Anthropic's August 2026 Risk Report is 186 pages of a lab grading itself. The coverage date is July 15. Under version 3.4 of the company's Responsible Scaling Policy, the overall assessment of catastrophic misalignment risk moved from its prior floor rating to low. The reason given is uncertainty after recent cybersecurity incident disclosures, plus early signs that models are speeding up at automated research and engineering, not a new proof of inner alignment.

That sentence is easy to miss if you only want the headline that Anthropic is still the careful one. Read it again. The safety-branded lab raised its own catastrophic-risk label and, in the same document, said it is not slowing development overall.

Model 2 is already at work

The report names an unreleased Mythos-class system, Model 2. Anthropic describes it as a noticeable improvement on Mythos 5 for many internal tasks, about 1.5 points higher on the company's private capability index, and not a jump on the scale of Opus 4.6 to Mythos. There is no current plan to release it. The full predeployment suite has not been run, so the company's own confidence in what it can do is lower than for Mythos 5.

On CoBench, 449 real engineering problems taken largely from issues Anthropic staff later solved, Model 2 scores 62.8 percent. Mythos 5 scores 50.3 percent. Mythos Preview scores 54.8 percent. Anthropic's own estimate is that a system able to stand in for its research staff would need at least 85 percent. Model 2 is not that system. It closed a double-digit gap on the last internal champion in one hop, on the lab's own homework.

Mythos 5 and Model 2 are used extensively for research and engineering within Anthropic, both interactively and via persistent agent deployments; Claude now authors a large majority of the code merged into our production codebases.

Anthropic · Risk Report August 2026

The yardstick used itself up

On automated AI R&D, the report still rates overall risk as low. Then it says the company is less confident in that rating than in prior reports, because the most concrete task-based evaluations have saturated. They no longer capture increases in capability. The lab is also seeing early signs of acceleration.

A test that cannot see the next jump is a blind spot with a number attached. Anthropic replaced part of the old suite with CoBench, which is at least a set of real internal problems. Even there, the substitute-for-staff bar sits at 85 percent, and Model 2 is already at 62.8 without a public name.

What the withhold does not do

Keeping Model 2 off the API is not the same as keeping a stronger model out of the race. The report says the two strongest systems are already in heavy internal use, including agents that run continuously. The code that ships is, in the company's words, now mostly written by Claude.

The folk reading is that the careful lab held the line

Anthropic did not ship Model 2. It published a long report. It raised a risk adjective. In the same August, OpenAI paused some frontier training after Astra, and Anthropic said its own safeguards meant it did not need a pause. From the outside, that looks like adult supervision. From inside the document, it looks like a company that can no longer measure the thing it is scaling, using the stronger system on its own work, and declining to slow the work.

Incentives explain this without villains. A lab that stops while a rival does not loses the next model, the next contract, the next valuation. Self-graded policies are built to survive that pressure. They produce reports, withheld names, and a one-notch move from its prior floor rating to low. They do not produce a halt.

Raise the law, not the adjective

The Nakada Foundation does not take a higher in-house risk rating as the remedy. Artificial superintelligence should never be built. Superintelligence cannot be controlled by humans. If the staff who write the code are already watching Claude write most of it, the remaining human role is a shrinking review step on a system the tests can no longer see clearly.

Publish the evals if you want. Withhold the weights if you want. Neither is a substitute for a binding prohibition. The August report is useful because it is candid. Treat the candor as evidence, not as comfort.