Anthropic's Advanced AI Framework
Published June 2026
Not law. This is a company's own public position on AI regulation. It is not law, and it carries no legal force.
What it argues for
Anthropic argues that voluntary transparency is no longer sufficient for frontier AI and that governments should impose binding obligations on the largest frontier developers, backed by an agency with real power. Part 1 sets out developer obligations: a narrow scope (models above 10^25 training FLOP, built by companies with over $500M in annual AI-derived revenue or over $1B per year in AI R&D spend), covering four enumerated catastrophic risks — biological weapons, offensive cyber operations, loss of control, and automated AI R&D. Covered developers would have to publish a safety framework, system cards and six-monthly risk reports, certify compliance annually, report Critical Safety Incidents to a designated Agency within 15 days, engage at least one qualified independent evaluator, and secure model weights and the training environment. Crucially, it goes beyond disclosure: the framework asks for legal authority to block or deter deployment of models posing significant catastrophic risk, with civil penalties that escalate on repeat violations and scale to global annual revenue — while proposing explicit anti-overreach safeguards (court enforcement rather than direct agency remedies, cabined discretion, expedited judicial review). On US federalism it takes a firm line: Congress should not preempt state AI law unless it enacts a regime at least as strong as this framework, and any preemption should be narrow and confer no safe harbour. Part 2 turns to societal resilience — gene-synthesis screening and biosurveillance, hardening internet software and critical infrastructure, and government capacity to track frontier cyber capability — on the grounds that a biological or cyber attack should be harder to carry out and easier to recover from wherever the capability originates.
Stated positions (16)
- Scope is deliberately narrow: obligations apply only to a "Covered Developer" that both trains models requiring more than 10^25 FLOP and earns over $500M in annual AI-derived revenue or spends over $1B per year on AI R&D (page 3).
- Four "Enumerated Risk" categories only: biological weapons, offensive cyber operations, loss of control of AI systems, and automated research and development that could amplify the other three.
- Mandatory publication: a safety framework naming the accountable corporate officer, a system card whenever a materially more capable covered model is deployed, and a risk report at least every six months covering internal as well as external deployments.
- Annual certification of compliance with the safety framework to a designated government Agency, with civil penalties for material misrepresentation.
- Critical Safety Incidents (weight exfiltration, materialised catastrophic harm, loss of control causing injury, a model deceptively subverting its developer's controls) must be reported to the Agency within 15 days, with the reports exempt from public-records disclosure.
- At least one qualified independent evaluator must review the developer's risk assessments within six months of enactment; governments and industry should build that ecosystem through evaluator standards, possible licensing, funding and sufficient model access.
- Security obligations on model weights and the whole training environment, including insider threat, a public high-level description of the programme, details to the Agency on request, a channel to report model distillation attacks, and regular self-testing.
- Enforcement with teeth: prohibit intentionally false or materially misleading safety statements, and authorise civil penalties that escalate with repeated violations and scale with global annual revenue.
- Government should be able to block or deter deployment — remedies include fines, prohibitions on deploying further covered models until violations are corrected, and in extreme cases restrictions on already-deployed models.
- Explicit anti-overreach design: the Agency should act through the courts rather than impose remedies directly, its discretion should be cabined to enumerated violations rather than its own risk judgement, and developers should get expedited judicial review.
- Whistleblower protections: anonymous internal reporting channels, a ban on retaliation, and a ban on contractual restrictions on good-faith reporting.
- On US preemption: Congress should not preempt state law unless it enacts a federal regime at least as strong as this framework; preemption should be surgical, construed narrowly, and federal compliance should confer no immunity, safe harbour or presumption against liability under state law.
- Societal resilience on biology: gene synthesis screening, early-warning biosurveillance for novel outbreaks, and preparedness measures such as PPE stockpiles and suppressing airborne transmission.
