AI Policy Wiki
Dashboard

Frontier Compliance Framework (February 2026)

medium confidence · updated 2026-06-06

Anthropic's regulatory compliance document for California's SB 53 (TFAIA) and the EU AI Act — distinct from the voluntary RSP, this is a structured mapping of safety practices to legal obligations.

The Frontier Compliance Framework (FCF) is a document published by Anthropic that maps the company's safety practices to legal obligations under two regulatory regimes: California's Transparency in Frontier AI Act (SB 53/TFAIA) and the EU AI Act. It is distinct from Anthropic's voluntary Responsible Scaling Policy and is presented by the company as documentation of what regulation requires rather than what its safety practices aspire to.

Anthropic published the FCF on anthropic.com in early 2026. The document carries a March header but was likely finalized in February and published in March.

Purpose and dual jurisdiction

The FCF serves two compliance functions. In the United States, it operates as Anthropic's "Frontier AI Framework" under California's SB 53 (TFAIA), documenting the technical and organizational protocols the company uses to manage, assess, and mitigate catastrophic risks. In the European Union, Anthropic Ireland Limited signed the EU General-Purpose AI Code of Practice, and the FCF serves as the publicly available safety and security framework summary for in-scope general-purpose AI (GPAI) models under the EU AI Act.

A single document therefore serves as compliance evidence for two regulatory regimes that define their triggering risks differently: TFAIA's "catastrophic risk" and the EU AI Act's "systemic risk."

Distinction from the Responsible Scaling Policy

The FCF is presented as separate from the Responsible Scaling Policy (RSP). According to the document, the RSP is Anthropic's voluntary best-practices framework, describing what the company believes safety should look like and which may exceed regulatory requirements, while the FCF describes what is required by law. In this framing the RSP is the company's forward-looking standard and the FCF is the regulatory floor.

Scope and risk categories

The FCF applies to frontier models that present "catastrophic risk" under TFAIA and "GPAI with systemic risk" under the EU AI Act. It covers four risk categories: cyber threats; CBRN (chemical, biological, radiological, nuclear); harmful manipulation; and sabotage and loss of control.

Structure

Section 2 of the FCF sets out a tiered process for systemic risk assessment and mitigation, consisting of systemic risk identification (processes to identify foreseeable and material risks of large-scale harm from state-of-the-art models), systemic risk analysis (severity and probability assessment), risk acceptance determination (explicit criteria for acceptable risk levels), risk tiers (categorized risk levels with associated response protocols), and safety mitigations (technical and operational countermeasures).

Sections 3 through 7 cover security risk management (model security and adversarial access), model reporting (transparency obligations under TFAIA and the EU AI Act), external expert input (independent assessment of risk claims), allocation of responsibility (a developer-versus-deployer framework), and change management (an update and approval process with a changelog).

Standards referenced

The FCF draws on METR's Responsible Scaling Policy framework, the Cloud Security Alliance AI Safety Initiative, ISO 42001 (AI management systems), NIST 800-53 (security controls), and Trust and Safety industry best practices.

The document situates a frontier AI developer's safety practices against binding regulatory obligations, with the same practices documented separately under a voluntary standard (the RSP) and a regulatory standard (the FCF), and the same document used as compliance evidence under two regimes whose definitions differ.

Relationships

  • instance-of: AI Safety Frameworks — the FCF connects voluntary safety frameworks to binding regulation.
  • depends-on: California SB 53 — the FCF is the compliance artifact SB 53 was designed to require.
  • depends-on: EU AI Act — the FCF also satisfies EU AI Act GPAI safety framework requirements.
  • related: RSP Version 3.1 — the voluntary framework the FCF is distinguished from.
  • related: NIST AI RMF — the FCF references NIST 800-53.

Provenance

Published by Anthropic on anthropic.com, dated February 2026 (March header; likely finalized February, published March). Raw source: Raw Sources/Frontier Compliance Framework Feb 2026.md.