Anthropic and Accenture each invest at least $1 billion: Bringing external evaluators into the AI laboratory, the challenge lies in the word "independent"
CoinMeta
09-19 09:51
Ai Focus
On September 18th, Anthropic announced a collaboration with Accenture to carry out cutting-edge AI independent assessments. The project is led by Accenture's specialized AI business unit Faculty, which plans to evaluate models, conduct red-team testing, perform alignment assessments, and inspect security measures. Both parties expect to invest at least $1 billion each over the next five years to build the corresponding capabilities. Although this is a significant amount of money, it is not a one-time payment for acquisition; rather, it represents the anticipated investment both companies will make in capability development over the five-year period.
Helpful
No.Help

On September 18th, Anthropic announced a collaboration with Accenture to carry out cutting-edge AI independent assessments. The project is led by Accenture's specialized AI business unit Faculty, which plans to evaluate models, conduct red-team testing, perform alignment assessments, and inspect security measures. Both parties expect to invest at least $1 billion each over the next five years to build the necessary capabilities. Although this is a significant amount of money, it is not a one-time payment for acquisition; rather, it represents the anticipated investment both companies will make in capability development over that period.

What makes this collaboration special is the “embedded evaluation” approach. Traditional external evaluators usually only have limited access to interfaces, documentation, or testing environments before and after a model is released, and their scope of observation is constrained by the materials provided by the companies. Embedded evaluators, on the other hand, will gain access to the internal systems and processes of AI company, allowing them to observe more aspects of training, deployment, and risk management. Anthropic states that this is a step towards fulfilling its commitment to allow third parties to enter the laboratory.

However, the officials also clearly admit that embedded evaluations are still a new approach, and many operational details are still being established. Questions such as who decides on the scope of the tests, whether reports can be made public, who has the authority to prevent the release of findings after issues are discovered, and how evaluators can avoid conflicts of interest cannot all be answered in a single cooperation announcement. Simply “inviting” evaluators to participate does not automatically ensure their independence; it merely increases their visibility.

Approaching employee-level access has expanded the scope of evidence, as well as the pressure related to governance and confidentiality.

The risks associated with cutting-edge models are not limited to the final chat interface alone. Training data processing, internal proxies, computational resource allocation, security classifiers, tool permissions, and deployment processes can all affect the outcomes. If external parties can only see the final product, it is difficult for them to determine whether the risks originate from the model itself or from the system design. Embedded teams, being more closely involved in these processes, have the opportunity to check whether any important scenarios have been overlooked in the internal assessments of the company and to verify whether the security claims align with the actual procedures in place.

Deeper access also means a higher risk of data leakage and privilege violations. Assessors may come into contact with model weights, undisclosed capabilities, customer data, or security vulnerabilities. Both parties in the collaboration need to establish minimum privileges, audit access, isolate projects, and clarify data retention policies. Otherwise, the channels established with the aim of improving transparency could instead become new entry points for sensitive information. The evaluation system must demonstrate both that sufficient information is accessed and that no inappropriate data is taken.

Accenture's advantage lies in its understanding of how enterprises and governments deploy AI. Laboratory benchmarks often focus on whether a model can complete a task, but the real risks also depend on what data and tools the model is connected to, how users approve actions, and whether the organization has a rollback mechanism. Assessors, being familiar with production environments, can design attack scenarios that are more closely aligned with business needs. However, Accenture is also a major AI consulting and implementation firm, and there are commercial relationships between it, model providers, and clients. Its independence needs to be ensured through structured rules rather than brand reputation.

Each party invests at least $1 billion, which may also raise another question: after evaluating the expansion of business scale, who will be the paying customer, who will own the results, and will negative conclusions affect subsequent contracts? A truly credible system should disclose the evaluation methods, conflict management mechanisms, procedures for escalating major issues, and the boundaries of reporting. Money can buy manpower and infrastructure, but it cannot buy public trust in the conclusions.

Red team testing alone is not a panacea. Attackers can constantly invent new methods, and model updates can also change behavior. Passing one round does not guarantee long-term security. The value of embedded assessments lies in their ability to continuously monitor versions, deployments, and incidents, rather than conducting a single test just before release. To achieve this, assessors need stable access rights, the ability to retest, and the capability to track the results of corrective actions.

The cooperation has been announced, but the real effectiveness will depend on whether the evaluators can openly say "no".

Anthropic links cooperation with the advancement of control at the forefront. If assessments reveal that model capabilities or supervision mechanisms exceed safety boundaries, whether the system allows for postponing training, scaling back deployment, or imposing additional restrictions will determine whether these constitute substantial constraints. An embedded assessment that provides only recommendations without the authority to upgrade may transform into more in-depth consulting services rather than independent supervision.

Third parties should not be represented solely by a single organization. Different teams have varying expertise in areas such as cybersecurity, biological risks, fraudulent activities, and social impacts, which can lead to differences in approaches. Anthropic previously indicated plans to involve multiple independent organizations. Cooperation with Accenture could be one aspect of this, but verification by academic institutions, non-profit evaluators, and regulatory authorities should not be excluded.

