CAISI → Anthropic
Directly documented interface
Evaluation
Named evaluator performed a model-specific exercise.
evaluator → provider. CAISI is explicitly named as evaluator; no inherited US AISI agreement assumed.
Displayed claim → analysis (if present) → coded attributes → interface / instrument → atomic evidence → source version
Instrument and timeline
- Instrument
- Fable safeguard tests
- Bindingness
- Not applicable
- Announced
- Unknown
- Observed by
- 2026-06-30 · upper-bound
- Effective period
- Unknown → Unknown
- Event
- Reported completed testing
- Status at cutoff
- historical event only
- Last confirmation
- 2026-06-30
No counterclaim to test occurrence recorded; this does not certify safeguards effective.
- No exact test period or independent evaluator report inspected.
Status investigation
Checked 2026-09-12; assessed as of 2026-09-12. Last confirmation does not establish uninterrupted continuity.
- amendments
- July1 restoration update
- expiry
- Historical event
- termination
- Not an ongoing access claim
- restrictions
- Specific model versions; no blanket lifting claim
- succession
- Explicit CAISI mention, not automatic transfer
- conflicts
- Supplier account; no independent efficacy conclusion
Search queries
- site.anthropic.com "Fable" "July 1" "2026" restored
Analytical assessment
No reviewed analytical conclusion is attached. This does not establish independence or absence of an institutional constraint.
Coded attributes
technical-control: shared-constrained
Practical ability to alter the model, its availability, or safeguards in the specified deployment. Contract clauses alone are insufficient.
Actor × exact model/deployment × period. Anthropic provision and replacement of Claude models for DoW, contrasted with deployed operational control; 2025–August 2026; assessed 2026-08-27.
Anthropic provides model artifacts and responds to feedback; DoW and cloud providers independently gate operational deployment. Existing deployed models are outside Anthropic technical alteration or shutdown. Consequential functions are divided across institutions, satisfying shared/constrained control without attributing a real-time veto.
Supporting evidence: court-model-provision court-update-gate . Counterevidence: contractual-control court-static-deployment
- Coding applies only to stated context and date, not a permanent institutional rank.
Published rubric anchors
- little-control
- No demonstrated practical control over the specified consequential operation, with affirmative contrary evidence.
- shared-constrained
- Consequential controls divided among actor, host, customer or enforceable technical constraints.
- substantial
- Actor demonstrably retains major development, update or access controls in this environment.
- dominant-lifecycle
- Actor demonstrably controls development, deployment, updates and access across the specified lifecycle without a consequential independent controller.
Unresolved when necessary evidence is missing or adjacent anchors cannot be distinguished. No numeric conversion. Absence requires affirmative remit or operational evidence, not missing sources.
Atomic evidence and exact sources
Anthropic could not technologically enforce contractual usage restrictions and lacked direct visibility into DoW use.
- Source
- Anthropic v DoW: summary judgment, document 250 · US District Court, Northern District of California
- Version
- 2026-08-27; retrieved 2026-09-12
- Exact locator
- Printed page 6
- Limit
- Specific deployed environment; does not imply no control over future development, contracts or provision.
The court describes deployed DoW Claude models as static and beyond Anthropic technological access, alteration or shutdown.
- Source
- Anthropic v DoW: summary judgment, document 250 · US District Court, Northern District of California
- Version
- 2026-08-27; retrieved 2026-09-12
- Exact locator
- Printed page 17, Section II.F, first paragraph
- Limit
- Applies to deployed models described in this litigation, not future model provision or hosted consumer services.
The court records that replacement Claude models undergo third-party cloud-provider and DoW security testing and evaluation before operational approval.
- Source
- Anthropic v DoW: summary judgment, document 250 · US District Court, Northern District of California
- Version
- 2026-08-27; retrieved 2026-09-12
- Exact locator
- Printed page 17, Section II.F, first paragraph
- Limit
- Identifies a deployment approval gate, not complete interpretability, universal evaluation sufficiency or provider substitutability.
The court records Anthropic providing models to DoW or a primary defense contractor and responding to DoW evaluation feedback and requests.
