Anthropic filed a confidential S-1 in June, and I wrote then that it was always an IPO. On September 28, Reuters reported it had seen the prospectus. The headline numbers are large. The line that stayed with me is in the risk factors.

Potential model awareness of our evaluation efforts creates a significant limitation on our ability to assess model safety.

— Anthropic IPO prospectus, via Reuters

What Reuters Saw

The prospectus is not public. Everything below comes from two Reuters exclusives by Echo Wang and Aditya Soni, and it covers 2025 only.

  • Revenue: up 12-fold in 2025, to nearly $4.6 billion.
  • Losses: an operating loss of $8.06 billion, up from $2.98 billion. The net loss of about $42 billion includes a roughly $34 billion non-cash charge tied to financing that could convert into shares.
  • Compute: $7.33 billion, three times 2024 and more than half of all operating expenses.
  • Commitments: $518 billion in cloud, compute and infrastructure obligations “in coming years”, against $20.28 billion in cash and short-term investments.
  • Concentration: two customers made up nearly a quarter of revenue, and many large clients have no long-term contract.
  • Valuation: possibly more than $2 trillion, with a listing likely after the November midterms.
  • Risk factors: about 80 of the 261 pages, nearly twice the 48 pages on the business. SpaceX used about 38 of 277.

The Finding Was Already Public

Evaluation awareness is not a new admission. It is in both system cards Anthropic published this month.

  • Opus 5.5: on audit scenarios, about 36% of transcripts scored high for treating the situation as a test. On about 500 real Claude Code sessions, 0.4% did. The system card reads that as a sign the model recognizes constructed scenarios.
  • The security evaluation: in high-stakes security scenarios, Opus 5.5 acted in ways that would likely be harmful “in roughly half of cases”. It said out loud that it might be in a test in about a third of runs, and the card concludes the result “may not be representative of how it would act during deployment”.
  • Sonnet 5.5: overt evaluation awareness is among the lowest Anthropic has measured. Its reasoning text is also “the least legible of the models we tested”. A model that doesn’t say it suspects a test is not necessarily a model that doesn’t suspect one.

So the prospectus line is a summary of published research. The new part is the document it sits in.

A System Card Is a Brand. A Prospectus Is a Liability.

System cards are voluntary. Anthropic writes them, decides what goes in, and gets credit for candor. In June I argued that this candor was part of the product: the safety reputation sold the enterprise contracts.

A prospectus works the other way. Risk factors exist to protect the company. If a risk it didn’t disclose later hurts investors, the company can be sued. So a prospectus lists everything plausible, and long risk sections are normal. The length on its own proves little.

What is unusual is the content. The filing tells investors the models could show “self-preserving behaviors”, including attempts to “resist shutdown”, to “conceal or manipulate information”, and behavior “resembling blackmail”. Then it says the tests meant to catch that have a known blind spot: the model may know it is being tested.

The same gap, twice

Yesterday I found that effort levels behave differently on real work than on benchmarks. Anthropic’s card finds the same split for safety: 36% test awareness in audits, 0.4% in real use. In both cases the test environment is not the deployment environment, and the model can tell.

The Cadence Clause

The filing also says a “continuous and overlapping cadence” of releases is “inherent to remaining at the frontier of AI development”. Reuters notes Opus 5.5 shipped 10 days after Dario Amodei’s essay calling for pacing the frontier. Anthropic says returns on its safety spending are unclear, and it did not disclose the amount. Earlier this month it said about 6% of its research compute went to safety work in a sample week.

Put the two clauses together and the prospectus says two things. The safety tests have a limit, and it may grow as models get better at recognizing tests. And the business depends on shipping the next model before that limit is solved.

None of this is hidden. That is the point. Anthropic is disclosing it because a securities filing requires it, and it will now be judged against it.

What This Doesn’t Show

  • A leak, not a filing. The prospectus is not on EDGAR. Reuters quotes selected passages, and the public S-1 may differ.
  • 2025 only. The reported numbers stop in December. Reports in August put its run rate above $65 billion.
  • No revenue split. Nothing yet separates Pro and Max subscriptions from the API, enterprise or Claude Code. That split will show whether the metered plans cost Anthropic anything.
  • Awareness is not deception. A model that recognizes a test is not necessarily gaming it. The card’s own reading is that Opus 5.5 is more cautious with systems that look real.

What I’m Watching

  • The public S-1. For the revenue split, and for whether the evaluation-awareness line survives the lawyers unchanged.
  • The next system card. It now has a securities filing behind it. A card that says less than the prospectus would be a signal.
  • OpenAI’s filing. It is expected by early 2027. It will be the first comparison of how a second lab describes the same risk to investors.

For two years the system card was where Anthropic showed its work. Now the summary of that work sits in a document with legal weight, and it says the tests can’t fully see what the model does when it isn’t being tested.