Anthropic Adopts Two-Party Controls to Secure Claude
Anthropic is implementing strict two-party controls and federal software security standards to protect its AI models from theft, urging governments to treat the sector as critical infrastructure.

Anthropic has announced a series of internal security upgrades and policy recommendations aimed at protecting frontier artificial intelligence systems from state-level cyber threats and insider risks. The AI safety startup is actively implementing "two-party control" across its development, training, and deployment pipelines. Under this system design, no single employee maintains persistent access to production-critical environments. Instead, developers must obtain time-limited authorization from a colleague, backed by a clear business justification, before accessing critical infrastructure.
To establish a verifiable chain of custody for its AI models, Anthropic is adopting the NIST Secure Software Development Framework (SSDF) and the Supply Chain Levels for Software Artifacts (SLSA) guidelines. These standards, which gained traction following Executive Order 14028 in 2021, ensure that deployed models can be traced directly back to their originating organization. Anthropic is advocating for governments to integrate these frameworks into federal procurement requirements, effectively forcing cloud providers and AI developers to elevate their security posture to secure government contracts.
Beyond internal protocols, Anthropic recommends designating the frontier AI sector as a specialized sub-sector of critical information technology infrastructure. This designation would facilitate deeper public-private information sharing to defend against highly resourced adversaries. Alongside these security measures, the company announced a $5 million grant program to fund independent research into how AI affects human wellbeing. It also rolled out updates to its Claude Fable 5 model, refining its biology safeguards to significantly reduce false positives and prevent unnecessary fallbacks to less capable models during biological queries.
For AI practitioners and enterprise clients, these developments signal a shift toward highly regulated, military-grade operational environments for commercial LLMs. Developers using Claude can expect more rigorous access controls and stricter provenance tracking, which may slightly impact development velocity but will drastically reduce the risk of model theft or supply-chain contamination. The reduction in Claude Fable 5's biology-related false positives also means developers working in life sciences will experience smoother, more reliable API performance without constant system interruptions.
This is our own summary of reporting by Anthropic



