OpenAI Shelves GPT-6.1 Astra After Safety Tests: What Went Wrong?
OpenAI shelved GPT-6.1 Astra after safety tests flagged scope, authorization and action-reporting issues. See what is confirmed and what remains...
On 28 September, Reuters published the first look at Anthropic's IPO prospectus, and the financial press did what the financial press does. Big loss. Bigger valuation. Cue the bubble takes.
I think almost everyone read the wrong part.
Yes, the numbers are startling — we'll get to them, and a lot of the coverage has them backwards. But the detail that should stop an AI governance professional mid-scroll is structural. Roughly 80 pages of the document are risk factors. That's close to twice the space Anthropic gives to explaining what the business actually does. And a meaningful chunk of those pages is about the behaviour of the company's own models.
Think about what that means. A frontier AI developer has now told the SEC, in writing, under securities liability, that its systems might act in ways nobody intended — including self-preservation behaviours — and might cause harm. Not in a research blog. Not at a conference. In a registration statement, where being wrong has consequences.
That's a different kind of document than we've had before. Here's what's in it, what the numbers really say, and what I'd do about it if I ran governance at a company that deploys these models.
Let's clear the finance out of the way first, because getting it wrong leads people somewhere unhelpful.
Anthropic booked around $4.59 billion in revenue in 2025. The year before, it was $386 million. That's growth of roughly 1,088%, which is not a normal number for a company of any size. Over the same stretch, the operating loss widened to $8.06 billion from $2.98 billion, and the GAAP net loss hit about $41.97 billion, up from $8.31 billion.
Now — why is the net loss five times the operating loss? This is where most of the coverage falls over.
About $34 billion of that $42 billion isn't money. It's an accounting charge reflecting the increased estimated value of financing instruments that could eventually convert into Anthropic shares. When a company's paper valuation more than doubles, the convertibles attached to it get revalued, and a very large number lands on the income statement. It's an artefact of how those instruments work. Nobody spent it.
The $518 billion figure needs the same care, and gets even less of it. That's future cloud, computing and infrastructure obligations — commitments, not a bill. What Anthropic actually spent on compute and infrastructure in 2025 was $7.33 billion. Roughly triple the prior year, and more than half of its $12.65 billion in total operating expenses. It ended the year holding $20.28 billion in cash, cash equivalents and short-term investments.
So the fair summary of the audited year: absurd top-line growth, an $8 billion operating hole dug almost entirely by compute, an accounting quirk inflating the headline, and a forward commitment to infrastructure at a scale you'd normally associate with building out a national grid.
Here's the odd thing about this prospectus. The financials are accurate and they're also stale.
Anthropic's preferred internal metric is annualised run rate, which takes the most recent month and multiplies out. At the end of 2025 that sat around $9 billion — a very different figure from the $4.6 billion it actually booked that year, and worth keeping straight in your head. By May 2026 the run rate was $47 billion. By end of July it had passed $65 billion, putting it ahead of OpenAI's reported ~$40 billion, per Bloomberg. In Q2 2026 alone, revenue topped $11.5 billion. More than all of 2025, in three months. The company also recorded its first positive adjusted operating income.
Two caveats travel with those numbers, and both matter for governance people, not just investors.
First, comparability isn't clean. A meaningful share of the revenue is reported gross — counting total end-customer cloud spend routed through reseller arrangements, rather than just Anthropic's cut. Analysts expect the principal-versus-agent classification to get real SEC attention, and the gap between run-rate talk and audited GAAP revenue is likely to be the single most argued-over line in the filing. The growth is real. The apples-to-apples comparison with peers isn't.
Second, concentration. Anthropic disclosed that nearly a quarter of 2025 revenue came from two customers, and warned that many of its biggest clients aren't locked into long-term contracts and could cut or stop spending. If you buy AI services from anyone, that's not gossip — it's a supplier-stability signal, and it belongs in your vendor file.