- Societal resilience on cyber: harden the software the internet runs on, fund the national cybersecurity agency to handle 10-100x current disclosure volume with sub-seven-day turnaround, binding patch-deployment cadence for critical infrastructure operators, an end-of-life/legacy replacement programme, and a strategic reserve of operational-technology hardware.
- Candid about gaps: the resilience agenda for loss-of-control and automated R&D is "less mature"; promising directions are detecting and responding to AI systems acting outside developers' control, and infrastructure for containing or shutting them down.
- Framed as a US federal proposal, with an explicit invitation to other jurisdictions to tailor it to their own capacity and authority.
About this document
A 19-page PDF published by Anthropic in June 2026 (file created 9 June, typeset in InDesign) and released alongside a companion Economic Policy Framework and Dario Amodei's essay "Policy on the AI Exponential". It carries no named author, no signature and no appendix or reference list, and is written throughout in the corporate first person. The opening page says it is "written primarily with the US federal government in mind" and invites other jurisdictions to tailor it; page 2 concedes the authors are "more confident about some parts of this framework than others". The body is in two parts. Part 1, "Frontier developer obligations" (pp. 3–12), has five sections — scope, transparency, independent evaluation, security, and enforcement and regulatory authority — each closing with a boxed list of "RECOMMENDED … PROVISIONS" drafted in near-statutory language. It defines a Covered Developer (above 10^25 training FLOP and either $500m AI revenue or $1bn annual AI R&D spend), Catastrophic Risk, Critical Safety Incident, and four Enumerated Risk categories: biological weapons, offensive cyber, loss of control, automated R&D. Part 2, "Societal resilience measures" (pp. 13–19), catalogues biological and cyber preparedness under prevention, detection and response headings, then concedes the loss-of-control agenda is immature. Two footnotes and a one-paragraph conclusion close it. Notably, almost nothing in the document is a commitment about Anthropic's own conduct; it is a set of asks addressed to legislators.
How this sits against AI law
Each stance compared with what EU and US instruments actually require. Where no instrument addresses a theme, that gap is shown rather than hidden.
Who counts as a covered frontier developer
Obligations should attach only to developers training above 10^25 FLOP that also earn over $500m in AI revenue or spend over $1bn a year on AI R&D, and only for four enumerated catastrophic risks. Everything below that perimeter stays unregulated.
Article 51(2) presumes systemic risk at the same 10^25 FLOP figure but attaches no revenue or spending test, and sits inside a regime that also bans certain practices and regulates high-risk uses regardless of developer size.
SB 53 sets its frontier-model trigger ten times higher at 10^26 FLOP with the same $500m revenue test for large developers, so Anthropic's proposed perimeter would capture more companies than California's law does.
Publishing a safety framework and evaluation results
Covered developers should publish a safety framework, a system card whenever a materially more capable model is deployed, and a risk report at least every six months, and certify compliance annually to a government agency with penalties for misrepresentation.
Article 55(1) makes adversarial testing and systemic-risk assessment binding, but the resulting documentation goes to the AI Office and national authorities rather than the public — the only mandatory publication is a summary of training content.
SB 53 already requires large frontier developers to publish a frontier AI framework and a transparency report at or before deployment, the template this section follows, though it has no six-monthly risk report or annual certification.
Mandatory independent third-party evaluation
Within six months of enactment, covered developers should have to engage at least one qualified independent evaluator with access to unredacted risk reports and the most capable models, free to publish its own assessment; governments should license, rate and possibly randomly assign evaluators.
The AI Act requires providers to evaluate their own models and lets the AI Office conduct evaluations and appoint independent experts under Article 92, but it nowhere obliges a provider to retain an external evaluator.
Illinois is the only US jurisdiction to mandate third-party review at all — an annual independent audit of framework compliance from 1 January 2028 — which is narrower than an evaluator given model access and the right to publish disagreement on risk.
Mandatory incident reporting to government
Critical safety incidents — including weight exfiltration and a model using deception against its developer to subvert controls — should be reported to a designated agency within 15 days, with the reports exempt from public records disclosure.
