The second risk report from Anthropic's Responsible Scaling Policy (RSP) landed in June 2025 with little fanfare outside the AI safety bubble. The document itself is a procedural update — a quarterly check-in on a self-imposed governance framework. Yet for those who track the intersection of narrative and market structure, this report is far more than a compliance exercise. It is the latest signal in a quiet but profound shift: from the age of pure capability competition to the age of narrative-driven trust markets.
I have spent the last five years watching how narratives form, harden, and collapse in crypto markets. The ICO boom of 2017 taught me that a whitepaper is not a contract; the DeFi summer of 2020 showed me that liquidity is a story written in code. Now, watching Anthropic issue its second RSP report, I see the same pattern emerging in frontier AI. The report is not a technical breakthrough — it is a narrative artifact, designed to build a specific kind of trust. And that trust, as I have learned, is the most volatile asset of all.
Context: The RSP as a Governance Signal
The RSP was first released in May 2023, making Anthropic the first major AI lab to formalize a tiered safety framework. It borrows from biological safety levels (BSL-1 to BSL-4), mapping model capabilities to ascending risk thresholds. The second report, released roughly two years later, confirms that the framework is now operational — not just a static document, but a recurring evaluation cycle. This alone sets Anthropic apart from OpenAI and Google DeepMind, which have published frameworks but not committed to regular, public updates.
The report's core contribution is the ongoing assessment of Claude 3.5 series models against ASL-3 criteria — the threshold for catastrophic risk capabilities in CBRN (chemical, biological, radiological, nuclear), cyber offense, and autonomous replication. But the report does not disclose whether Claude 3.5 Sonnet or Opus has actually crossed that threshold. It does not reveal the test sets used, the red team results, or the specific mitigation measures deployed. What it reveals is the existence of a process — a process that Anthropic controls, executes, and interprets.
Core: The Narrative Mechanism of Self-Regulation
From my perspective as a narrative strategist, the RSP operates on a trust mechanism that is structurally identical to a centralized exchange's proof-of-reserves audit. The lab claims to hold certain safety reserves (e.g., control over model weights, access restrictions). It publishes a periodic report attesting to those reserves. But the verification is performed by the lab itself. There is no independent third-party auditor with access to the underlying code, the full test results, or the decision-making process behind threshold calibration.
In crypto, we learned the hard way that self-audited reserves are not reserves. The collapse of FTX was not a failure of technology — it was a failure of narrative. The narrative of safety and transparency was built on documents that no one could verify. Anthropic's RSP is not different. It is a beautiful, well-intentioned narrative structure, but it lacks the one thing that makes a narrative credible in a trustless environment: cryptographic verifiability.
This is not a critique of Anthropic's intentions. I have spent time auditing DeFi protocols and know how easy it is to believe your own governance models are sound. The team at Anthropic is genuinely committed to safety. But the mechanism of self-assessment, self-publication, and self-enforcement creates a moral hazard that no amount of good intentions can eliminate. The report's value is not in the data it withholds, but in the narrative it sustains: that Anthropic is the responsible actor in a race where others are carelessly sprinting.
Contrarian: The Phantom Safety Premium
The contrarian angle is uncomfortable but necessary. The RSP narrative may actually increase systemic risk. By creating a public, institutionalized safety framework, Anthropic provides a powerful signal to regulators, enterprise customers, and investors that the catastrophic risks are being managed. This signal reduces the urgency for external oversight. It convinces buyers that they can trust the model without demanding independent verification. It allows the industry to avoid the hard questions about what happens when a model actually crosses the ASL-3 threshold.
Consider the parallel to DeFi's yield farming narrative. In 2020, protocols like Curve offered high yields with complex incentive structures. The narrative was that these yields were sustainable because of clever tokenomics. In reality, they were Ponzi dynamics masked by mathematical elegance. The narrative collapsed when the underlying liquidity dried up. Anthropic's RSP is a form of yield farming on trust: it generates a premium — higher enterprise valuations, favorable regulatory treatment, and brand differentiation — while the underlying asset (verifiable safety) remains opaque.
Moreover, the RSP's focus on catastrophic risks creates a blind spot. The framework does not address everyday social harms: bias, discrimination, privacy violations, psychological manipulation. These are the risks that will affect millions of users before any CBRN event occurs. By prioritizing the spectacular over the mundane, Anthropic is building a narrative that is both incomplete and self-serving. It is the equivalent of a DeFi protocol that secures its treasury against flash loans but ignores the reentrancy bug in its withdrawal function.
Takeaway: The Real Test is Yet to Come
The second RSP report is a milestone in the institutionalization of AI safety governance. But for those of us who have learned to read between the lines of market narratives, it is also a warning. The true test of any safety framework comes not when it is published, but when it is violated. When a Claude model inadvertently generates harmful content, or when a security breach exposes model weights, the narrative will collapse — or it will hold. The difference will depend not on the document, but on the verifiability of the claims it makes.
In the crypto world, we have a saying: "Code is law, but narrative is truth." Anthropic's RSP is a narrative of lawfulness. But until that narrative is backed by cryptographic proof, independent audits, and transparent failure modes, it remains a story — a very good story, but a story nonetheless. Don't trade the model; trade the story. And this story is still being written.