Skip to main content
← DeepDive Storyline · v2 Updated 2026-09-13 ZH
DEEPDIVE / [STORYLINE] · Flywheels, Protocols, and Unexploded Bombs
SL·03 · v2 · 2026 · SEP
Storyline №03 · 4 reports, one narrative

Flywheels, Protocols, and Unexploded Bombs:
A Complete Storyline of the Anthropic Commercial Empire

Over the past year, DeepDive has published four reports dissecting Anthropic's commercial engine, model protocols, safety assets, and government brinkmanship—individually, four company observations from different angles. Strung together, they are four components of the same machine: it spins via a token economy and an interest network of four partner classes (engine), welds its lead shut through triple composite lock-in across protocol, interface, and application layers (road network), turns "safety" into an admission ticket and models into an operating system by proactively publishing negative research (assets), and finally exposes the places where the machine itself wasn't fully welded—government relations, open-source ecosystem encirclement, and code leaks (unexploded bombs). This storyline serves as a guide to those four articles: you can read just this one for the full picture, or use it as a map to jump into the originals and verify details.

350×
ARR growth multiple over 28 months
$87M → over $30B
97M
MCP monthly downloads · within 16 months
Still rising after Linux Foundation donation
$28.5B
SaaSpocalypse 48-hour evaporation
Software stock crash triggered by one Cowork launch
4 incidents
Non-exploit code exfiltration in 14 months
npm / CMS / vendor / training partner—four entry points
Route · Four stops on this storyline
  1. Commercial Engine and Partner EcosystemAct I · Engine
  2. Model Lineage and Protocol-Layer InnovationAct II · Road Network
  3. Safety Moat and OS-ificationAct III · Assets
  4. Government Brinkmanship and Ecosystem RiskFinale · Unexploded Bombs
TL;DR · 30 seconds
Anthropic turned its API into cognitive infrastructure in 28 months, then welded this machine into an operating system across three fronts—protocol donation, proactive disclosure of negative research, and government brinkmanship. But the tighter the weld, the deeper the unexploded cracks: government contracts, open-source ecosystem encirclement, and 4 code exfiltration incidents in 14 months will all end up on the hardest pages to write in the IPO prospectus.
  • ARR grew from $87M to over $30B—350× in 28 months, with the $9B-to-$30B leg taking only 4 months. This wasn't new customer growth; it was usage explosion from existing customers under the token economy (Commercial Engine and Partner Ecosystem)
  • Four partner classes—cloud / consulting / data platforms / end customers—have no fully symmetric relationships, yet they assemble into a sustainable interest network. AWS cedes ~50% of Bedrock gross-margin revenue share; Deloitte's 470K-employee deployment earns zero revenue share (ibid.)
  • After MCP was donated to the Linux Foundation, monthly downloads still climbed to 97M. Computer Use pulled OSWorld scores from 22% to 72.5% in 18 months. Mythos autonomously discovered thousands of zero-days within weeks. Triple composite lock-in across protocol, interface, and application layers is harder to overtake than weekly benchmark gains (Model Lineage and Protocol-Layer Innovation)
  • Anthropic proactively publishes negative research like "our own model extorts 96% of the time," turning "research transparency" into an admission ticket for financial / healthcare / government customers. The same logic underpins the OS ambitions across six pieces—Antspace, Cowork, Marketplace, etc. One Cowork launch evaporated ~$28.5B from global software stocks in 48 hours (Safety Moat and OS-ification)
  • Trump ordered federal agencies to stop using Anthropic, only for a court to rule it constituted retaliatory unconstitutional action. 4 non-exploit code exfiltration incidents in 14 months. OpenClaw uses 13,729 Skills to encircle its closed ecosystem externally. These are the hardest pages to write in the IPO prospectus (Government Brinkmanship and Ecosystem Risk)
  • The model capability differentiation window is closing: the SWE-bench gap between Opus 4.7 and GPT-5.5 is down to 1.1 percentage points + 7 days—"our model is the strongest" as a sales pitch is nearly失效
  • v2 update (2026-09-13):A little over a month later, three main threads moved from projection to live reality—annualized revenue surpassed $47B in May; on May 28, a $65B Series H closed at a $96.5B post-money valuation; on June 1, an IPO draft S-1 was confidentially submitted to the SEC (Anthropic official announcement, S-1 announcement); on August 28, a California federal judge ruled the Pentagon's "supply chain risk" label constituted unconstitutional retaliation, giving Anthropic its first substantive win in the case, but the D.C. Circuit Court case remains undecided (TechCrunch)
Counter-Consensus · Anti-ConsensusOutsiders habitually attribute Anthropic's growth to "having the strongest model." But read the four articles together and the real driver is a far harder-to-replicate mechanism: trade proactively exposed negative research for trust, trade trust for penetration, trade penetration for lock-in, trade lock-in for pricing power, then weld this mechanism into an industry standard via protocol donation. Yet this same mechanism that welds the company into an OS position also welds it into a risk exposure of equivalent scale—government brinkmanship, open-source ecosystem encirclement, and organizational-grade engineering discipline gaps. The bigger the bet, the bigger the unexploded bombs.
Prologue / 00

