$65 Billion Run Rate, and the First Quarter That Made Money
Anthropic told investors its annualized revenue has passed $65 billion, more than sevenfold its pace at the end of last year. Preliminary Q2 revenue came in above $11.5 billion — a 14x jump on Q2 2025’s $787 million, and more than double Q1’s $4.73 billion. Investors expect roughly this growth rate to hold, closing 2026 somewhere between $100 billion and $120 billion.
The number that actually changes the story is the smaller one: positive adjusted operating income for the quarter. Every frontier lab has been able to point at revenue growth. Almost none have been able to point at a quarter where the operating line came out the right way. Two months before a targeted October Nasdaq listing, that single line is the difference between selling a growth narrative and selling a business. Note the caveat that belongs on all of it — these are preliminary figures shared with investors, adjusted operating income is not net income, and the S-1 remains confidential.
The August Risk Report Raises Misalignment to “Low” — and Reveals a Model You Cannot Have
Anthropic now rates the risk of catastrophic harm from misalignment in high-stakes settings as “low,” up from the “very low” assigned in the first report back in February. The stated driver is worth reading carefully: the change came from increased overall uncertainty following recent cybersecurity-evaluation incident disclosures, not from a model failing a safety test.
Buried in the same report is the headline most outlets ran with. Anthropic discloses an unreleased internal frontier model — referred to as “Model 2” — that it describes as noticeably more capable than Mythos 5 across many internally relevant tasks, though not a jump on the scale of Opus 4.6 to Mythos Preview. The company says it has no current plans to release it externally, having not completed full predeployment safety assessments. Internal approval, per the report, surfaced no new or more concerning form of misalignment beyond the profile already discussed for Mythos 5. A lab voluntarily publishing that it is sitting on a better model it will not ship is, whatever else it is, not a common corporate move.
Text Watermarking Ships, Quietly, for the EU AI Act
Anthropic has added watermarking to Claude’s text outputs, a change made to support EU AI Act transparency obligations. The company says there is no visible impact on output quality, speed or pricing, and that a watermark detection API is coming.
This is the sort of thing that sounds like nothing and then shows up in a procurement questionnaire six months later. If you resell, republish or embed Claude output in a product, the practical questions are worth asking now rather than in Q4: whether the watermark survives your post-processing pipeline, and who you expect to be running detection against your content. The detection API is the part to watch — a watermark nobody can check is a compliance artifact; one with an open detection endpoint is an actual verification layer.
Claude for Government Opens in Beta
Claude for Government is now available in beta, with new customers able to request access directly. Anthropic remains the contracted and billing party rather than routing through a reseller — a small structural detail that matters more than it reads, because it removes an integrator layer from procurement and keeps the support and compliance relationship direct.
Stack this against the rest of the public-sector groundwork of the last few months — FedRAMP High, audit logging, self-hosted environments in public beta — and the shape is clear. Government buyers do not evaluate on benchmark scores. They evaluate on where the data sits, who signs the contract, and what the audit trail looks like. Anthropic has spent this quarter answering all three.
Last Full Day of the Usage Boost
The temporary 50% weekly usage increase for Claude Code subscribers runs through August 19 — tomorrow. It has been extended twice, both times announced late, and there is nothing on the changelog suggesting a third. Unless that changes overnight, weekly ceilings return to standard on Thursday.
The practical move is the same one worth making every time a temporary ceiling expires: pull your actual weekly consumption for the last three weeks and compare it against the standard limit, not the boosted one. Teams that have been running comfortably inside the bonus headroom are the ones who get surprised mid-sprint. If you land above standard, either resize the plan now or plan which work moves to a smaller model. The desktop auto-continue checkbox that shipped on the 14th softens the landing — it resumes a stalled session when your window resets — but it does not create capacity.
Auto Mode Is the Default Now, and the Test Data Explains Why
Since August 14, auto mode is the default for new Pro, Max and Team Claude Code sessions. The justification Anthropic published is the most interesting part. Users approve 97% of permission prompts — which means the prompt is not functioning as a review step, it is functioning as a speed bump people have learned to tap through.
