AI Governance Institute logo
AI Governance Institute

Intelligence for Compliance and GRC Teams

← News
Research2026-04-19

Anthropic and OpenAI Governance Structures Risk Amoral Drift on AI Safety, Harvard Law Review Warns

What happened

A January 2026 article titled Amoral Drift in AI Corporate Governance, published in the Harvard Law Review, examines the corporate governance structures of OpenAI and Anthropic and concludes that both arrangements carry meaningful risk of eroding AI safety commitments as commercial pressures intensify. The analysis focuses in particular on Anthropic's charter, which grants safety-focused Class T trustees the authority to elect three of five board directors either after May 24, 2027, or once the company reaches $6 billion in cumulative investment. The authors argue that mechanisms designed to insulate safety objectives from profit motives are susceptible to gradual weakening over time, a process they label amoral drift. The article situates these concerns within a broader legal and regulatory debate about whether hybrid structures such as public benefit corporations, capped-profit models, and trustee-based oversight arrangements can withstand the sustained financial pressures of large-scale commercial AI deployment. OpenAI's governance crisis in late 2023 and its subsequent shift toward a conventional for-profit structure is cited as an early indicator that such arrangements can change rapidly.

Why it matters

  • ·Regulated industries such as financial services firms subject to SR 11-7 and health sector entities under FDA AI guidance face heightened regulatory exposure if a vendor's safety governance weakens without triggering a formal internal review, potentially leaving organizations reliant on commitments that are no longer enforceable.
  • ·Enterprise procurement and third-party risk teams that treat vendor-published safety commitments as static assurances may face operational disruption if governance changes at Anthropic or OpenAI alter the safety properties of deployed AI systems without advance notice.
  • ·Organizations that have not documented baseline governance structures for their AI vendors, including specific trigger conditions such as Anthropic's May 2027 director-election clause, may be unable to demonstrate due diligence to auditors or regulators if those structures subsequently change.

Governance controls affected

What to do now

  • Document the current governance structures of Anthropic and OpenAI as a vendor risk baseline, recording specific trigger conditions such as Anthropic's May 24, 2027 director-election threshold and the $6 billion cumulative investment trigger.
  • Review and update AI vendor contracts to include provisions requiring notification of material governance changes, board composition shifts, or amendments to published safety charters.
  • Establish a recurring monitoring process, at least semi-annual, to track governance amendments at frontier AI vendors as the May 2027 date approaches and as Anthropic nears the $6 billion investment threshold.
  • Reassess AI risk classifications for systems procured from Anthropic and OpenAI to reflect the possibility that vendor safety governance may weaken, and adjust human oversight and approval requirements accordingly.
  • Brief procurement, legal, and third-party risk stakeholders on the Harvard Law Review findings and incorporate amoral drift risk as a named category in vendor AI risk assessment templates.

What to watch next

Compliance teams should monitor Anthropic's board composition and any charter amendments as the company approaches the May 24, 2027 director-election trigger and the $6 billion cumulative investment threshold, both of which could materially alter the influence of safety-focused trustees. OpenAI's continued structural evolution toward a conventional for-profit model should also be tracked, as further changes could affect the enforceability of its published safety and use policies. Regulatory bodies in financial services and healthcare are likely to scrutinize vendor AI governance arrangements more closely in light of growing academic and legal commentary, so organizations in those sectors should anticipate updated guidance on third-party AI oversight obligations.

Stay ahead of stories like this

Get every US AI governance development like this one, plus the rest of the week's developments. Every Thursday.

Powered by Buttondown.

Related Coverage

Research2026-07-26

Algorithm Registries and Third-Party Audit Models from Smart City Governance Offer a Transferable Blueprint for Enterprise Transparency Programs

RAISEF AI published a case study examining responsible AI governance patterns in smart city and urban public-sector deployments, including algorithm registries, localized performance dashboards, and third-party audits of public-facing models. The study identifies these mechanisms as transferable to enterprise settings, where transparency and auditability obligations are increasing. It recommends structured disclosure processes that preserve sensitive implementation details while satisfying external accountability requirements.

Enforcement2026-07-30

Court Finds No Evidence Behind Trump's Anthropic 'Supply Chain Risk' Ban

A federal judge has found the Trump administration lacks sufficient evidence to justify designating Anthropic a supply chain risk and barring its technology from federal use. The dispute stems from stalled Department of Defense contract negotiations in which Anthropic objected to its AI being used for mass surveillance or lethal targeting. Judge Rita Lin is now weighing whether to convert her earlier temporary injunction into a permanent order.

Research2026-07-30

Structural LLM Vulnerability Demonstrated Across OpenAI, Anthropic, Alibaba, and DeepSeek Models, Undermining Training-Based Safety Controls

Researchers presenting at ICML have demonstrated that large language models cannot be made fully secure against a class of attack called 'chain-of-thought forgery,' because models identify instruction sources by text style rather than by structural role. Exploits successfully extracted dangerous information from models produced by OpenAI, Anthropic, Alibaba, and DeepSeek, including GPT-5 and GPT-5.4. Enterprise compliance teams that treat safety training as a sufficient guardrail for high-risk deployments must reassess that assumption.