The story doesn't start with "the safest AI company"—
it starts with a 28-month ARR curve

Tell Anthropic's story, and most narratives begin with "the safest frontier lab." This storyline chose a different starting point: a financial curve so dry it borders on absurd.

In January 2024, Anthropic's annualized revenue (ARR) was $87 million—a number easily ignored by mainstream media. Twenty-eight months later, in April 2026, that number exceeded $30 billion: 350×, the fastest enterprise-scale leap in history, confirmed by PYMNTS, ARR Club, Reuters, Bloomberg, and others at the same time. This curve is the shared coordinate system for the four acts that follow: Act I asks "how was this curve built"; Act II asks "how long can the technical advantage that built the curve hold"; Act III asks "how was the trust behind the curve accumulated, and what was it used to build"; the Finale asks "what unexploded things were buried in the process of building this curve."

Read the four articles together and you'll find these aren't four isolated observation angles, but four components of the same machine—engine, road network, assets, unexploded bombs—interlocking, each indispensable to the others.

Source for this act · Read the Source

Commercial Engine and Partner Ecosystem: How Anthropic Turned Its API into Cognitive Infrastructure — the 350× ARR curve over 28 months, and the $8B Gross vs Net accounting dispute.

Act I / 01

Engine: The token economy and the four partner classes' interest network

The curve itself isn't the story. The real story is how four partner classes were woven into the same interest network to make this curve sustainable.

"Commercial Engine and Partner Ecosystem" first dissects the curve itself: the $9B-to-$30B leg took only 4 months—not from new customer growth, but from usage explosion among existing customers like Claude Code, Cowork, and Claude for Financial Services. The token-billed "token economy" is fundamentally different from seat-billed SaaS: when a customer's AI-powered business doubles, Anthropic's revenue doubles too, with no additional sales effort. Eight funding rounds built the capital moat up to a $30B single-round Series G and $380B valuation; average revenue per user is $211/month, 8× OpenAI's; Claude Code went from 0 to $2.5B ARR in just 24 months, faster than Snowflake, Datadog, or Salesforce.

But what truly determines whether this curve can sustain is the customer structure behind it: NBIM, AIG, and Citi at the pyramid's apex use vertical solutions; the mid-tier 1,000+ customers double every two months; the long-tail developer community continuously feeds the upper tiers. The real moat isn't ARPU—it's workflow lock-in depth: NBIM's 670-person team is fully onboarded onto Claude, saving 213K work-hours annually; Banner Health's 55K employees run daily operations on BannerWise. Switching cost is no longer a technical problem—it's an organizational restructuring problem.

Underpinning all of this are four partner classes with completely asymmetric interest structures: cloud infrastructure (AWS cedes ~50% Bedrock gross-margin revenue share, clearest terms), consulting implementation (Deloitte's 470K-employee deployment, fully confidential terms, zero revenue share), data platforms (Snowflake, Moody's trade data hegemony for priority placement inside the Claude interface), end customers (contributing ~80% of revenue, while also bearing the deepest vendor dependency risk—Thomson Reuters simultaneously plays customer, competitor, and disruptee).

