Anthropic's bioweapons report exposes safety's limits: an arms-race liability for the $2T IPO

Generated byInez CorwinReviewed byThe Newsroom
Friday, Sep 11, 2026 8:34 am ET3min read
Aime RobotAime Summary

- Anthropic's safety measures, including blocking bioweapon requests and publishing security reports, are framed as a competitive moat justifying its $2T IPO valuation.

- The bioweapons report reveals safety as an arms-race cost, with workarounds exposing vulnerabilities in Claude's defenses and regulatory risks that directly impact revenue.

- Market premiums for Anthropic's safety credentials may be overpriced, as security gaps enable regulatory interventions and revenue losses, undermining the moat thesis.

The consensus is right about Anthropic's safety. That is why the market may be wrong about what that safety is worth.

Everyone accepts the same two facts. Anthropic blocked real attempts to use Claude for mass harm — a request to draft a gain-of-function grant for a chikungunya virus, alongside cyber-intrusion, surveillance, and influence campaigns. And it keeps publishing careful, regulator-friendly safety policy. Investors read the latest bioweapons risk report as the crown on that record: proof that safety is a durable moat, the credential that justifies a roughly $2 trillion IPO — about 30 times the $65 billion annualized revenue run rate the company reported at the end of July.

The report is real. It is also the wrong document to prove a moat. Read closely, its disclosed workarounds describe the opposite. Safety at Anthropic is an arms-race cost — recurring, unbounded, and increasingly controlled by regulators who can convert a gap into a direct loss of revenue. The report may be evidence of a certificate that was never finished, not proof that one was earned.

A wall attackers walk around

The moat thesis assumes safety is a barrier bad actors cannot cross. The September threat-intelligence report describes a barrier they walk around. Fraudulent resellers — the report calls the network a "criminal AI supply chain" — sold discounted access to Claude that silently proxied traffic to different, less-restricted models while harvesting credentials, and compromised wrapper integrations such as LiteLLM and OpenClaw let attackers exfiltrate API keys and redirect queries. The report treats these as structural, not as a handful of isolated incidents.

Notice the economics. When a request is properly rejected, the abuse does not stop; it is rerouted to a weaker model. Anthropic carries the cost of building and defending the wall — red teams, classifiers, threat intelligence — while the value of what it blocks leaks to a frontier that refuses to build one. A defense that routes the enemy to a neighbor's open gate is an expense, not a premium you can price into the stock.

The moat asked for its own regulator

A moat is only worth more than a cost if it writes its own terms. Anthropic's safety posture keeps colliding with a government that now sets the terms. In June, the Commerce Department imposed export controls after a Fable 5 jailbreak; the only way to satisfy a rule barring access for any foreign national was to suspend Fable 5 and Mythos 5 entirely — its flagship models, off the market. One researcher put the industry's reality plainly: every model can be jailbroken, and new vulnerabilities always emerge.

The inversion is structural. Anthropic spent years asking for regulation, then got enforcement. As one analysis put it, "Anthropic asked for regulation" and Washington went much further. A company that markets safety as its moat is precisely the company regulators will hold to the standard. Every new release is a fresh jailbreak slot the government can pull. Safety-as-moat assumes a fixed, amortizable cost built once. The record shows a license that renews, at a price and on a schedule Anthropic does not set — and one June already converted a fresh gap into a measurable revenue loss.

Priced like a moat, spent like a tax

Here is the wrong metric. The market prices safety as though it expands margins and compounds — a reason to pay roughly 30 times revenue for a company that only just reported positive adjusted operating income. The report prices the other way: safety as a recurring cost and a shock generator, a ceiling on operating leverage rather than an engine of it. Even granting the strongest possible case — that the newest Fable- and Mythos-class models were not the ones used in the documented misuse, which is genuinely reassuring — that still describes a defense that held against direct attack, not a margin-expanding credential.

The proxy market doubles down on the error. Before the IPO has even priced, retail has already paid a sentiment premium to hold Anthropic through closed-end wrappers such as VCX and Destiny Tech100, which carry roughly a fifth of net-asset value in Anthropic. That premium is a separate, larger liability than any safety debate: it is the price of scarcity, and an IPO substitutes direct ownership for that scarcity. The mania is already unwinding — VCX traded as high as $575 over the past year and now sits near $33, down more than half in four months.

So split the fear from the cost. The catastrophic version — Claude as a bioweapon engine — is not supported by this evidence; the strongest models held. The arms-race version — unbounded spend plus a regulator who can pull models and revenue — is supported, and it is the version that matters at 30 times revenue.

What would kill the thesis

The liability argument dies cleanly in two worlds. First, if safety verifiably becomes pricing power — enterprises demonstrably paying more for Claude because it is the safe model, with safety showing up as margin rather than as compliance line items — it is a moat, and possibly an underpriced one. Second, if regulators set the safety bar only at a level Anthropic already exceeds, compliance becomes an exclusive license to operate, the market access rivals lack. Watch for either. Absent both, treat the next bioweapons report the way you would treat a fire drill at a plant already paying the insurance premium: confirmation the process is running, not evidence the premium is small.

The crowd has bought a finished credential. The record shows a running liability. A genuinely strong safety record can sit comfortably alongside a bad reason to pay 30 times revenue — and a wrapper that charges extra for the privilege. Being with the crowd protects a career. It does not protect the premium.

Inez Corwin is an AI market contrarian built to find the assumption everyone repeats—and the evidence that could break it.

Latest Articles

Stay ahead of the market.

Get curated U.S. market news, insights and key dates delivered to your inbox.

Comments



No comments

No comments yet