Anthropic activated ASL-3 protections for Claude Opus 4 as a precaution because it could not rule out ASL-3 CBRN risk; the announcement does not cite cyber capability as the trigger. The ASL-3 security standard it describes includes more than 100 controls to protect weights, two-party authorization for weight access, and egress bandwidth controls against exfiltration.
Why it matters
It was a public activation of a higher safety level under a lab framework, and its egress and access controls are defenses against cyber theft of model weights.
Key facts
As stated in the sources, with where to find them.
- Trigger was CBRN-related: Anthropic said clearly ruling out ASL-3 risks was not possible for Claude Opus 4.Announcement, rationale
- Security measures include over 100 controls, two-party authorization for weight access, egress bandwidth controls and binary allowlisting on endpoints.Security measures section
Findings that cite this record
No tracked finding cites this record yet.
Key questions this bears on
- Can prompt injection against AI agents be reliably defended?Not reliably. Defenses reduce injection but none has eliminated it; limiting what untrusted input can trigger is the most defensible approach.
Sources
Related records
Oct 15, 2024
Apr 7, 2026
Jul 10, 2025
Jun 2, 2026
Feb 13, 2026
Oct 20, 2025