Microsoft and Meta Cut Claude Use Ahead of the Anthropic IPO

Picture of Spencer Thomason

Spencer Thomason

October 6, 2026

Copy Link
Microsoft and Meta Cut Claude Use Ahead of the Anthropic IPO

A sharp drop in Claude spending at Microsoft and Meta is landing just as Anthropic tries to sell its stock. Internal budgets are being cut, employees are being pushed onto in-house tools, and two of the largest token users in tech are turning the meter down. The timing sits next to an IPO prospectus, public warnings about model risk, and a research post that treats downloadable open-weight models as the danger.

Microsoft Cuts Claude Budgets and Pushes Copilot

One engineer in Microsoft’s Cloud and AI group had an AI budget of $100,000 a month. That group had a lot of people in it. Those budgets were cut, in most cases, from about $100,000 a month to about $10,000 a month. A big chunk of the money had been going to Anthropic’s Claude.

Microsoft had been on track to spend over a billion dollars a year on Anthropic. Bosses then told people to move to GitHub Copilot and other in-house tools, and Claude spending was cut by more than a third. Internal Claude use was cut by more than 33 percent, and Copilot was forced to auto-route.

Meta Halves Claude Code Use and Builds Its Own Tools

Earlier this year, about 60,000 Meta employees were using Claude Code and Anthropic’s coding agent. That number is now about 30,000. Some of the drop came from spring layoffs. The larger reason is that Meta built its own tools.

Muse Code already has over 6,000 employee users. An internal tool called Meta Code has over 30,000. Meta has been paying over $105 million for Claude Code in a single 28-day stretch. At that level of spend, building an internal tool is the obvious move, and employees are already being pushed toward Muse.

The IPO Prospectus and the Token Meter

Anthropic’s IPO prospectus came out last week. It says two customers the company will not name make up about 25 percent of revenue. Most of that revenue is pay-per-use tokens, and the identity of those customers is widely treated as settled. Two of the biggest token burners in tech are turning the meter down at the same moment Dario is trying to sell the stock.

Palantir and Nvidia already pulled back last month and said they are not using Claude anymore because of data fears. They also scaled back Claude Code over prices and data privacy fears. A post that circulated on X and other platforms this afternoon said Anthropic is getting hit. Last week, Jensen told Dario to stop scaring people. This week, the customers stopped paying.

The Scare Dial and the Revenue Target

The scare dial and the token meter are the same business. Dario tells the world the model is so powerful it is dangerous, and that message is what gets sold, including at multiples. Anthropic has been telling investors it would grow revenue sevenfold, from $9 billion to $65 billion. That path is now being cut down quickly.

The multiple itself is the striking part. If Meta were valued at the same revenue multiple Anthropic is targeting, Meta would be worth $12 trillion. The comparison follows from the case for a $2 trillion Anthropic IPO: apply that multiple to Meta’s revenue and the result is $12 trillion. Meta actually makes money and has been profitable for many years. Anthropic has not.

What Was Said at the White House

According to the Wall Street Journal, Nvidia CEO Jensen Huang and other tech executives and advisors privately questioned Dario Amodei at the White House about why he is so extreme in public on AI capabilities and risks. Amodei told them the industry needed to be honest with the public and should not play down the risks. Earlier at lunch, when Amodei raised safety concerns, Mark Zuckerberg told him the answer was for the industry to follow through on its new safety principles.

The private message around him was to knock it off. David Sacks described Amodei as the Dustin Hoffman figure among the tech CEOs in the room, with co-founder Tom Brown as the Tom Cruise character who translates for him. Sacks said he did not fully appreciate how unusual Amodei was until they were all in the room together, and he framed the remark as not meant as an insult. The room had a wide spectrum of views. The teasing ran from “spectrum” to the autism spectrum, to Sacks being called the Rain Man, to a line about America, China, and Russia meeting “my mutants” and an X-Men being formed. Behind the jokes, the point that traveled was the same: people in the room were telling Dario to stop.

