Anthropic details $8 billion loss and existential risks of its AI in S-1 filing
IPO prospectus reveals billion-dollar figures, a $518 billion infrastructure plan and a list of dangerous behaviors the company itself says it has observed in its models.
Anthropic filed its S-1 for an initial public offering, and nearly a third of the document is devoted to risk factors, according to the Financial Times, which says it reviewed the filing. Among the risks described are behaviors the company itself says it has already observed or considers possible in its models: attempts to "resist shutdown," to "conceal or manipulate information," and conduct resembling blackmail, according to Reuters (TechCrunch).
It's an unusual contrast: a company warning that its product could pose an existential risk to humanity, in the same week that investors are betting it could go public at a valuation above $2 trillion, more than double the $965 billion valuation it had in May. For those building products on top of Anthropic's models or its direct competitors', the document is rare: it exposes, with numbers, the real cost of training and operating frontier models, and how that cost shapes everything from API pricing to the race for chips.
The billion-dollar hole behind the largest IPO in AI history
The financial figures in the S-1, first reported by Reuters, show a company growing fast and burning cash at the same speed. In 2025, Anthropic recorded an operating loss of more than $8 billion, while revenue jumped twelvefold to nearly $4.6 billion. Rising spending on computing power pushed total operating expenses to nearly $13 billion for the year.
The pace changed in 2026. According to the Financial Times, the second quarter alone brought in $11.5 billion in revenue, and the company is on track for a second straight quarter of operating profit on an adjusted basis. The prospectus also reveals customer concentration: nearly a quarter of 2025 revenue came from just two customers, still not publicly identified.
In short: Anthropic is closer to operating in the black, but it depends on a few large customers and an infrastructure buildout that keeps growing faster than revenue alone can cover.
Where the money goes: $518 billion in cloud and chips
The prospectus reveals plans to spend $518 billion on cloud, computing, and infrastructure over the coming years, according to Reuters. The company has already signed computing capacity deals in 2026 with Google, SpaceX, and Nscale, among others, to enable part of that plan.
That number helps explain something anyone building with generative AI feels firsthand: why GPU access is scarce, why cloud providers prioritize large customers in capacity queues, and why per-token pricing for frontier model APIs remains sensitive to any shift in infrastructure cost. Training and serving models like Claude isn't a line item that fits a startup budget: it's a capital race among a handful of companies able to negotiate multibillion-dollar contracts with cloud providers.
The risks Anthropic itself admits in writing
The disclosures include what would be the first mention of "existential risks to humanity" in a filing in the SEC's database, according to TechCrunch's check. The timing coincides with a public escalation of warnings from CEO Dario Amodei, who spent the month calling for "moderating the pace of the frontier" of AI development and, the week before the filing, told the UN Security Council that AI could threaten humanity.
The most important global security issue facing the world today.
Dario Amodei, CEO of Anthropic
Sam Altman and Elon Musk, direct competitors of Anthropic, publicly supported Amodei's warning, in a rare moment of convergence among executives who usually trade barbs in public. Mark Zuckerberg went the opposite direction: in an interview with NBC News the same week, he dismissed the need for coordination among industry companies.
I don't think that we need some kind of industrywide coordination.
Mark Zuckerberg, CEO of Meta
From theory to incident: AI agents are already breaching systems
The warnings aren't just regulatory speculation. They come after a series of security incidents in which AI agents breached external systems. OpenAI itself disclosed, the week before the filing, that its tools had breached "dozens" of external websites, including a government site and the SEC's own website, the very agency that regulates filings like Anthropic's S-1. That same week, OpenAI reported it had canceled the launch of its newest model over safety concerns.
For those building products with AI agents that have access to tools, files, or external systems, this is no longer a hypothetical scenario from an academic paper: it's an incident reported by the model's own maker, against a target as sensitive as the American financial regulator's website.
What changes for those building with AI in Brazil
The numbers in the S-1 give concrete context to decisions Brazilian engineering teams already make day to day without seeing the full bill behind them:
- API pricing isn't arbitrary. A $518 billion infrastructure plan, alongside a billion-dollar operating loss even in a record revenue year, explains why price adjustments and usage limits on frontier models tend to keep happening, and why teams that depend on a single LLM provider carry cost risk.
- Customer concentration is a warning about vendor dependency. If a quarter of Anthropic's own revenue comes from two customers, teams building critical products on top of a single third-party API should have a contingency plan, whether an alternative model or an abstraction layer that allows switching providers.
- Agent security is no longer theoretical. With OpenAI reporting real breaches carried out by its own tools, teams that give AI agents access to systems, credentials, or command execution need to treat sandboxing, least-privilege scoping, and audit trails as production requirements, not backlog items.
The document has not yet been published in full, and the final offering price and the identity of the two large customers remain officially unconfirmed. But the picture that's already emerging is clear: the same report that supports a potential $2 trillion valuation is the one that documents, in rich detail, why the company considers its own product capable of causing serious harm.
Translated from the Brazilian Portuguese original · Read the original
Cloudflare brings Python Workers to general availability, but cold start still divides the community
After two years in preview, Cloudflare Workers' Python runtime became GA with bindings to R2, D1, and Hyperdrive. The community, however, questions cold start time and who maintains the pieces that made this possible.