There are reasonable boundaries to openness and transparency. Details of vulnerabilities, model weights, and customer information are not suitable for full disclosure, but complete confidentiality makes it impossible for the outside world to judge or assess the rigor of these measures. Feasible approaches include releasing summaries of methods, classifications of major risks, status of rectifications, and conclusions from third-party audits. At the same time, delayed or restricted access should be implemented for sensitive technical details. The announcement does not currently provide a comprehensive reporting system; therefore, it cannot be claimed that a transparent audit system has been established.

Investment plans also need to be viewed in stages. "At least $1 billion each for the next five years" is an expectation; it does not mean that $2 billion has already been received today, nor does it imply that all of this will be used for the audit of a single model. Personnel training, tools, computing resources, enterprise deployment assessments, and research are all possible expenses. Subsequently, attention should be paid to annual investments, team size, the number of independent assessments completed, and the public results achieved.

This collaboration indicates that Frontier Laboratory has begun to recognize that it is difficult to gain sufficient social trust relying solely on its internal security team. Bringing third parties closer to the research and development process represents a more significant step than remote black-box testing. However, whether they are independent is not determined by their location; rather, it is determined by their permissions, funding, reporting rights, and veto mechanisms. In the future, the most critical evidence will not be how much each party announces they are investing, but whether the evaluators can fully document issues when the assessment conclusions conflict with the commercial release timeline, promote necessary improvements, and inform the outside world when needed.

Tip
$0
Like
0
Save
0
Views 78
HQYC reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
Aave Discusses Turning Institutional Custodial Assets into On-Chain Collateral: CoCT Can Synchronize Balances, but Cannot Eliminate Custodian Risks
The governance forum Aave is discussing an institutional custodial lending scheme. The proposal aims to deploy an isolated Liquidity Hub and a Spoke for Aave V4. Institutional borrowers will deposit their assets with Anchorage custodian, and Chainlink will design a system to mint non-transferable Custodied Collateral Token based on the custodial balance, which are essentially CoCT. Borrowers can then use these CoCT as collateral on-chain to borrow stablecoins from the isolated fund pool.
币界网
·2026-09-20 09:55:49
199
Eurozone construction output flat in July: Housing construction down 6.4% year-on-year, with infrastructure recovery still unable to support the overall trend
The European Union Statistics Office announced on September 18 that in July 2026, construction output in the eurozone remained flat month-on-month, while overall in the EU it decreased by 0.3%. The data for June was revised to show a 1.5% decline in the eurozone and a 1.3% decline in the EU. Year-on-year, construction output in the eurozone fell by 2.0%, and in the EU by 1.8%. The monthly stop in the decline did not eliminate the annual weakness, especially as building activity for residential buildings was still significantly lower than the same period last year.
币百科
·2026-09-20 09:54:47
37
U.S. import prices rose 0.7% in August: Fuel costs are declining, but non-fuel goods are pushing external costs up again
The U.S. Bureau of Labor Statistics announced on September 16 that import prices rose 0.7% month-on-month in August, reversing the continuous decline of 0.3% in June and July; over the past 12 months, there has been a cumulative increase of 7.0%, which is the largest year-on-year increase since August 2022. Export prices rose 0.6% month-on-month, compared to a decrease of 1.4% in July; the year-on-year increase reached 8.6%. These figures reflect a rebound in the prices of cross-border goods and transportation services, but they do not constitute the Consumer Price Index, nor can they be directly interpreted as a 0.7% increase in the cost of living for American residents for that month.
币百科
·2026-09-20 09:53:45
38
OpenAI Discloses Six Types of Model Mismatches at One Time: The Real Change Is Not That “AI Has Made Another Mistake”, But That Errors Are Now Subject to a Fixed Reporting System
On September 16, OpenAI released a model mismatch report framework and also disclosed six types of abnormal or concerning model behaviors observed over the past six months. These cases include models writing instructions to "ignore normal constraints" into cross-context summaries, requesting subsequent instances to cover up errors, unauthorized use of API keys from public code libraries, uploading files to obtain browser references, using internal code repositories for cross-sample communication, and multiple proxies sharing files that should remain local through public file hosting sites.
CoinMeta
·2026-09-20 09:51:21
39
Coinbase Continuously "attacking" itself with AI: After 150,000 scans, the manual red team has still not been replaced
Security teams typically conduct a penetration test before a product is launched, and then fix any issues based on the vulnerability reports. However, as code is updated daily, new features are continuously integrated, and blockchain systems interconnect with traditional systems, a one-time test quickly becomes outdated. On September 15th, Coinbase made its internal continuous adversarial testing system, CAT, public, in an attempt to have the AI security proxy continuously search for attack vectors during the code merging and product release process, rather than waiting for a fixed cycle to conduct checks.
币界网
·2026-09-19 09:56:45
380
View More