Akamai and Anthropic signed a seven-year $11.6 billion CPU-focused cloud deal, with a warrant giving Anthropic up to about 5% of Akamai.
Cloud services and cybersecurity company Akamai announced that it has expanded its partnership with Anthropic, which will purchase a total of $11.6 billion in cloud computing services over the next seven years to support continued growth in CPU workload demand; if the partnership expands further, the total could rise to as much as about $20 billion. Akamai’s share price jumped sharply after hours, and the market clearly viewed this as an important milestone in its cloud business transformation.Source information also indicates that this is the largest contract in Akamai’s history.[1][2]
More notably, this deal is not just a compute purchase but also includes an equity arrangement. Akamai issued Anthropic a warrant that allows it to buy non-voting Series B preferred stock convertible into Akamai common shares at $111.33 per share, equivalent to about 5% of the outstanding common stock; about 2% vests with this purchase commitment, while the remaining 3% is tied to future purchase volume.[1][2]
This partnership highlights a shift in the demand structure for AI infrastructure. The report makes clear that as AI moves from chatbots to agentic systems that can autonomously execute tasks, computing demand is no longer centered only on GPU training and inference, but also includes CPU-intensive work such as tool calls, code execution, and file handling. Akamai also said that as much as 90% of an AI agent’s execution time may be spent on non-GPU work, meaning the bottleneck in AI systems is shifting from single-accelerator compute to broader general-purpose computing and workflow orchestration.[1][2]
From an architectural perspective, the value of Akamai Cloud is not isolated compute power, but its distributed cloud infrastructure. Akamai was originally known for CDN and cybersecurity services, then entered cloud computing through the acquisition of Linode, and later used its existing global network infrastructure to connect core data centers and edge nodes into a distributed cloud platform. This design is especially well suited for AI agent workflows that require low latency, broad geographic distribution, and extensive state changes and interaction with external tools.[1][2]
From a security and risk governance standpoint, the increase in these CPU workloads means the attack surface will expand from the model itself to the execution environment, file handling, toolchains, and permission boundaries. When AI agents can execute code and manipulate files, the absence of least privilege, sandbox isolation, and input validation can amplify prompt injection, malicious files, privilege misuse, and supply chain contamination into systemic incidents. Although the source does not mention any specific vulnerability or CVE, the workload pattern described is sufficient to show that security controls must extend from model governance to execution-layer governance.[1][2]
In addition, the equity-linked commercial structure deserves attention. When the customer is both a source of capital and an asset holder, the line between cloud supply, capital markets, and business growth becomes blurred, making it harder for the market to interpret true demand using traditional revenue models. The source notes that some Wall Street investors have concerns about circular transactions in the AI industry, because companies buying from one another and investing in one another may inflate the appearance of demand without necessarily producing the same scale of sustainable cash flow.[1]
For Akamai, this contract not only strengthens the growth narrative of its cloud business, but also positions the market to view it less as a traditional CDN and cybersecurity provider and more as an AI infrastructure supplier. If cloud revenue continues to expand as management says, it may eventually surpass other businesses, creating a structural shift in Akamai’s corporate positioning.[1]
For Anthropic, this means it is no longer relying on a single type of compute resource and is beginning to incorporate CPU into its core AI infrastructure strategy. This is especially important for AI agent products, internal tool orchestration, post-processing, and workflow automation, because these functions often depend more heavily on general-purpose compute and distributed coordination than on model inference itself.[1][2]
For the broader AI supply chain, this case may become a template for future partnerships between major AI companies and infrastructure providers: long-term contracts, expansion clauses, warrants, and a linkage between cloud services and capital. This model helps lock in supply and spread expansion risk, but it may also make it harder for outsiders to assess true demand and the long-term cost structure.[1]
For security teams, distributed cloud and AI agent scenarios like this will require stronger governance, including identity and access management, workload isolation, log observability, data minimization, and consistent control across multi-region deployments. Because the source does not provide specific product or version details, any practical risk assessment should return to the architectural layer rather than assuming a single vulnerability can explain all risk.[1][2]
First, separate AI agent tool execution from model inference so that external inputs, code execution, and sensitive data access are not all handled within the same permission domain. This reduces the likelihood that a single prompt or file event will spread into a full-scale compromise.[1][2]
Second, establish clear quotas, sandboxes, and outbound network controls for CPU-intensive workloads, especially processes that handle files, scripts, and external API calls. The source already indicates that most AI agent execution time may occur outside GPU work, and these processes are exactly where attackers are most likely to gain a foothold.[1][2]
Third, enforce least privilege and fine-grained authorization by separating tool calls, file read/write access, code execution, and credential access, and require human review or secondary confirmation for high-risk actions. For distributed platforms that must execute across nodes, unified identity governance and short-lived credentials are especially important.[1]
Fourth, monitor supply chain and commercial risk in parallel. When cloud purchasing, equity arrangements, and operational cooperation are intertwined, companies should look beyond SLAs and performance and also track partnership concentration, financial dependence, and exit mechanisms to avoid cascading shocks if either the technical or commercial side changes.[1]
Fifth, create a traceable audit chain for AI agent outputs and behavior, including prompts, tool parameters, execution results, and file change logs. Only by fully aligning what the model did with what the system actually executed can organizations quickly assign responsibility and define remediation scope after an incident.[1][2]
5-Step Remediation Checklist