Anthropic drew heightened scrutiny from security and policy communities over how its AI safety and governance commitments are evolving and how its models are being positioned for sensitive use cases. A Help Net Security analysis reported that Anthropic’s updated Responsible Scaling Policy (RSP) 3.0 represents a structural shift from maintaining absolute risk below fixed thresholds to a more relative, competitor-dependent posture—implying Anthropic may be less willing to pause or constrain capability development if peers do not. The same reporting also noted Anthropic’s launch of Claude Code Security as a move that unsettled parts of the cybersecurity market and raised questions about trust and vendor assurances in security-adjacent AI offerings.
In parallel, Lawfare reported the Pentagon labeled Anthropic a national security risk tied to usage restrictions Anthropic imposed on a military contract, while also describing reporting that the U.S. military used Anthropic’s Claude model in initiating operations in Iran less than a day later—highlighting the tension between policy concerns and rapid military adoption of frontier AI. Separately, Anthropic announced the creation of the Anthropic Institute, a research unit intended to study long-term societal impacts and risks from advanced AI; the company stated its models can already discover severe cybersecurity vulnerabilities and argued that governments and industry will face near-term governance challenges as capabilities accelerate.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
On March 11, 2026, Anthropic announced the creation of the Anthropic Institute, a research unit focused on long-term societal risks from advanced AI. The company said the institute would study issues such as cybersecurity, economic disruption, governance, and value alignment, while partnering with outside experts.
Anthropic filed a lawsuit challenging the U.S. government's designation of the company as a supply-chain risk. The legal action was later supported by an amicus brief from employees at OpenAI and Google DeepMind, according to one reference.
Following Anthropic's removal, OpenAI replaced Anthropic in the relevant government role or workstream. One account adds that OpenAI later backed away from claims it would follow Anthropic's stated red lines.
After Anthropic's public stance, the U.S. government suspended use of Anthropic tools in government institutions and designated the company as a supply-chain risk. Multiple references describe this as a major escalation in the conflict between Anthropic and federal authorities.
Later in early 2026, Anthropic took a public stance against Pentagon uses of AI such as mass surveillance of Americans and fully autonomous weapons. This position became a key trigger in the subsequent dispute with the U.S. government.
In early 2026, Anthropic published RSP 3.0, reportedly shifting from fixed safety thresholds toward a more competitor-relative posture. Commentators cited this as a meaningful change to the commitments underlying Anthropic's safety-focused brand.
In early 2026, Anthropic launched Claude Code Security as part of its push into cybersecurity-focused AI offerings. The release is described as part of a rapid sequence of public moves that shaped perceptions of the company in the security community.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourcelawfaremedia.org
Open sourcehelpnetsecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.