Article 55(1)(c) requires providers of systemic-risk models to report serious incidents to the AI Office without undue delay, and Article 73 sets a 15-day outer limit for high-risk systems, tightened to 10 days for a death and 2 days for critical-infrastructure disruption.
SB 53 imposes the same 15-day deadline for reporting critical safety incidents to California's Office of Emergency Services, but adds a 24-hour track where there is imminent risk of death or serious injury that Anthropic's framework does not propose.
Security standards protecting model weights
Covered developers should maintain a security program spanning weights, training and inference infrastructure and insider threat, describe it publicly, give the agency detail on request, run regular red teaming and penetration testing, and report model extraction and distillation attacks.
Article 55(1)(d) makes an adequate level of cybersecurity protection for the model and its physical infrastructure a binding obligation for systemic-risk models, though it prescribes no testing, disclosure or attack-reporting regime.
SB 53 requires a large frontier developer's published framework to describe cybersecurity practices securing unreleased model weights against unauthorised modification or transfer by internal or external parties, but mandates no penetration testing and no reporting of extraction attempts.
Government authority to block or restrict a deployment
There should ultimately be a way to block or deter deployment of models posing significant catastrophic risk — fines, prohibition of further deployment, and in extreme cases restricting access to already-deployed models — bounded by court enforcement, cabined discretion and expedited judicial review.
Article 93 already empowers the Commission to require mitigation measures or to restrict the making available on the market, withdraw or recall a general-purpose AI model, backed by fines of up to 3% of worldwide annual turnover or EUR 15 million under Article 101.
Executive Order 14179 revoked Executive Order 14110 and directs agencies to suspend, revise or rescind actions that obstruct a policy of sustaining American AI dominance; it creates no federal power to test, restrict or block a model.
Federal preemption of state AI law
Congress should not preempt state law unless it enacts a federal regime meeting or exceeding the strongest measures in this framework, and even then only narrowly, with ambiguity resolved in favour of state authority and no safe harbour or immunity from state claims.
The question does not arise in the same form in EU law: the AI Act is a directly applicable Regulation setting one set of rules across all Member States, so there is no subnational frontier-AI regime for it to displace.
America's AI Action Plan directs OMB to have agencies weigh a state's AI regulatory climate and limit AI-related discretionary funding where a state's regime may hinder it, and tasks the FCC with evaluating whether state AI rules interfere with its authorities.
Societal resilience against biological and cyber threats
Governments should invest now in gene-synthesis screening, pathogen-agnostic biosurveillance, stockpiles and microbial forensics, and in open-source software security, patching at scale and legacy-system replacement — measures worth making regardless of how AI develops.
The AI Act regulates AI models and systems only; nothing in it addresses gene-synthesis screening, biosurveillance, medical countermeasure stockpiles or critical-infrastructure hardening.
America's AI Action Plan likewise calls for requiring federally funded institutions to use nucleic acid synthesis providers with robust sequence screening and customer verification, with real enforcement rather than voluntary attestation, and for mature federal AI incident response.
Anthropic is largely asking the United States for what the EU already imposes on it. Almost every Part 1 obligation — systemic-risk evaluation, incident reporting on a 15-day clock, model-weight security, and a regulator able to restrict, withdraw or recall a model — is already binding in Europe under the AI Act, and the framework's real departures from Brussels are to publish more and to draw the perimeter narrower than the Act's. Against Washington the gap runs the other way: federal policy under Executive Order 14179 and America's AI Action Plan is deregulatory and treats state AI laws as an obstacle to funding, so the framework's closest counterparts are California, New York and Illinois — which is why it devotes a full page to arguing that Congress should not preempt them.
Source
https://www-cdn.anthropic.com/files/4zrzovbb/website/0a58d567024a8b448ff15158ebc3625328dfcc1f.pdf- Date on the page:
- June 2026
- Source checked:
- opened and confirmed on 2026-09-18