Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
RSP version 3.3 revised the CB-2 capability threshold from a description focused on assisting 'moderately resourced expert-backed teams' to a more operationally specific definition requiring that a model could functionally substitute for world-leading specialist expertise in end-to-end novel biological or chemical weapons development. Anthropic characterizes this change as a clarification rather than a substantive revision.
This analysis describes what Anthropic's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
The revised CB-2 threshold introduces greater operational specificity into the definition of what constitutes a threshold-crossing capability, which affects how future model assessments are conducted and documented under the RSP. The document's characterization of the change as a 'clarification' rather than a revision means Anthropic applies prior system card arguments to the new threshold without re-running prior analyses.
Interpretive note: The document asserts the threshold change is a clarification and that prior arguments remain valid under the new definition, but this interpretive judgment is made unilaterally by Anthropic and may be assessed differently by external reviewers or regulators.
This provision governs how Anthropic determines whether a model requires additional safety measures under the RSP; it does not directly affect user terms or access, but it defines the internal governance standard applied to assess the safety of models users interact with.
Cross-platform context
See how other platforms handle RSP v3.3 CB-2 Threshold Clarification and similar clauses.
Compare across platforms →Monitoring
Anthropic has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"RSP v3.3 threshold: AI systems that can functionally substitute for the scarce human expertise that is currently the primary barrier to novel development of chemical and biological weapons with potential for catastrophic harm. That is, a well-resourced team could, using the model, accomplish the end-to-end agent design and deployment (including, as relevant, agent design, verification and validation, formulation, and dissemination) that would otherwise require recruiting one of a small number of world-leading specialists. We view this change as a clarification of the intent of our earlier threshold, and believe that the arguments given in past system cards for why a model didn't cross the threshold as previously defined would also work as arguments for why a model doesn't cross the threshold as now defined.Excerpt from Anthropic's Claude Opus 4.8 System Card
(1) REGULATORY LANDSCAPE: The CB-2 threshold definition engages AI safety governance frameworks and may be relevant to regulatory bodies assessing whether self-regulatory RSP commitments provide sufficient public protection, including the UK AI Security Institute and EU AI Act implementing authorities. The threshold's operational specificity (referencing 'end-to-end agent design and deployment' and 'hundreds' of world-leading specialists) may be reviewed by external auditors assessing RSP adequacy. (2) GOVERNANCE EXPOSURE: Medium. The document's assertion that the threshold change is a 'clarification' and that prior arguments remain valid under the new definition involves an interpretive judgment that external reviewers may evaluate differently. If the revised threshold is assessed as substantively narrower or broader than the prior definition, prior model determinations could require revisitation. (3) JURISDICTION FLAGS: Regulatory bodies in the EU, UK, and US with AI safety oversight mandates may independently assess whether the CB-2 threshold and its application to Opus 4.8 satisfy applicable public safety standards. The characterization of the change as a clarification rather than a policy revision may affect how regulatory bodies treat continuity of prior risk determinations. (4) CONTRACT AND VENDOR IMPLICATIONS: Organizations that contracted for Anthropic services under RSP v3.1 commitments should assess whether the v3.3 threshold change affects their understanding of the safety guarantees associated with their service agreements. The document does not indicate that contractual notice was provided to existing customers regarding the threshold revision. (5) COMPLIANCE CONSIDERATIONS: Compliance teams should document their independent assessment of the CB-2 threshold revision and its implications for their risk posture when deploying Opus 4.8 in life sciences, defense, or research contexts. Where regulatory filings or vendor risk assessments reference RSP version commitments, updates may be warranted to reflect the v3.3 threshold language.
The revised CB-2 threshold introduces greater operational specificity into the definition of what constitutes a threshold-crossing capability, which affects how future model assessments are conducted and documented under the RSP. The document's characterization of the change as a 'clarification' rather than a revision means Anthropic applies prior system card arguments to the new threshold without re-running prior analyses.
This provision governs how Anthropic determines whether a model requires additional safety measures under the RSP; it does not directly affect user terms or access, but it defines the internal governance standard applied to assess the safety of models users interact with.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Anthropic.