Zendoric
← Back to the day · September 2, 2026

Anthropic's $40B bill to Musk shows compute, not cleverness, is the real chokepoint in frontier AI

🕒 Published on Zendoric: September 2, 2026 · 08:27

✨ AI-generated · how it's made

Anthropic has agreed to pay roughly $1.25 billion a month through May 2029 — more than $40 billion — for exclusive access to Colossus 1, the Memphis data centre built by Elon Musk's companies. Reports describe a clause letting SpaceX reclaim the compute if Anthropic's models are found to harm humanity, though neither company has jointly confirmed the wording. Our thesis: the headline is the rivalry, but the substance is that safety commitments are migrating from corporate governance into supply contracts.

The deal, as reported: Anthropic pays xAI/SpaceX about $1.25 billion a month through May 2029 for full access to Colossus 1, the Memphis facility Musk's companies built for AI training. That is more than $40 billion over the term, in exchange for the site's entire capacity — over 220,000 Nvidia processors drawing 300 megawatts, roughly the continuous draw of a mid-sized city's worth of homes. Musk's xAI keeps the larger Colossus 2 for training Grok, so Anthropic is not queuing behind a competitor's jobs; it has exclusive use of a separate and still enormous plant. The effect on products is already visible: Anthropic says the added compute let it double Claude Code's usage limits and lift peak-hour caps for paying customers.

The clause is what the industry is actually talking about. Multiple reports describe a provision allowing SpaceX to reclaim the compute if Anthropic's models are found to engage in actions that harm humanity. We should be precise here, because precision is the whole point: the exact contractual wording and status have not been jointly confirmed by either company. It is widely reported, not verified. Treat it as a claim about the deal, not a fact of the deal.

Even as a reported term, it deserves scrutiny rather than applause. "Harms humanity" is not a standard anyone can adjudicate — it names no threshold, no evidentiary bar and, crucially, no neutral arbiter. A safety condition whose trigger is defined by the counterparty is not a safety mechanism; it is leverage with a moral vocabulary. And the counterparty here is a competitor: Musk has previously called Anthropic "woke," "misanthropic" and "evil," then said after the deal closed that "everyone I met was highly competent and cared a great deal about doing the right thing" and that "no one set off my evil detector." Warm words are not a governance framework. If the clause exists as described, the interesting question is not whether Musk would ever pull the plug over model behaviour, but that a rival now holds a plausible pretext to interrupt a competitor's most expensive input.

Strip the personalities away and the economics are unremarkable, which is the real signal. Frontier labs are compute-constrained across the board, and building 300MW of your own capacity takes years of permits, transformers and grid interconnects that no amount of capital compresses to months. Renting a finished plant from whoever has one — including someone who has insulted you in public — is straightforward infrastructure maths. That inverts the popular story about this industry. The scarce asset is not model architecture or research talent; it is energised, cooled, GPU-filled buildings. Anthropic's identity is built on being the safety-first lab, and it now depends on a rival's real estate to keep serving customers. That is not hypocrisy. It is what a supply bottleneck looks like when it becomes strategic.

Our reading: this is a preview of how AI will actually be governed, and it should make everyone slightly uncomfortable. We have argued that export controls turned a model into a geopolitical asset; this turns a data centre into a governance instrument. Conditions on model behaviour are migrating out of boards, charters and regulators and into commercial leases, where they are negotiated privately, enforced unilaterally and disclosed only when they leak. That is a bad substitute for evidence-based public governance — no appeal, no defined standard, no transparency — and it is the same failure mode we have flagged in automated decisions elsewhere: the problem is not the verdict, it is the absence of due process around it. If safety commitments are going to be contractually enforceable, the terms and the arbiter should be public.

The long view is still the optimistic one, with the caveat attached. Compute at this scale is what makes the genuinely civilisational work possible — protein and disease modelling, materials, drug candidates screened by the million. Concentration in a handful of privately controlled megasites is a fragile way to get there, and the antidote is boring rather than dramatic: more suppliers, more geographies, more open-weight models that run outside anyone's exclusive lease, and public disclosure when infrastructure contracts carry behavioural conditions. Watch for one specific thing over the next quarters — whether either company formalises or denies this clause. Whichever way it goes, it sets the template for every compute contract signed after it.

🔗 Related on Zendoric

Sources & references