Anthropic's Responsible Scaling Policy version 2.0, effective October 15, 2024, and its 2.x revisions list cyber operations among capabilities requiring ongoing assessment rather than as a formal capability threshold with required safeguards. The policy says Anthropic would consult cyber experts, consider tiered access controls or phased deployment for models with advanced cyber capabilities, and run pre- or post-deployment testing.
Why it matters
It shows how one major lab treated autonomous exploit development as a monitored risk without committing to a cyber-specific ASL trigger during 2024-2025.
Key facts
As stated in the sources, with where to find them.
- Cyber Operations is defined as the ability to significantly enhance or automate sophisticated destructive cyber attacks, including discovering novel zero-day exploit chains, developing complex malware, or orchestrating extensive hard-to-detect network intrusions.RSP v2.2, capabilities under Ongoing Assessment table
- The ongoing-assessment entry mentions possible tiered access controls or phased deployments for models with advanced cyber capabilities.RSP v2.2, Ongoing Assessment column
- Version history: v2.0 effective Oct 15, 2024; v2.1 Mar 31, 2025; v2.2 May 14, 2025.RSP updates page, version table
Findings that cite this record
No tracked finding cites this record yet.
Key questions this bears on
- How are attackers using AI agents in real operations?Increasingly to run parts of intrusions: providers and vendors report agent-driven espionage, extortion and credential theft, and malware that queries LLMs.
Sources
Related records
May 22, 2025
Feb 13, 2026
Jun 2, 2026
Apr 7, 2026
Feb 24, 2026
Jul 2, 2026