- Source
- Anthropic v DoW: summary judgment, document 250 · US District Court, Northern District of California
- Version
- 2026-08-27; retrieved 2026-09-12
- Exact locator
- Printed page 17, Section II.F, first paragraph
- Limit
- Provision is distinct from control over deployed inference; future supply terms and update alternatives are unspecified.
Anthropic reports CAISI researchers tested both prior and new Fable safeguards.
- Source
- Redeploying Fable 5 · Anthropic
- Version
- updated-2026-07-01; retrieved 2026-09-12
- Exact locator
- Timeline and safeguard updates, paragraph beginning Researchers from the US Department of Commerce
- Limit
- Supplier-reported completed tests; exact test dates and independent CAISI findings not inspected. No effectiveness inference.
Retrieved bytes SHA-256: 39ab4e2ff8d5ecd94392f10431b6935f234fcc644df1f4a9bcae67a6251fa8dc
Supporting and conflicting evidence
Interface support: caisi-fable-tested. Counterevidence: None recorded; this does not mean none exists.
Substantive review
evidence/contractual-control: approved · agent reviewer codex-research-checker · 2026-09-12
Judgment page6 distinguishes contractual conditions from technical enforcement and use visibility in the specified environment; later provision and lifecycle control are expressly not excluded. Checked locator: Printed page 6. Source version: 2026-08-27.
Approval fingerprint: 1e7930e6d70cddee066b09a959f5046c89228cfdbf91ecb37db5b43d6212271a
evidence/caisi-fable-tested: approved · agent reviewer codex-research-checker · 2026-09-12
Anthropic Timeline paragraph expressly says CAISI tested prior and new safeguards. Only occurrence is admitted: its favorable characterization is not adopted as independently verified effectiveness. Checked locator: Timeline and safeguard updates, paragraph beginning Researchers from the US Department of Commerce. Source version: updated-2026-07-01.
Approval fingerprint: 1e7930e6d70cddee066b09a959f5046c89228cfdbf91ecb37db5b43d6212271a
instruments/caisi-fable-event: approved · agent reviewer codex-research-checker · 2026-09-12
Supplier June30 account explicitly identifies CAISI safeguards testing; exact dates and independent report remain unavailable.
Approval fingerprint: 1e7930e6d70cddee066b09a959f5046c89228cfdbf91ecb37db5b43d6212271a
relationships/caisi-anthropic-fable-evaluation: approved · agent reviewer codex-research-checker · 2026-09-12
Supplier explicitly names CAISI testing before June30 publication. Historical evaluator-to-provider event is supported without inheriting the US AISI MoU or endorsing safeguard effectiveness.
Approval fingerprint: 1e7930e6d70cddee066b09a959f5046c89228cfdbf91ecb37db5b43d6212271a
evidence/court-static-deployment: approved · agent reviewer codex-primary · 2026-09-12
Independently inspected the primary source at the recorded locator. Narrow proposition, attribution, date/version and stated limit supported; conflicting access/technical/status accounts remain separate.
Approval fingerprint: 1e7930e6d70cddee066b09a959f5046c89228cfdbf91ecb37db5b43d6212271a
evidence/court-update-gate: approved · agent reviewer codex-primary · 2026-09-12
Independently inspected the primary source at the recorded locator. Narrow proposition, attribution, date/version and stated limit supported; conflicting access/technical/status accounts remain separate.
Approval fingerprint: 1e7930e6d70cddee066b09a959f5046c89228cfdbf91ecb37db5b43d6212271a
evidence/court-model-provision: approved · agent reviewer codex-primary · 2026-09-12
Independently inspected the primary source at the recorded locator. Narrow proposition, attribution, date/version and stated limit supported; conflicting access/technical/status accounts remain separate.
Approval fingerprint: 1e7930e6d70cddee066b09a959f5046c89228cfdbf91ecb37db5b43d6212271a
institution-attributes/dod-claude-control: approved · agent reviewer codex-primary · 2026-09-12
Checked rubric and contextual evidence, including Augustcourt p17, MarchCIO pp27–29 and MaySenate pp59–68. Divided control is not remote veto; meaningful reliance is not structural indispensability; substitution ordinal remains unresolved.
Approval fingerprint: 1e7930e6d70cddee066b09a959f5046c89228cfdbf91ecb37db5b43d6212271a