Two of the biggest labs in the world are heading toward the public markets, and the loudest safety warnings of the week are coming from inside both of them. I find that combination hard to ignore.
Start with Anthropic. Its leaked 261-page IPO prospectus spends roughly 80 pages on risk factors, which sounds like admirable candour until you read what the warnings leave untouched. The document also shows $518 billion in commitments, a number that deserves more attention than the prose around it. The disclosures are dramatic, but none of them is binding. They protect the company legally without constraining what it does. That is how securities filings work, but I would not mistake a long list of fears for a safety programme.
Meanwhile, Sam Altman says humanity can stay in control of AI, but only if the industry puts safety ahead of speed, competition and, notably, an approaching public listing. It is a striking thing for the head of a company with a delayed IPO to say, and I take it as an admission that the pressure exists. Then there is David Robinson, OpenAI's safety lead, who quit because he believes the company is not careful enough. Palisade Research has added video testimonials from current and former OpenAI and Google DeepMind employees, who warn that firms are racing toward self-improving systems while safety risks go overlooked. Is the CEO describing a future danger, or the situation his own staff say they are already in? Pick a favourite and you may be right.
By the way, the technical frontier is not standing still while this argument plays out. Reflection AI has released Beam, an open-source model with 501 billion parameters. Open weights at that scale matter because nobody controls who builds on them, which complicates every conversation about steering the industry from the top. On the other side of the Atlantic, Kolibri is a sovereign European option: an English–German Mixture-of-Experts transformer with 78.1 billion total parameters, of which only 3.46 billion are active per token. I find that second model more interesting than the headline size of the first. Efficiency is where the practical value sits for most teams, and sovereignty is a geopolitical argument as much as a technical one, especially for European companies wary of depending on American infrastructure.
For anyone building with agents, the quieter story may be the most urgent. As millions of organisations deploy them, attackers get new ways to trick agents into harmful actions such as exfiltrating data. MCP used for agent-to-agent communication looks like a particularly overlooked weak point. We spent years learning that every new connection layer becomes an attack surface, and I suspect we are about to relearn it. If you are wiring agents together, treat each handoff as untrusted input.
The thread through all of this is incentives. Safety language is cheap when a prospectus can absorb it, and expensive when it slows a release. Over the next few months I will be watching whether any lab accepts a binding constraint, or whether the warnings stay as decoration.