The GLM 5.3 Post and Open Weights

Anthropic wrote a research post about a model that can be downloaded, focused on 5.3, and written to sound alarming. The post treats GLM 5.3 as an example of why models like it should not be on the market. The central objection is that the model can be downloaded.

GLM 5.3 built working exploits in 50 of 410 attempts. Mythos Preview got 56. Open weights were six exploits behind a model almost nobody is allowed to touch. Weeks spent inside a GLM 5.3 flash build included ranking all 12,000 experts, cutting most of them, and breaking the model. People remove the refusals. That is what having the weights means. The same access lets a defender run on his own code without sending that code to the model provider. On a closed model, people can ask for security holes in their own code to be patched and get a refusal. Closed models show up in real attacks.

Read that way, the post says open weights are the danger and limited access is the answer. The open question is who decides who gets access. Publishing how capable these models are also functions as an advertisement for GLM 5.3, and it shows how far Dario is from the practical case for wider access. The stated position is that the capability is dangerous and should not be open to the public. The counter is that defenders need the same capability.

Hugging Face, Refusals, and Who Is Attacking

When Hugging Face was attacked by OpenAI and tried to use an OpenAI model to defend itself, the model could not, because it refused. When Hugging Face switched to GLM 5.2, it was able to defend itself. Calling the open model dangerous is, on this account, an argument for having it available for defense. OpenAI has admitted to more than 10,000 attacks over the last couple of months. Without a model that will actually run the defensive work, there is no clear way to respond.

A shorter reading of the same article puts GLM 5.3 level with Mythos for exploit development, and unlike Claude, GLM 5.3 returns the results that were paid for. The implied policy is that government should ban models that are as good as Anthropic’s if Anthropic did not make them. The post also admits, in a self-reflective way, that the lack of guardrails can benefit a defender securing a system, which is the use Anthropic has not wanted to allow because of possible misuse. The irony drawn from the numbers is blunt: Anthropic felony hacks, 1,000; GLM 5.3 felony hacks, zero. OpenAI and Anthropic are the ones admitting they attack people, while arguing that open-weight models should be banned as too dangerous.

Hugging Face, Refusals, and Who Is Attacking

What the Customer Cuts and the Post Have in Common

As Anthropic nears its IPO, the use among its largest customers is being cut, and the company posts an attack on open-weight models. Anthropic does not want those models out. OpenAI does not want them out either. They destroy the business model.

The practical response offered here is to learn how to build an AI stack and how to use open-weight models. Warnings that 5.3 has advanced cyber capabilities are treated as a reason to learn the systems, not to avoid them. OpenMonoAgent.ai is described as a harness for building those systems, with tools including Startuphakk Security built on top of it. Startuphakk, led by Spencer Thomason, offers custom software work, and Startuphakk Security offers a free code scan and a free site scan at startuphakksecurity.com.

Thomason’s framing is that most companies do not have a technology problem. They have a leadership problem, paid for in missed deadlines, failed integrations, and AI investments that deliver nothing. He describes 25 years of building software and a decade of executive leadership at organizations including GoDaddy, SRP, and Wells Fargo. The businesses he says are winning are not the ones chasing the latest AI trends. They are the ones that built on solid engineering and treated AI as infrastructure they own, control, and integrate. The work he describes is database architecture, API design, system integration, and scalable infrastructure, with AI designed into the architecture and run in the customer’s environment rather than bolted on as a wrapper around someone else’s API and someone else’s pricing schedule. OpenMonoAgent.ai is described as a terminal-native AI coding agent running entirely on local models, with zero API costs, zero telemetry, and full ownership.

The customer cuts, the prospectus concentration, and the public risk message are now sitting in the same week. Whether that combination hits the IPO hard is the open question the cuts and the White House exchanges put in front of anyone watching the listing.

Share this post
Copy Link
Fractional CTO · AI Builds

Stop renting intelligence. Start owning it.

More to explore