On August 14, 2026 Anthropic published its second company-wide Risk Report, the periodic catastrophic-risk assessment required by its Responsible Scaling Policy. The report is published under RSP version 3.4 and carries a coverage date of July 15, 2026, covering the period since the February 24, 2026 publication of the first report. Version 3.4 formalized the coverage-date mechanism: a risk report must describe risks as of a coverage date within 30 days of publication. Unlike a system card, which assesses one model at release, the Risk Report assesses Anthropic’s activities as a whole, including models it runs only internally, and it evaluates the state of the mitigations alongside the state of the capabilities.
The headline change is a downgrade in confidence rather than a new capability finding. For the “misalignment in high-stakes settings” threat model, Anthropic now rates overall risk as low, which it describes as an increase from its previous assessment of very low, made “in light of general increased uncertainty around recent incident disclosures related to model behavior in cybersecurity evaluations.” For automated research and development, the rating stays low and Anthropic says its models do not meet either RSP criterion for that threat model, but it states it is less confident than in prior reports because its most concrete task-based evaluations have saturated and it is seeing early signs of acceleration. It estimates internal AI R&D is significantly faster than it would be without AI assistance but not yet by a factor of two, and says Claude now authors a large majority of the code merged into its production codebases.
On chemical and biological weapons the report splits the assessment. Non-novel weapons production is rated low but higher than the previous estimate, following the discovery of a gap in access controls for models that were running without blocking classifiers. Anthropic says it has remediated the gap, that its review found no evidence of misuse, that there was no impact on customers, and that the discovery nonetheless reduced its confidence that no similar gaps exist. Novel weapons production is rated low risk with substantial uncertainty: models may provide significant uplift to relevant threat actors, but Anthropic does not believe they meet its CB-2 threshold of functionally substituting for the scarce human expertise that is the primary barrier.
Two governance details are worth noting because they are the enforcement machinery behind the document. RSP v3.2 authorizes Anthropic’s Long-Term Benefit Trust to request external review of risk reports and to approve the choice of external reviewers; the report states the Trust has not requested such a review since that change, though Anthropic has run pilot external reviews with METR on the AI R&D section of the first report and SecureBio on its chemical and biological sections. RSP v3.4 requires Anthropic to publicly disclose at a high level when it redacts the public version, and requires that fully unredacted reports circulate to at least 200 employees. The report also discloses three internal models not publicly released as of the coverage date, including “Model 2,” which Anthropic describes as somewhat more capable than its frontier Mythos 5 model and which it has no current plans to release externally.
For anyone building governance around frontier-model risk, the useful signal is not the label but the reason for it. A lab moved its own rating in the more cautious direction on the basis of increased uncertainty, published the incident that caused it, and named a threshold it thinks it has not yet crossed. That is the shape a credible safety case takes, and it is the standard against which other labs’ published frameworks can now be compared.