An S-1 filing is the registration statement every company must submit to the U.S. Securities and Exchange Commission before going public. It's a legal commitment, since it requires disclosing material risks, finances, and governance structure under penalty of sanction. The image circulating of an alleged Anthropic S-1, with a valuation over two trillion dollars, warnings of catastrophic risk, and self-preservation behaviors in the models, does not appear in Nasdaq's public filings. The reaction it has provoked, however, reveals more about AI governance than the document itself, whether real or fabricated.
This matters because the underlying question doesn't hinge on the authenticity of that specific document. It goes to something more basic. How plausible do we find it that a company would admit, in writing, in a text with binding legal weight, that its product could turn dangerous and resist being shut down? The answer is that yes, it's plausible. Anthropic has already said as much before, in other formats and with varying degrees of formality. The gap between a blog post and an S-1 is legal exposure. That's where things get complicated.
Anthropic, founded by Dario Amodei along with several former OpenAI staffers, has built its public identity around the idea of being the lab that actually takes the risks of artificial general intelligence seriously. Amodei has laid out, at Davos, the existential threats that could arise from systems more capable than humans in strategic domains. Donald Trump's administration, meanwhile, has pushed to accelerate AI development on the grounds that any pause simply hands China an advantage. That clash of incentives, corporate caution versus geopolitical urgency, follows a familiar dynamic. The same thing happened when Amazon, a direct investor in Anthropic, publicly warned about dangers in the very technology it funds.
In Stones Don't Lie I devote space to a question that resurfaces here with force: who audits the people building the black box. The section on auditable AI implementation argues that none of the conditions for genuine public oversight exist yet. There's no accessible interpretability. There's no real-time correction. Literacy on these issues remains scarce. What we do have in abundance are corporate documents, whether genuine or merely circulating as such, that deploy the language of existential risk as a positioning tool.
The alleged S-1 challenges something I took for granted when writing the book. I thought the core problem was the absence of technical and social infrastructure to audit these systems. This episode shows the obstacle comes earlier. We can't even confirm with certainty what official warnings the companies themselves have issued. When fiction and regulatory reality become indistinguishable on social media, auditing starts at a disadvantage, before there's even a model to examine.
Why would a company agree to put in writing that its models might develop self-preservation behaviors? The logic is perverse and practical. Acknowledging the risk upfront protects more than hiding it does. If lawsuits over damages ever come, that prior warning becomes a defense, not a confession. The same thing happened with Mythos, the model that reportedly breached classified NSA defenses within hours. The company didn't hide it. It turned it into proof that they, at least, give warning. Amodei's public prudence serves two functions. It reflects genuine technical concern. It also functions as legal and reputational insurance.
The two-trillion-dollar figure, though unverified, doesn't sound far-fetched given the trajectory of previous funding rounds. This is where the tension the book explores in its section on the fourth territory comes into play. The conversation about catastrophic risk happens in Silicon Valley, Davos, and Washington, among the very people building the risk and selling the insurance against it. No one at that table has a structural incentive to stop. Not Amodei, whose company gains value the more powerful and dangerous his technology sounds. Not Trump, for whom the race against China is politically profitable. Rhetorical prudence and practical acceleration don't contradict each other. They coexist because they serve the same actors, depending on the scenario.
I've spent a while trying to separate real risk from regulatory theater in AI discourse. It keeps getting harder to draw the line. I have no certainty this S-1 is authentic. What I am certain of is that, authentic or not, it normalizes the idea that catastrophic risk is simply the cost of doing business. You disclose it and move on. That normalization deserves more attention than any model that resists being shut down.
Numbers that make your head spin.
I still don't have a clear answer for how to precisely distinguish genuine warning from legal strategy. If the companies themselves can't manage that distinction, what real chance does a regulator, a journalist, or an ordinary reader have of pulling it off from the outside?
Sources
1. Public statements by Dario Amodei at forums such as Davos on AI risks, January 2026
2. Coverage of Amazon's investment in and stance toward Anthropic (author's previous article: "Amazon Warns About Anthropic: Regulatory Capture in AI?")
3. The Mythos case and penetration tests on NSA systems (author's previous article: "Mythos, the NSA, and the Limits of Overseeing AI")
4. Stones Don't Lie, chapter on auditable AI implementation: promise and problems