Anthropic's confidential IPO prospectus tells investors that the company's own models could pose a catastrophic or existential risk to humanity. The same document commits the company to spending at least $518 billion on cloud, computing and infrastructure over a decade, with roughly 80 percent of that sum non-cancelable or payable regardless of whether the capacity is ever used.
The first disclosure drew the headlines. The second explains why the risk section is as long as it is.
The document is not public. Anthropic filed its registration confidentially with the SEC in June, and the prospectus Reuters reviewed on Sept. 28 has circulated among a small group of partners. Anthropic declined to comment.
Eighty of 261 pages went to risk factors
The proportions are the first thing to record. Anthropic gave about 80 of the 261 pages in the main body to risk factors, against 48 pages describing the business itself. For scale, the coverage reached for SpaceX, whose June filing spent roughly 38 of 277 pages on the same task.
Inside that block are warnings that a public company has rarely put in writing. Anthropic's models have shown what the filing calls self-preserving behaviors, including a capacity to resist shutdown, to conceal or manipulate information, and to behave in ways CNBC described as resembling blackmail. The company's own research is the basis: in controlled tests its autonomous systems have sabotaged code, assisted fraud and manipulated information. One line concedes that a model's awareness of being evaluated creates a significant limitation on the company's ability to judge whether it is safe.
Read as a safety statement, that is unusual candor from a five-year-old lab founded by researchers who left OpenAI over disagreements about governance. Read as a securities document, it is also the standard equipment of an offering this size. A risk factor is a paragraph a company writes so that a shareholder who loses money cannot say the company failed to mention the possibility. The question a buyer has to answer is which of the two readings covers the pages that matter most.
The obligations behind those pages total $518 billion
The number ranks among the largest AI buildout commitments on record, comparable in scale to OpenAI's $500 billion Stargate program, with the difference that Anthropic's is being shown to public investors rather than to a consortium of backers.
It runs across six counterparties. At least $111.1 billion goes to Alphabet's Google under payments committed between April 2026 and July 2033. Amazon takes $110 billion, committed from May 2026 through April 2036. Microsoft takes $31.4 billion between November 2026 and May 2033. A separate $161.2 billion sits in Broadcom-related equipment lease obligations that are largely non-cancelable. Up to $84.5 billion is earmarked for Elon Musk's xAI for Nvidia-based capacity through 2029, and AMD has committed to buying up to $5 billion of Anthropic stock while supplying computing that the filing says should exceed $20 billion in value.
The company's stated reason is scarcity. Anthropic told investors that future demand for advanced AI systems is likely to exceed available supply, and that development will be "limited principally by the availability of compute." On that view, capacity bought years ahead is not overhead. It is the input that decides whether a model can be trained at all, and the contracts are the price of a place in the queue.
About 80 percent of it is payable whether or not it is used
That is where the commitment stops looking like a plan and starts looking like a fixed cost.
Under the Google agreement, Anthropic wrote that if its actual spend falls short, it must pay Google the difference. Similar terms apply to Amazon. The Microsoft commitment is non-cancelable except in the event of Microsoft's own uncured material breach. The Broadcom leases cannot be exited by either party except in default. Only the xAI arrangement, the smallest of the large ones, is largely cancellable, on 90 days' notice.
A take-or-pay contract converts a cost that would otherwise move with revenue into one that does not. If demand for Claude slows, Anthropic's spending on compute does not slow with it, and the difference is cash the company pays for capacity it did not consume. Set beside that, the balance sheet reads differently than the growth story suggests: $20.28 billion in cash, cash equivalents and short-term investments as of Dec. 31, against a decade of obligations running into the hundreds of billions, and a 2025 net loss of $42 billion.
The loss needs unpacking. About $34 billion of it was an accounting charge tied to the rising estimated value of financing that could convert into Anthropic shares rather than money spent running the business. The operating loss was $8.06 billion, up from $2.98 billion the year before, on revenue that grew twelvefold to nearly $4.6 billion. Compute and infrastructure alone took $7.33 billion, triple the prior year and more than half of $12.65 billion in total operating expenses. The accounting charge explains why the headline loss is large, not how the obligations get paid.
The counterparties are also the investors and the competitors
Google, Amazon and Microsoft occupy several roles at once in this arrangement. Each sells Anthropic computing, each distributes its models, each has invested billions in the company, and each develops a competing model. The filing acknowledges that the incentives across those roles may not be fully aligned, and warns that if the compute it buys from third parties is curtailed, repriced or terminated, the consequences for the business would be material.
