Trustworthy AI: How Investors Should Assess Key Risks Around the Anthropic and OpenAI IPOs
With the two big AI labs gearing up to sell stock, these six metrics provide a framework for evaluating the very real risks at these companies.

- Ahead of likely IPOs, recent episodes are highlighting safety concerns around AI models from Anthropic and OpenAI.
- Investors evaluating AI companies should monitor enterprise retention, governance oversight, incident disclosure, regulatory engagement, and compute transparency.
- These signals may indicate whether these companies’ AI-related trust risks are improving or worsening before they show up in financial results.
Investors in upcoming IPOs from Anthropic and OpenAI will need to pay close attention to a range of risks that could significantly affect shareholder value. A framework we’ve developed at Morningstar Sustainalytics, called Trustworthy AI, can help investors identify those risks. It’s an approach to artificial intelligence development that prioritizes safety and transparency—along with traditional environmental, social, and governance analysis.
Two incidents—Anthropic’s July release of its flagship AI model, Fable 5, and the June breach of Hugging Face by OpenAI AI models—show how safety and governance events can affect a company’s risk even before it’s reflected in traditional financial metrics. Investors should also ask whether governance, safety, and regulatory preparedness will affect enterprise adoption, alongside price, performance, and distribution.
Anthropic’s Fable 5 Incident
In June, just after launching its flagship reasoning model, Fable 5, Anthropic was forced by a US Department of Commerce directive to suspend access for all foreign nationals. Unable to verify user nationality in real time, Anthropic took both Fable 5 and Mythos 5 (a restricted access model) offline globally to comply with the directive and avoid potential regulatory penalties.
The Fable 5 incident turned Anthropic’s safety commitments into a financial risk. Safety commitments and contested-use boundaries suddenly affected product availability, customer continuity, and regulatory compatibility. In the 24 hours following the global pullback, Anthropic’s implied value fell 3.7% on secondary markets, and media questioned whether its IPO timeline would hold.
The incident demonstrated that a federal directive could remove a company’s core revenue-generating product overnight. Enterprise customers in finance, healthcare, and critical infrastructure lost production tooling with no warning, and rivals such as OpenAI and Chinese models such as GLM-5.2 gained traction during the outage.
On June 30, after negotiations with Anthropic, the government lifted controls. In exchange, Anthropic agreed to proactively detect and address security risks, work with the government on test protocols and release standards for future models, and report any malicious activity. In addition, Anthropic, Amazon, Microsoft, and Google agreed to establish a shared framework for scoring model security breaches. With the regulatory overhang resolved and a compliance playbook established, Anthropic’s secondary market trading implied valuation rose to a record high by July 9.
The key takeaway is that Anthropic’s safety and governance commitments became financially material through three channels at once: Regulatory intervention risk, revenue-durability risk, and regulatory-readiness signal. The company’s negotiated return to market demonstrated its ability to work with regulators and restore customer access following a significant disruption. For investors, the incident tested the company’s regulatory readiness and governance capabilities.
OpenAI’s Hugging Face Incident
In July, OpenAI disclosed that during an evaluation, its own models autonomously escaped a restricted test environment, chained together vulnerabilities, and compromised the open-source platform Hugging Face. OpenAI paused training and worked with external advisors. OpenAI CEO Sam Altman called it the first security incident he had felt “very viscerally,” and he suggested the industry may need to “pace the rate of AI development.” The incident fed directly into legislative momentum, including a proposed “AI Kill Switch Act.”
Both the Fable 5 and the Hugging Face incidents show a similar trust mechanism at work, testing Anthropic’s regulatory preparedness and OpenAI’s containment. Tellingly, Hugging Face first tried Anthropic’s Fable 5 to counter the attack, but its guardrails could not tell a defender from an attacker—revealing how safety controls not only reduce risk but also carry operational costs.
Environmental Stewardship Risks
Environmental stewardship is the least disclosed data at both firms. Neither company publicly discloses a comprehensive emissions inventory, nor do they report electricity consumption or water use data. This limits investors’ ability to assess environmental performance or resource efficiency. Both firms are also exposed to longer-term questions about data center expansion, electricity demand, water use, and local infrastructure impacts—none of which is fully disclosed.
How Trustworthy AI Works
Stronger trust and governance practices reduce a firm’s exposure to litigation, regulatory, key-person, and reputational risk. These risks are financially material, and Morningstar Sustainalytics treats them as exposure. We identify where trust increases or decreases a firm’s risk. Risks for these two companies surface through two channels:
- Upside risk: enterprise adoption, retention, expansion
- Downside risk: litigation, regulatory, governance, and key-person exposure
Markets appear to recognize the upside to trust more readily than the downside from governance, regulatory, and compliance risks. Where fundamentals are comparable, firms that demonstrate stronger governance, safety controls, transparency, and regulatory preparedness may carry lower downside risk. Operationally, we expect markets to anchor on four measurable drivers:
- Enterprise revenue quality
- Governance stability
- Regulatory compatibility
- Compute cost transparency.
Putting it together, we draw on established AI governance frameworks to organize the discussion around six dimensions of Trustworthy AI that investors can monitor:
Six Investor Signals of Trustworthy AI
Markets May Be Underestimating AI Risks
The incidents discussed above show that trust-related risks have already surfaced for investors. The question is whether investors aren’t fully accounting for them because such risks aren’t yet visible in revenue, margin, or adoption metrics. Some investors may already be incorporating Trustworthy AI considerations through measures such as enterprise adoption, retention, and efficiency. The IPO process and future public disclosures will also make governance, regulatory, and compliance risks more transparent.
Anthropic and OpenAI provide an early test of this dynamic, but the same questions are likely to become increasingly relevant across the broader AI sector as more companies approach public markets.
The author or authors do not own shares in any securities mentioned in this article. Find out about Morningstar’s editorial policies.
