What is this document
106-page report published by Anthropic to implement the third version of its Responsible Scaling Policy (RSP). This is the first report of its kind—the company plans to update it every 3–6 months. Unlike a system card, which is released with each model and describes the properties of a single model, this report assesses the entire organization’s operations: not only model capabilities, but also security controls, monitoring, deployment safeguards, and overall residual risk.
The document examines four categories of catastrophic risk: production of novel chemical or biological weapons, development of novel CB weapons, high-risk sabotage potential, and automated AI R&D acceleration. For each scenario, a threat model is provided, relevant models (mostly Claude Opus 4.6), an assessment of existing capabilities, applied measures, and a final risk verdict.
Findings: three of the four categories are rated as “very low” risk, while the novel CB weapons category is rated “low, but with significant uncertainty.” The most candid section of the report is the chapter on acceleration dynamics, which acknowledges that even with low direct risk, the company may indirectly accelerate competitors who do not implement such safeguards. There is also one fully redacted appendix (7.7).
Structural similarity to EU regulatory logic
Most interestingly, this non-regulatory document mirrors nearly all the structural elements of EU cyber and digital regulation.
Tiered thresholds. Anthropic’s ASL-2 / ASL-3 thresholds operate in the same way as DORA’s “critical third-country ICT service providers” (CTPP) status, MiCA’s “significant” ART/EMT issuer threshold, CRA’s Annex I classes of important and critical products, or AI Act Article 51’s systemic-risk GPAI models. The logic is consistent: cross a capability or scale threshold—face a heavier package of obligations.
Scenario-based testing. Anthropic’s “threat models” methodology closely resembles DORA Article 26’s threat-led penetration testing (TLPT / TIBER-EU) and CRA’s required risk analysis throughout the product lifecycle. The difference is that TLPT is conducted by independent external testers under a scope approved by the supervisory authority.
Internal control environment. The report describes measures such as mandatory manual code review before merging into shared repositories, automated screening of at least 10% of Claude Code requests for classifier monitoring, sandboxing, egress traffic restrictions to protect model weights, and a bug bounty program. These are essentially secure software development lifecycle (SSDLC) and internal threat management controls, which CRA refers to as “vulnerability handling” requirements, and ISO 27001 as Group A.8 controls.
Residual and absolute risk. Here Anthropic offers something regulation does not: separate assessment of how much risk is added by the company’s own systems, and how much risk would arise if the entire industry behaved the same way. EU law assesses the subject in isolation; systemic sectoral risk assessment is left to supervisory authorities. This dual perspective is methodologically valuable and deserves attention in GRC practice.
Where the similarity ends: three gaps
First — lack of independent validation. The report is a self-assessment. Only a pilot METR external review is mentioned, after which a few phrasings about internal employee surveys were refined. Compare this to CRA, which requires third-party conformity assessment for critical products via a notified body; DORA requires independent IRT risk management system review and internal audit; MiCA requires a license from the national competent authority before commencing operations. AI Act Article 55 imposes adversarial testing and documentation submission to the AI Office for systemic-risk GPAI providers, but not a mandatory independent audit.
Second — asymmetry in incident reporting. External users receive no monitoring for sabotage—reliance is placed on voluntary reporting. In the regulated world, this is untenable: DORA sets tiered reporting for significant IRT incidents (initial, interim, final), NIS2 requires 24-hour early warning and 72-hour reporting, CRA from 11 September 2026 obliges manufacturers to report actively exploited vulnerabilities to ENISA and CSIRT within 24 hours, and AI Act Article 73 requires reporting of serious incidents.
Third — redacted appendix. The transparency boundary where commercial secrecy meets the public interest. EU law resolves this tension not through secrecy, but through confidential access for the supervisory authority.
United Kingdom
The UK consciously lacks a horizontal AI statute. Instead, it relies on a principles-based, sectoral regulator system (FCA, PRA, ICO, Ofcom), the FCA/PRA operational resilience regime with important business services and impact tolerances, the Critical Third Parties regime under FSMA 2023, and the role of the AI Security Institute. In such a system, a voluntarily published vendor risk report carries greater weight—it effectively fills a regulatory void. At the same time, it is the sole source of evidence, which is not a sustainable position from a financial sector risk management perspective.
Lithuania
Three practical angles.
Financial sector. Lithuania has an disproportionately large number of EMIs and PIUs, so DORA is felt more strongly here than in many Member States. If such an institution uses Claude or any other foundation model, the vendor enters the third-country ICT service provider register and is subject to 28–30 contractual requirements—exit strategies, audit rights, subcontracting chain, data location. The Anthropic risk report is useful as evidentiary material in the vendor’s documentation, but it does not replace contractual guarantees or your own risk assessment.
Crypto-asset service providers. MiCA-licensed CASPs under Bank of Lithuania supervision also fall within the scope of DORA. AI use for market abuse or AML monitoring creates a dual layer of obligations: MiCA requires resilient and appropriate systems, DORA requires IRT risk management, and AI Act requires transparency under Article 50.
AI Act timeline. On 24 July 2026, the Digital Omnibus on AI (Regulation (EU) 2026/1744) was published in the Official Journal, entering into force on 27 July. High-risk system obligations under Annex III are deferred until 2 December 2027, and Annex I obligations until 2 August 2028. However, transparency requirements under Article 50 apply from 2 August 2026, and GPAI obligations (Articles 51–55) have been in force since August 2025 and remain unchanged. The deferral is not a pause—inventory and classification work will not become easier.
What to do with this
Practical takeaway for the GRC function: treat such vendor risk reports as a source of evidence, not as assurance. Specifically—map the report’s statements to your control library (which controls it actually confirms versus which it merely declares), record the three gaps identified above as residual risk in the vendor profile, and compensate for them contractually—audit rights, incident reporting timelines, subcontractor transparency.
One final note. The report shows what mature risk assessment looks like where regulation is absent: clear threat models, identified control boundaries, and acknowledged uncertainty. Many regulated firms subject to mandatory DORA or NIS2 requirements do not have such a document about themselves.
Analysis based on Anthropic “Risk Report: February 2026” (edition 2026-07-08).



