Anthropic, an AI safety and research company, has detailed its approach to securing frontier artificial intelligence models. The company emphasized the increasing capabilities of these models necessitate enhanced security measures, moving beyond standard practices for commercial technologies.
The recommendations aim to advance public discussion on secure deployment practices for all labs and suggest government regulatory approaches that encourage strong cybersecurity. Anthropic states it is in the process of implementing these recommendations internally.
Key Points
- Anthropic is implementing two-party controls, the NIST Secure Software Development Framework (SSDF), and the Supply Chain Levels for Software Artifacts (SLSA).
- Future advanced AI models require security levels exceeding standard commercial practices due to their potential impact on economic and national security.
- Two-party control is recommended for securing advanced AI systems, drawing parallels to practices in manufacturing, food, medical, and finance tech.
- The NIST SSDF and SLSA are identified as gold standards for secure software development, translatable to AI model development and deployment.
- Executive Order 14028 in 2021 is cited as an example of how government procurement can encourage higher development standards.
- Frontier AI labs should engage in public-private cooperation, potentially through designating the sector as a sub-sector of existing IT critical infrastructure.
Context
According to Anthropic, the strategic nature of advanced AI technology means that frontier AI research and models must be protected from theft or misuse. The company suggests that governments and frontier AI labs must be prepared to safeguard advanced models, model weights, and the underlying research. This includes developing robust best practices and treating the advanced AI sector as akin to "critical infrastructure" in terms of public-private partnership for security.
Why It Matters
This guidance indicates that builders and deployers of frontier AI models may face increasing pressure to adopt rigorous cybersecurity practices. The recommendations suggest a shift toward treating AI development with the same security considerations as critical infrastructure, potentially influencing future procurement requirements and regulatory landscapes.
What To Do
- Note the recommended adoption of NIST SSDF and SLSA for secure model development.
- Watch for further guidance on "two-party control" mechanisms in AI systems.
- Consider how current development practices align with the suggested "critical infrastructure" designation for the AI sector.
- Review the implications of potential government procurement requirements for AI companies and cloud providers.