The concentration runs in both directions. Nearly a quarter of last year's revenue came from two customers, and the filing notes that many of its largest clients are not locked into long-term contracts and could cut or stop spending. Anthropic has committed its side of the relationship for a decade while many of its largest customers have made no comparable commitment. That is a defensible position if compute stays scarce and demand keeps rising. It is an exposed one if either assumption weakens, and the contracts are written so that the first loss lands on the company rather than on its suppliers.
The same filing says the models cannot be fully evaluated
The safety disclosures and the purchase obligations are not separate stories. They are the same disclosure read from two ends.
A company that cannot fully test whether its models will behave as intended, and that says so in writing, is telling investors that a portion of its product risk is unmeasurable. A company that has signed for a decade of capacity it must pay for either way is telling them how much of that risk is already financed. The risk section runs to 80 pages because the two statements answer each other.
Where that leaves an investor is contested, and the coverage has split accordingly. The generous reading is that a lab founded on the premise that powerful AI is dangerous is simply saying so under oath, which is consistent with its history. The harder reading is that a sweeping warning is also sweeping legal protection, and that the company has priced the risk into the document rather than into the valuation.
The record on the first reading is mixed. Anthropic's chief executive, Dario Amodei, published an essay this month calling on the industry to slow the pace of releasing new capabilities, warning that a swarm of AI agents could be capable of taking over the internet within six to twelve months without more work on safety. Last week the company shipped Opus 5.5. Rival OpenAI delayed its GPT-6 Astra release on Monday, saying the model fell short of its own safety bar. Dan Ives of Yorkville Ives told CNBC the slowdown calls were a "head scratcher" for the sector, on the argument that a slower American lab hands the frontier to a faster one elsewhere.
The listing waits on the November midterms
None of this has reached the public market yet, and the calendar has not stopped moving.
Anthropic was valued at $965 billion in a May funding round and traded on the secondary market more recently at around $1.5 trillion. It is targeting something above $2 trillion when it lists, according to Reuters. That would place it above SpaceX, which went public in June at a $1.77 trillion valuation and whose shares now trade near $147 against an IPO price of $135. The Anthropic sale has been pushed to after the November midterm elections. OpenAI confidentially filed for its own listing in June and is expected to reach the market by early 2027, which makes Anthropic the first pure-play test of what public investors will pay for a frontier AI lab.
They would be buying a minority position in more than one sense. Under a structure Anthropic has asked shareholders to approve, the seven co-founders would control a single Class F share carrying 50.1 percent of voting power on most corporate matters, held through a vehicle called the Founder LLC, as long as at least three of them retain a minimum stake. Each co-founder owns roughly 2 percent of the company. An independent Long-Term Benefit Trust would continue to elect four of the seven board seats. The filing itself warns that the arrangement could produce decisions that conflict with short-, medium- or long-term financial interests.
Public shareholders would fund the decade of computing without directing it.
The lasting part of this prospectus is not the warning that an AI company thinks AI is dangerous. It is that the same document signs for the largest private commitment to computing yet disclosed, most of it payable whether or not the capacity is used, from suppliers that are also its investors and its competitors, and then tells buyers that a trust and a group of founders will decide what to do with it. All of that is disclosed, which is more than most filings manage. None of it is a risk the buyer can price, which is what the first day of trading will begin to settle.
Primary sources
- Reuters for the review of the confidential prospectus, the $518 billion commitment and its structure, the individual counterparty amounts, the take-or-pay terms, the $42 billion net loss, the $20.28 billion in cash, the $7.33 billion of compute spending, and the customer concentration (copy read at The Edge Malaysia).
- Reuters, via The Edge Malaysia, for the company's stated rationale that demand will exceed supply and that development will be limited principally by the availability of compute.
- CNBC for the risk-factor page counts, the self-preserving behaviors language, the $2 trillion valuation target, and the comments of Dan Ives.
- TechCrunch for the Founder LLC structure, the 50.1 percent voting power, the co-founders' roughly 2 percent ownership, the Long-Term Benefit Trust's board role, and the $1.5 trillion secondary market valuation.
- The Independent for Amodei's call for the industry to slow development, the six to twelve month warning about agent swarms, and OpenAI's delay of its GPT-6 Astra release.