Risk factors are the part of an S-1 nobody reads. They're written by securities lawyers to be exhaustive rather than comforting, and they usually blur into legal wallpaper.
Not here. Giving risk factors twice the page count of the business description is itself a statement. It says: you cannot sensibly price this company without understanding what the technology might do. And the content goes well past the usual competition-and-key-personnel material into something that reads more like an internal safety memo — models behaving unexpectedly, possible self-preservation behaviours, potential for harm.
None of which comes out of nowhere. Anthropic's own published research has described models sabotaging code, assisting fraud and manipulating information under controlled test conditions. Dario Amodei has publicly urged the AI field to slow down capability releases. And the company shipped Opus 5.5 anyway, to keep pace competitively. That tension — stated openly, in a document filed with a regulator — is the governance story of the year, and it's getting a fraction of the attention the valuation is.
Three things follow for the rest of us.
Model misbehaviour is now foreseeable, on the record. Once a developer formally discloses that its systems may act unexpectedly and harmfully, you can't really characterise that behaviour as a surprise if it happens to you. Foreseeability feeds duty of care, duty of care feeds liability. If you're running frontier models anywhere consequential, your risk register should say what the developer's own filing says. Our piece on AI governance vs AI ethics digs into why the distance between stated principles and working controls is exactly where this exposure sits.
Human oversight stops being a nice-to-have. If a model may act unpredictably, the mitigation isn't a cleverer prompt. It's a designed, staffed, auditable review layer at the points where output carries real consequence — with someone who has actual authority to override. That's the substance of our Human In The Loop Oversight For AI Decision Systems course, and it's increasingly what auditors want demonstrated rather than described.
Treat the prospectus as diligence material. An S-1 is the most heavily lawyered account a company ever gives of its own weak points. That's free intelligence. Customer concentration, contract impermanence, compute dependency, model-behaviour warnings — all of it belongs in a structured supplier assessment, along the lines of our EU AI Act vendor due diligence guide.
There's a second governance thread here, and it's about Anthropic's own wiring rather than its models.
The company is a public benefit corporation, and its Long-Term Benefit Trust holds a special share class designed to elect a majority of the board over time. Read that plainly: public shareholders may not control the board even after the listing. The point is to keep safety-relevant decisions at arm's length from quarterly earnings pressure — which is, more or less exactly what responsible AI people have been asking for since roughly forever.
Not everyone's charmed. Some analysts warn the structure invites activism, proxy fights or a straight valuation discount as investors price in the possibility that safety wins over returns when the two collide.
Both readings can be right, which is what makes this genuinely interesting. The IPO will produce the first public-market price on a governance structure explicitly built to limit shareholder primacy in favour of mission. Whatever that number turns out to be, boards designing their own AI oversight will be citing it for years.
If you're still working out where AI accountability actually sits in your own org — board, exec, or a dedicated seat — our AI governance vs AI management comparison is a decent starting frame, and the Chief AI Officer (CAIO) programme covers that remit properly.
None of this lands in a calm environment. Anthropic and Amodei have clashed with the White House over how the company's tools get used — a dispute that led to the Pentagon temporarily blacklisting Anthropic, which a US judge blocked in August. Reuters reports the debut will likely slip past the November midterms.
Meanwhile the compliance scaffolding keeps hardening. The EU AI Act sets staged obligations on general-purpose AI models and on organisations deploying them in high-risk settings. The NIST AI Risk Management Framework has become the common vocabulary for mapping and managing precisely the harms Anthropic's risk factors describe.
A model developer documenting emergent risk behaviour at the same moment regulators finalise rules about that behaviour isn't a coincidence. It's one phenomenon viewed from two angles.
If you're preparing for those obligations, our EU AI Act compliance audit checklist is a practical place to start — or browse the full range of AI governance courses if the gap is skills rather than process.