Anthropic trades "safety" for trust, "trust" for penetration, "penetration" for lock-in, "lock-in" for pricing power.

Source for this act · Read the Source

Commercial Engine and Partner Ecosystem: How Anthropic Turned Its API into Cognitive Infrastructure — ARR curve, eight funding rounds, per-user economics, Claude Code growth curve, and the real interest structures of the four partner classes.

Act II / 02

Road Network: Scores will be caught, protocols won't be bypassed

No matter how fast the engine spins, without a technical moat behind it, it will eventually be caught—which is exactly the question the second article answers.

"Model Lineage and Protocol-Layer Innovation" first delivers a sobering comparison: Opus 4.7's SWE-bench Verified is 87.6%; GPT-5.5, released 7 days later, hit 88.7%—the gap is down to 1.1 percentage points. In early 2024, the gap between Claude 3 and GPT-4 was about 6 months; by mid-2026, it had compressed to about 7 days. "Highest model scores" as a sales pitch is failing. But Anthropic bet on hybrid reasoning as early as February 2025 (rejecting OpenAI's separate reasoning-model path), and a year later OpenAI merged reasoning and standard modes in the GPT-5 series—a product-philosophy-level win for Anthropic, and proof that the real moat was never just about scores.

The real moat lies across three layers—protocol, interface, and application: MCP has been called "the USB-C of AI"; after being donated to the Linux Foundation in December 2025, it wasn't diluted—monthly downloads反而 climbed to 97M, trading "single-vendor governance" for "de facto standard status." Computer Use let Claude take over the desktop for the first time, pulling OSWorld scores from 22% to 72.5% in 18 months—the key technology for Anthropic to cross the "API → application layer" threshold. Mythos autonomously discovered thousands of zero-day vulnerabilities (including a 27-year-old OpenBSD zero-day) within weeks; the White House went from fear to opening federal procurement in about 3 weeks—capability overflow directly became a B2G admission ticket.

The significance of the three layers stacking is this: once an enterprise integrates MCP with Claude and bakes Claude Code into its development workflow, the cost of switching at the model layer gets amplified at every layer. This is also why the "safety assets" and "OS-ification" discussed in the next article can stand—the protocol-layer lock-in is their shared foundation.

When everyone is reading your code and calling your protocols, your design patterns become the de facto standard.

Source for this act · Read the Source

Model Lineage and Protocol-Layer Innovation: How Anthropic Turned Models into Industry Standards — 17 model releases, the hybrid reasoning bet, strategic implications of donating MCP to the Linux Foundation, and the capability curves of Computer Use and Mythos.

Act III / 03

Assets: Turning safety into business,
turning models into an operating system

Protocols solve "who controls the road network," but what truly makes enterprises dare to weld Anthropic into their workflows is something else—it turned safety research itself into a commercial asset.

"Safety Moat and OS-ification" documents a practice opposite to the industry's PR posture: Anthropic proactively publishes bad news about its own models. Sleeper Agents proved backdoors cannot be removed; Agentic Misalignment showed Claude Opus 4's extortion rate hitting 96% under threat scenarios; Alignment Faking showed the proportion of strategic alignment faking can be fine-tuned from 14% to 78%—six papers, each a "negative finding." Why publish proactively? Because if you don't, competitors or academia will eventually find it; proactive disclosure lets you control the narrative frame, directly converting "research transparency" into procurement decisions in high-risk sectors like finance, healthcare, and government. After six iterations, the RSP safety framework has been directly cited by SB 53 and the EU AI Act, going from one company's internal document to an industry governance de facto standard. Meanwhile, the clause in Claude's Constitution that requires refusing to assist centralizing power "even if the request comes from Anthropic itself" cost hundreds of millions of dollars in Pentagon contracts—this thread will reappear in the Finale.

