RSP version 3.3 revised the CB-2 capability threshold from a description focused on assisting 'moderately resourced expert-backed teams' to a more operationally specific definition requiring that a model could functionally substitute for world-leading specialist expertise in end-to-end novel biological or chemical weapons development. Anthropic characterizes this change as a clarification rather than a substantive revision.
This analysis describes what Anthropic's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
The revised CB-2 threshold introduces greater operational specificity into the definition of what constitutes a threshold-crossing capability, which affects how future model assessments are conducted and documented under the RSP. The document's characterization of the change as a 'clarification' rather than a revision means Anthropic applies prior system card arguments to the new threshold without re-running prior analyses.
Interpretive note: The document asserts the threshold change is a clarification and that prior arguments remain valid under the new definition, but this interpretive judgment is made unilaterally by Anthropic and may be assessed differently by external reviewers or regulators.
This provision governs how Anthropic determines whether a model requires additional safety measures under the RSP; it does not directly affect user terms or access, but it defines the internal governance standard applied to assess the safety of models users interact with.
Cross-platform context
See how other platforms handle RSP v3.3 CB-2 Threshold Clarification and similar clauses.
Compare across platforms →"RSP v3.3 threshold: AI systems that can functionally substitute for the scarce human expertise that is currently the primary barrier to novel development of chemical and biological weapons with potential for catastrophic harm. That is, a well-resourced team could, using the model, accomplish the end-to-end agent design and deployment (including, as relevant, agent design, verification and validation, formulation, and dissemination) that would otherwise require recruiting one of a small number of world-leading specialists. We view this change as a clarification of the intent of our earlier threshold, and believe that the arguments given in past system cards for why a model didn't cross the threshold as previously defined would also work as arguments for why a model doesn't cross the threshold as now defined.Excerpt from Anthropic's Claude Opus 4.8 System Card
(1) REGULATORY LANDSCAPE: The CB-2 threshold definition engages AI safety governance frameworks and may be relevant to regulatory bodies assessing whether self-regulatory RSP commitments provide sufficient public protection, including the UK AI Security Institute and …
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
The revised CB-2 threshold introduces greater operational specificity into the definition of what constitutes a threshold-crossing capability, which affects how future model assessments are conducted and documented under the RSP. The document's characterization of the change as a 'clarification' rather than a revision means Anthropic applies prior system card arguments to the new threshold without re-running prior analyses.
This provision governs how Anthropic determines whether a model requires additional safety measures under the RSP; it does not directly affect user terms or access, but it defines the internal governance standard applied to assess the safety of models users interact with.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Anthropic.