Anthropic's AI accountability wishlist, three years later
Most of what the 2023 NTIA submission asked for exists now, built by state law and Brussels, not Washington.
In June 2023, Anthropic filed a comment with the NTIA's request for input on AI accountability. It asked for seven things: more funding for evaluation research, mandatory disclosure of eval methods and results, capability thresholds that gate deployment, pre-registration of large training runs with the government, a class of expert third-party auditors, mandatory external red-teaming before model release, and antitrust clearance so labs could collaborate on safety without legal exposure.
That document is old enough now to score. Three years later, most of the wishlist exists in some form. Almost none of it arrived through the door it was filed into.
The NTIA did its part. Its AI Accountability Policy Report landed in March 2024 with eight sets of recommendations, including independent audits of high-risk systems and certification for AI auditors. Then the election happened. The administration that took office in January 2025 rescinded the Biden executive order on AI and renamed the US AI Safety Institute the Center for AI Standards and Innovation, stripping "safety" from the letterhead. The federal accountability agenda the report sketched was shelved before any of it became binding.
And yet the asks kept landing, just elsewhere.
What shipped
Take pre-registration of training runs, the most surveillance-flavored item on the list. Executive Order 14110 delivered it in October 2023, requiring companies to report runs above 10^26 FLOPs to Commerce under the Defense Production Act. That died in January 2025. But the EU AI Act picked up the same idea with a lower bar: providers must notify the Commission when a model's training compute crosses 10^25 FLOPs, and the general-purpose AI obligations have applied since August 2025. Pre-registration exists. It just lives in Brussels.
External red-teaming went from proposal to routine, though not to mandate. In August 2024 the US AI Safety Institute signed agreements with Anthropic and OpenAI for pre-deployment access to frontier models, and by November it had published a joint US-UK testing report on an upgraded Claude 3.5 Sonnet. The same government teams, post-rename, red-teamed Anthropic's Constitutional Classifiers before Claude Opus 4 and 4.1 shipped, surfacing cipher-based evasions and universal jailbreaks that got fixed pre-release. By mid-2026, Google, Microsoft, and xAI had signed similar agreements. The 2023 submission said "mandate." What exists is a handshake that five labs have chosen to extend.
Disclosure is the clearest win, and the path it took is telling. System cards with real eval data became an industry norm without any law requiring them. Then California made the practice binding: SB 53, signed in September 2025 and effective January 1, 2026, requires large frontier developers to publish safety frameworks, disclose catastrophic-risk assessments, report incidents, and protect whistleblowers. Anthropic endorsed the bill and published a compliance framework for it. Read the sequence back: a lab asked the federal government for mandatory disclosure in 2023, got a report and then a reversal, and ended up backing a state statute that codified what it was already doing voluntarily.
What didn't
The auditor profession never materialized. This was the idea both Anthropic's submission and the NTIA report leaned on hardest: an independent layer of certified evaluators with serious ML expertise, analogous to financial audit. In 2026 there is no auditor certification, no standard audit design for frontier models, and no firm you could hire to render an independent opinion on a model's safety case that regulators would accept. What filled the gap is two government red teams (CAISI and the UK's AI Security Institute) plus the labs grading themselves through responsible scaling policies. That's accountability infrastructure, but it's thin, and all of it is either politically revocable or self-administered.
The antitrust guidance never arrived either. Labs still coordinate on safety through the Frontier Model Forum while lawyers hover. And interpretability research, which the submission wanted publicly funded, remains bankrolled almost entirely by the labs themselves.
Where it touches your stack
If you build on frontier models rather than train them, this history has concrete consequences.
The disclosure artifacts are now real engineering documents. System cards and SB 53 safety frameworks carry eval results on jailbreak resistance, cyber capability, and autonomy that used to be either secret or marketing. Read them during model selection the way you'd read a database's Jepsen report. A provider's published framework also tells you the conditions under which it will gate or pull a model, which is availability risk you should design around.
If you deploy in the EU, the AI Act's general-purpose model provisions require providers to hand downstream integrators documentation on capabilities, limitations, and integration. That's leverage you didn't have in 2023: when a vendor's docs are thin, the documentation obligation is now theirs, not yours to reverse-engineer.
And plan around statutes, not agencies. The AISI-to-CAISI whiplash is the cautionary tale: a voluntary federal program can be renamed, refocused, or defunded in a news cycle. The EU AI Act and SB 53 will still be generating compliance requirements in five years. Anything built on an MOU might not survive the next inauguration.
Score the 2023 wishlist five out of seven, with an asterisk the size of an election. The piece that mattered most, an accountability layer that is neither the government nor the labs, is the one nobody built.
Sources & further reading
- Charting a Path to AI Accountability — anthropic.com
- AI Accountability Policy Report — ntia.gov
- Strengthening our safeguards through collaboration with US CAISI and UK AISI — anthropic.com
- Anthropic is endorsing SB 53 — anthropic.com
- Microsoft, Google, xAI giving government early access to AI models for review — thehill.com
- US AISI and UK AISI Joint Pre-Deployment Test: Upgraded Claude 3.5 Sonnet — nist.gov
Priya covers AI frameworks, developer productivity tooling, and the startup ecosystem across South and Southeast Asia, bringing a researcher's rigour and a practitioner's empathy to every story. She is deeply sceptical of benchmarks and asks hard questions so her readers don't have to.
Discussion 0
No comments yet
Be the first to weigh in.