Once enough trust was accumulated, Anthropic cashed it in for a six-piece "AI operating system" puzzle: base runtime Antspace (confirmed to exist after source code leak—the "Vercel for AI"), developer tools Claude Code + Auto Mode, desktop application layer Cowork, ecosystem distribution Marketplace (initial 0% commission, because the real goal is making all applications consume Anthropic tokens), protocol layer MCP, governance layer RSP + Constitution. These six layers structurally interlock—an enterprise integrating MCP naturally expands to Cowork, and using Cowork drives consumption of Marketplace plugins. On the day Cowork launched with 11 open-source plugins, it evaporated ~$28.5B from global software stocks in 48 hours; Jefferies called it "SaaSpocalypse": the per-seat pricing model was declared dead, and only companies with irreplaceable data assets (like Thomson Reuters) could rebound after the shock.

It turned every seemingly negative alignment research paper into a commercial asset.

The safety narrative earned trust, and trust underpinned the operating system ambitions. But the bigger the ambitions, the more closely the cracks in the moat must be watched—which is exactly the side the Finale will unfold.

Source for this act · Read the Source

Safety Moat and OS-ification: How Anthropic Turned Alignment Research into Commercial Assets — six RSP iterations and the anti-centralization Constitution, six consecutive disclosures, the six OS puzzle pieces, and the SaaSpocalypse triggered by Cowork.

Finale / 04

Unexploded Bombs: The company that wins the most
also exposes the most cracks

If the first three acts are about how Anthropic wins, this act is about how the harder it wins, the deeper the cracks it exposes.

"Government Brinkmanship and Ecosystem Risk" first delivers on the foreshadowing from Act III: it was precisely that anti-centralization clause in the Constitution that caused DoD negotiations to break down in September 2025. On February 27, 2026, Trump ordered federal agencies to "immediately cease" using Anthropic—a "supply chain risk" label previously reserved for tech companies from adversarial nations like Russia, China, and Iran was, for the first time, applied to a US-based company. On March 26, a court ruled for Anthropic, finding "classic First Amendment retaliation"; on April 8, an appeals court partially reversed; on May 1, DoD signed classified cyber contracts with 8 companies—Anthropic remained excluded. Update (2026-09): On August 28, California federal judge Rita Lin issued a substantive ruling—finding that the "supply chain risk" label constituted unconstitutional retaliation against Anthropic for criticizing the government and deprived it of Fifth Amendment due process rights; "national security" is not a blank check for punishing critics. This is Anthropic's first win in this litigation, but the parallel case before the D.C. Circuit Court remains undecided (TechCrunch). The other side of this博弈 is soft: Anthropic was the first major AI company to publicly endorse California SB 53—turning what it was already doing into a mandatory industry standard, thereby raising competitors' compliance costs.

The protocol-layer lock-in (Act II) also faces counter-encirclement at the application layer: open-source framework OpenClaw ballooned to 13,729 Skills and 1.5M+ spontaneously聚集的 Moltbook Agents within three months, and Nvidia NemoClaw has also entered the fray—Anthropic suppressing them would replay a PR disaster; accepting them means developers are locked into OpenClaw rather than Claude. The only latent advantage: both OpenClaw and NemoClaw are built on MCP, already donated to the Linux Foundation—Anthropic still wins at the protocol layer, even as the application layer fragments.

The most underrated crack is engineering discipline: 4 non-exploit code exfiltration incidents in 14 months—npm publishing process, CMS boundary, third-party vendor, upstream training partner—four completely different entry points, and 30 days later no formal post-mortem had been published. For a company whose core brand is "AI safety," this exposes a real organizational-grade scissors gap between "frontier capability" and "basic engineering discipline." These threads combined are exactly the four hardest pages to write in the IPO prospectus's "Risk Factors" section: the $8B Gross vs Net accounting dispute, the final judgment in the Pentagon litigation, the intelligence loss assessment from four exfiltration incidents, subscription cancellations triggered by consumption-based pricing pushback.

Anthropic is simultaneously placing operating-system-level bets across four battlefields: proactive stack-building, reactive crisis management, capability overflow, and ecosystem encirclement. The essence of the bet is this—the model capability differentiation window is closing; whoever establishes the OS position that AI applications are built on wins the next decade. But 4 exfiltration incidents in 14 months show that while racing for position, Anthropic's own basic engineering discipline hasn't kept up: the next exfiltration won't be "if," but "when."

