Anthropic’s Advanced AI Framework, read through the Ungoverned: AI Minimum Viable Governance’s 12 Ps of Responsible AI Oversight©.
This is the first in an ongoing series. Every other week, I take one major AI governance framework — from the frontier labs to the regulators to the Vatican — and read it through the same practical lens: what it gets right, where the gaps are, and what leaders can actually do about it.
Here is something I did not plan to write today. I asked Claude to compare Anthropic’s newly released Advanced AI Framework against the AI Minimum Viable Governance framework in my book Ungoverned — expecting a diplomatic non-answer. What came back was clear, structured, and a little uncomfortable. So I am sharing it with my commentary.
Anthropic has published one of the most serious governance frameworks in the AI industry. It deserves to be read carefully and to be credited. It is proactive where most governance is reactive, specific where most is vague, and accountable where most hides behind assurance language.
And yet, if you lead a hospital, a university, a bank, or any institution deploying AI into consequential decisions, this framework was not written for you. It was written about the companies whose models you deploy. That distinction is the whole reason for this series — and it is where the Seba 12 Ps of Responsible AI Oversight do their work.
What the Framework Gets Right
Anthropic’s framework governs frontier model developers and the governments that oversee them. Its strongest features are structural and genuinely admirable.
It builds accountability before the incident rather than assembling compliance after it. It requires a named corporate officer accountable for implementation — not a committee, a person. It produces evidence rather than promises, through safety frameworks, regular risk reports, and system cards. It calls for independent evaluation with real independence standards and provisions to prevent evaluator shopping. And it requires critical-incident reporting within a tight window, backed by penalties for false statements.
Every one of those instincts aligns with how I argue institutions should govern in Ungoverned. The disagreement is not philosophical. It is about altitude — and about who is left uncovered.
Reading Anthropic Through the 12 Ps
The 12 Ps govern the institution that deploys AI, not the lab that builds it. Run the framework through each, and the picture comes into focus: strong where the developer’s obligations live, silent where the institution’s begin.
Purpose. The framework assumes the developer’s purpose is building safe frontier models. It says nothing about whether your deployment serves your mission or merely your convenience. Operationalize: before any consequential AI use, write down the decision it serves and whether that decision belongs to your mission.
Problems. Anthropic addresses catastrophic, civilizational risk. Your risk is narrower and more immediate: is this tool actually solving the decision problem in front of you, or introducing a new one? Operationalize: name the specific problem before you procure the tool.
Profits. The framework governs large developers by revenue. It does not ask who within your institution benefits from a deployment and who bears its risk. Operationalize: map the beneficiary and the risk-bearer for each use; if they differ, govern the gap.
People. This is the framework’s largest blind spot relative to the 12 Ps. It addresses systemic risk to humanity, not the individual student, patient, worker, or customer affected by a single institutional decision. Operationalize: identify everyone touched by an AI-shaped decision and give them standing.
Planet. The framework touches compute and capability thresholds, but not your institution’s energy, infrastructure, or physical-world footprint. Operationalize: account for the compute and energy cost of what you deploy.
Process. Its obligations are episodic — periodic reports. Institutional governance is continuous: monitoring, updates, escalation, rollback, and incident learning. Operationalize: build a standing review cadence, not a filing calendar.
Policy. Anthropic sets rules for developers. It does not set the rules governing your specific use case and its limits. Operationalize: write the use-case policy — what this tool may and may not be used for, in your context.
Protections. The framework names red lines for catastrophic capabilities. It names no complaint pathway for the individual flagged, scored, or triaged inside your institution. Operationalize: build the red lines and the recourse channel for vulnerable groups.
Privacy. Developer-side transparency is real here; institutional data governance is absent because that is your responsibility, not the lab’s. Operationalize: govern data access, retention, exposure, masking, and secondary use at the point of deployment.
Provenance. Anthropic’s system cards are a genuine contribution to model lineage and traceability — one of the clearest alignments with the 12 Ps. Operationalize: extend that lineage discipline to your own data and decisions, not just the model’s.
Preparedness. The framework assumes developer competence and cadence. It assumes nothing about your leadership’s readiness to govern what you deploy. Operationalize: assess governance competence and cadence before, not after, deployment.
Product Ownership. The sharpest gap. Anthropic names the owner of the model within the lab. No developer-level framework can name who owns the outcome once that model shapes a real decision inside your walls. Operationalize: name an accountable owner for every consequential AI use, before it goes live.
The Pattern
Read all twelve together, and the shape is unmistakable. Anthropic governs Provenance, Preparedness, and Process well — at the developer’s altitude. It is silent on People, Protections, and Product Ownership at the institution’s level, because those were never its job.
This is not a flaw in Anthropic’s framework. It is the boundary of it. The framework does what it set out to do. The error would be for an institutional leader to read it, feel covered, and deploy.
The One Line for Your Next Board Meeting
Anthropic governs what frontier developers must prove to the government. The 12 Ps govern what your institution must build before it deploys. Those are not the same gap — and you are still exposed on the second one, no matter how well the first is met.
If your institution already references Anthropic’s framework, you have done the developer-side diligence. The deployment-side floor is still yours to build. Start with the three Ps where the gap is widest: name an owner (Product Ownership), give affected people recourse (Protections), and set a governance cadence before an incident sets one for you (Preparedness).
Next in the series: OpenAI’s governance framework, read through the same twelve lenses.
Ungoverned: A Practical Guide to AI Minimum Viable Governance from your library, or find it at amazon.com/dp/B0GXSTVY6C.
Follow the series at freddieseba.com/newsletter.
Drafted and refined using AI-assisted tools for synthesis and clarity. Final editorial judgment and responsibility remain with the author.