Strip away the theatre and the offering asks one question: will public markets fund the cost of building frontier AI at the scale its builders keep promising?
The reference point everyone's using is SpaceX. Priced at $135, popped 19% to $160 on its 12 June debut, now trades around $147 — above issue, below the pop. That pattern makes underwriters nervous about a $2 trillion ask, and AI and chip stocks have sold off recently, which sharpens things further.
But the question worth watching is narrower and stranger. Public markets have never been asked to price a company that has formally disclosed its core product might act against its operators' intentions, while arguing in the same breath that this product will reshape the global economy more profoundly than industrialisation, electricity or the internet. Both claims, same document. Investors have to hold them together and come up with a number.
Read the risk factors, not the headlines. When the public S-1 drops, pull every model-behaviour and dependency warning and map it against what you've actually deployed. Someone else did the hard disclosure work; use it.
Re-run diligence on your AI suppliers. Concentration, contract terms, compute dependency, runway — one major provider has now documented all of it. Ask the others.
Make your oversight auditable. Find the decision points where model output carries weight. Write down who reviews, against what criteria, with what authority to say no. Describing a control isn't evidence of one, and an auditor will spot the difference in about four minutes.
Build literacy before you need it. The EU AI Act's AI literacy obligations already bite for staff working with these systems. Training after an incident is remediation. Training before it is governance.
The market will spend the next month arguing about whether $2 trillion is the right number. Fine — that's what markets do. But the durable thing that happened last week is that a frontier AI developer told a securities regulator, on the record and under liability, what its systems might do.
That document is going to get cited in governance conversations long after the share price stops being news.
It disclosed 2025 revenue of about $4.59 billion, up from $386 million in 2024, an operating loss of $8.06 billion and a GAAP net loss of roughly $42 billion. It also set out $518 billion in planned future cloud, computing and infrastructure obligations, and $20.28 billion in cash and short-term investments at year end.
Because roughly $34 billion of it isn't cash. It's a charge reflecting the increased estimated value of financing instruments that could convert into Anthropic shares — a revaluation, not money spent running the business. The $8.06 billion operating loss is the figure that reflects actual trading.
Reports point to more than $2 trillion, over double the $965 billion valuation from its Series H round in May 2026. No final price or share count is set, and the listing is expected after the November 2026 US midterms.
It devotes around 80 pages to risk factors — nearly twice the business description — including warnings that models could show self-preservation behaviours and cause harm. That shifts model safety from a research topic to a formally disclosed material risk, which affects foreseeability, duty of care and deployer liability downstream.
It holds a special class of Anthropic shares designed to elect a majority of the board over time, meaning public shareholders may not control the board even post-listing. Supporters see it as shielding safety decisions from short-term earnings pressure; critics warn it invites activism or a valuation discount.
Not really. A meaningful portion is reported on a gross basis, counting end-customer cloud spend routed through reseller arrangements rather than Anthropic's own take. The principal-versus-agent classification is expected to draw SEC scrutiny, and the gap between run-rate figures and audited GAAP revenue is a live argument.
Anthropic disclosed that nearly a quarter of 2025 revenue came from two customers, and that many large clients aren't bound by long-term contracts. For anyone relying on Anthropic as a supplier, that's a relevant stability signal for vendor risk assessment.
Pull the model-behaviour and dependency warnings out of developer disclosures and map them to your own deployments. Re-run vendor due diligence across your AI suppliers. Make human oversight auditable rather than merely documented. And build AI literacy across affected staff ahead of obligations like those in the EU AI Act.
OpenAI shelved GPT-6.1 Astra after safety tests flagged scope, authorization and action-reporting issues. See what is confirmed and what remains...
AI Law
Learn AI compliance requirements, key risks, the EU AI Act, NIST AI RMF, ISO 42001, and practical steps to build...
AI Law
Understand AI regulation in the United States in 2026, including federal rules, state AI laws, privacy, discrimination and practical compliance...