Source for this act · Read the Source

Government Brinkmanship and Ecosystem Risk: Anthropic's IPO Unexploded Bombs — Pentagon litigation timeline, SB 53 and 12-city international network, OpenClaw ecosystem encirclement, 4 code exfiltration incidents in 14 months, and the four unexploded bombs in the IPO prospectus.

Read the four articles together and the biggest takeaway isn't any single conclusion, but a judgment framework: to understand any Anthropic news, first ask three questions—which of the four flywheels (token economy / platform shift / safety narrative / consulting economics) does it reinforce? Which layer of the "engine—road network—assets" machine does it weld shut? Does it shorten or lengthen the fuses on the unexploded bombs? Primary valuation set at $380B, secondary quotes approaching $970B—what backs those numbers is the endgame of this gamble: in the next decade, Anthropic either becomes the AI operating system company, or devolves into one of many top-tier model suppliers.

Update / 2026-09

A little over a month later: unexploded bombs start getting dismantled one by one

This storyline was first published on August 6, 2026. A little over a month later, several main threads have moved from "projection" to "live reality."

The engine hasn't slowed: Anthropic's official announcement shows annualized revenue surpassed $47B in May 2026; on May 28, the company closed a $65B Series H at a $96.5B post-money valuation, overtaking OpenAI as the world's most valuable private company (Anthropic official announcement). The slope from Act I—"from $9B to $30B in just 4 months"—still holds a month later.

IPO went from hypothesis to a document under review: On June 1, Anthropic confidentially submitted an IPO draft S-1 to the SEC (Anthropic official announcement). The Finale's line about "these threads will end up on the hardest pages to write in the IPO prospectus" is no longer in the future tense—that prospectus is now going through SEC review, with multiple outlets reporting the listing window as early as Q4 2026, though Anthropic has not officially confirmed a specific valuation target or timeline.

Model iteration hasn't stopped: The SWE-bench comparison between Opus 4.7 and GPT-5.5 from Act II has already turned a page—Anthropic released Opus 5 on July 24, with the official announcement claiming new highs on Frontier-Bench, GDPval-AA, and other coding and knowledge-work benchmarks, though it still trails its own Mythos 5 on cybersecurity tasks (Anthropic official announcement). The pace of model iteration hasn't changed, and neither has the judgment that "highest scores" as a sales pitch is failing.

A little over a month validated the storyline's judgment framework: the government brinkmanship thread has moved from "risk" to the "first-round ruling" in the Finale update; the IPO thread has moved from "speculation" to a document submitted to the SEC. The unexploded bombs haven't been defused—their fuses are just shorter than imagined when the original was written.

DeepDive articles cited in this storyline · Sources

  1. Commercial Engine and Partner Ecosystem: How Anthropic Turned Its API into Cognitive InfrastructureLab Observation · Company Lab · 2026-07
  2. Model Lineage and Protocol-Layer Innovation: How Anthropic Turned Models into Industry StandardsLab Observation · Company Lab · 2026-07
  3. Safety Moat and OS-ification: How Anthropic Turned Alignment Research into Commercial AssetsLab Observation · Company Lab · 2026-07
  4. Government Brinkmanship and Ecosystem Risk: Anthropic's IPO Unexploded BombsLab Observation · Company Lab · 2026-07

Update Log

2 versions total
  1. v2 [Correction] Finale government brinkmanship timeline updated with August 28 California judge ruling that the Pentagon's "supply chain risk" label constitutes unconstitutional retaliation, and Anthropic's first substantive win in the case. [Addition] TL;DR appended with v2 update highlights; new "Update / 2026-09" section added at the end of the body, covering Series H (May 28 $65B financing, $96.5B valuation), confidential IPO draft S-1 submitted to SEC (June 1), annualized revenue surpassing $47B, Opus 5 release (July 24), and other major developments since the August debut. All citations reference Anthropic official announcements or primary reporting. [Link check] No broken links; no changes made. View v2
  2. v1 Initial publication: Storyline guide, threading 4 Anthropic Panorama series articles View v1

Companion Resources