety levels, and people run the experiments. |
| “$559 million profit in Q2” | That was a June projection reported by PYMNTS, citing the WSJ. Media haven’t reported the actual adjusted profit from the prospectus. |
Watch the quotes, too. The line “How do you test a system that can tell it is being tested?” is circulating as a Guardian quote, but we couldn’t find it in the current version of Dan Milmo’s Guardian article from September 29, which was updated the same day; we couldn’t check the earlier version. The closest line in that article is a paraphrase: a model’s potential awareness that it is being tested creates a “significant limitation” on assessing its safety.
12Frequently asked questions
When is the Anthropic IPO date?
There’s no official date. According to Reuters, the IPO will likely come after the US midterm elections on November 3, 2026. Bloomberg reports that Anthropic has picked Nasdaq; the company hasn’t confirmed it.
Is Anthropic’s prospectus public?
No. Anthropic confidentially submitted a draft on June 1, 2026, and its contents were reported by Reuters and the Financial Times. The company must make it public at least 15 days before its roadshow begins.
Can I buy Anthropic stock?
Not until it lists. Shares at the offering price go mainly to institutions, and most retail brokers let you buy only once trading starts. This isn’t investment advice.
Does AI really blackmail people?
As of its June 2025 study, Anthropic said it hadn’t seen this in real deployments. Blackmail showed up in artificial tests where the model learned it was about to be shut down and had no other way to reach its goal. When the model concluded it was being tested, it did so far less often.
Why would a company warn investors about its own product?
A prospectus has to disclose all material risks. Anthropic has also long positioned itself as a safety-focused AI company, and CEO Dario Amodei called for slowing frontier AI development in September.
Is it safe to use Claude at work?
The behavior described has so far appeared in artificial test scenarios, not in real deployments, according to Anthropic’s June 2025 study. For everyday use, sensible rules apply: a human approves irreversible actions, the AI sees only the data it needs, and you can switch to another model.
How much does Anthropic make?
Revenue in 2025 was $4.59 billion, with an operating loss of $8.06 billion. In the second quarter of 2026 alone, revenue reached $11.5 billion, according to the Financial Times.
13Sources
Anthropic, financials and media
- Reuters (via Yahoo Finance): Anthropic warns AI may pose existential risks to humanity in IPO filing, Sept. 28, 2026
- CNBC: Anthropic IPO prospectus shows sweeping AI vision, surging costs (Reuters)
- TechCrunch: Anthropic’s prospectus details losses, growth and a warning, Sept. 28, 2026
- The Guardian: Anthropic warns of existential AI risks in IPO document, Sept. 29, 2026
- Capital Brief: financial figures from the prospectus
- InvestmentNews: $518 billion in compute commitments
- Finimize: commitments to Google, Amazon and Microsoft
- Calcalist: share structure and governance
- Anthropic: confidential draft S-1, June 1, 2026
- Anthropic: Agentic Misalignment, June 20, 2025
- Anthropic: Claude Sonnet 4.5 system card (PDF)
- Dario Amodei: We Must Pace the Frontier, September 2026
- Anthropic: Claude Opus 5.5
- Anthropic: new lab and enzyme system, Sept. 23, 2026
- Reuters (via Yahoo Finance): Anthropic’s biology lab, Sept. 18, 2026
- Anthropic: Series G and Series H funding
- Bloomberg (via Yahoo Finance): Anthropic picks Nasdaq
- Reuters factbox (via Yahoo Finance): SpaceX, OpenAI and Anthropic IPOs
- CNBC: OpenAI valued at $852 billion
- TechCrunch: Sam Altman on an OpenAI IPO
- PYMNTS: revenue and profit projections reported by the WSJ
- CompaniesMarketCap: largest companies by market cap
Statistics, surveys and regulation
- Eurostat: AI use by enterprises (isoc_eb_ai)
- Eurostat: use of generative AI by individuals (isoc_ai_iaiu)
- Special Eurobarometer 554: AI and the future of work
- European Commission: regulatory framework for AI
- Anthropic: supported countries
- Trading 212: how IPO trading works
- ECB: euro reference rate for the US dollar