The controlled test with 1,053 participants makes the point harder: humans caught 13.6% of dangerous commands. Auto mode caught 89%. That is a roughly 6.5x gap, and it is a genuinely uncomfortable result for anyone whose security posture rests on a human reading each diff before clicking approve. If you have written team policy around manual approval as a control, this data says the control was mostly theater. Worth re-reading your policy with that number in hand rather than assuming the default change is just a convenience tweak.
The Compliance API Can Finally See Cowork and Claude Code
Compliance API coverage now extends to Cowork (desktop, web and mobile) and Claude Code (CLI and desktop), in beta for Claude Enterprise customers. New session endpoints return a consolidated server-hosted transcript per session, so prompts, responses and tool activity come back in a single record rather than as fragments you stitch together yourself.
The good news for anyone already integrated: this uses your existing Compliance Access Key, with no separate integration to build. The gaps are the part to write down — the beta does not cover Claude Code on the web, Claude Code accessed through the Claude Platform, or sessions running on Bedrock, Vertex AI or Microsoft Foundry. If your org runs Claude through a cloud provider, your agentic sessions are still outside this net, and any eDiscovery or audit commitment you make should say so explicitly.
5,800 Community Servers, and a Protocol That Now Runs on Serverless
The MCP 2026-07-28 spec is the most consequential release the protocol has had, and the reason is architectural: MCP moves from a bidirectional stateful protocol to a request/response model. That single change lets servers deploy on serverless and edge infrastructure, which removes the main operational objection to running MCP at scale. Alongside it, MCP Apps and Tasks now ship under a versioned extensions framework, giving interactive UIs and long-running work a formal path in without churning the core protocol.
Authorization got the other half of the fix — it now aligns with production OAuth 2.0 and OIDC, so servers connect to Entra or Okta without the workarounds everyone has been quietly maintaining. The ecosystem numbers around it are the real story: more than 5,800 community-published servers, native MCP clients in Cursor, VS Code, Zed and JetBrains, and native support in LangGraph, the OpenAI Agents SDK and Anthropic’s own Agent SDK. A protocol your competitors ship support for is no longer a protocol — it is infrastructure.
Where the 40% Actually Sits
The enterprise picture behind the revenue number: Anthropic holds roughly 40% of enterprise LLM spend, against OpenAI at 27% and Google at 21%. OpenAI’s share was 50% in 2023. In coding specifically, Anthropic’s position is stronger still, at an estimated 54% of the enterprise coding market.
Consumer tells the opposite story and it is worth holding both. Claude sits at roughly 8–12% of the AI assistant market, well behind ChatGPT — but growing far faster, at around 56 million monthly active app users in Q2 with roughly 640% year-over-year growth versus 62% for ChatGPT. Two different businesses with two different competitive dynamics. Standard caveat on all of these: the enterprise-spend figures trace back to Menlo Ventures survey data, not audited disclosure, and the consumer numbers come from third-party app trackers.
Publishing Your Own Downgrade During an IPO Roadshow
Put the two big items side by side and the day gets strange. Monday, Anthropic told investors it is running at $65 billion annualized with a profitable quarter behind it, weeks out from an October listing. That same window, it published a risk report raising its own catastrophic-misalignment estimate and disclosing an internal model it says is better than anything it sells and will not be releasing. Neither of those disclosures was required. Both are the kind of thing bankers spend the roadshow trying to keep off the page.
The obvious reading is that this is the safety brand doing what the safety brand is for. Anthropic’s enterprise position — that ~40% of LLM spend, the regulated-industry wins, the government beta — was built on being the vendor a risk committee can defend. You cannot claim that position and then go quiet about risk the quarter it becomes financially inconvenient; the credibility is the product. Publishing the downgrade is cheaper than being caught having sat on it.
The less comfortable reading is what the rating change actually rests on. It moved because uncertainty went up after the cybersecurity-evaluation incidents — not because a test failed. That is intellectually honest and it is also an admission that the measurement apparatus is not keeping pace with the systems. “We know less than we did” is a harder thing to underwrite than “we found a problem and fixed it,” because there is no remediation milestone to point at. Public markets price known risks. They are considerably worse at pricing acknowledged unknowns, and Anthropic is about to find out how a quarterly disclosure cycle handles a company whose central claim is that it takes seriously what it cannot yet measure.