AI Governance Institute logo
AI Governance Institute

Intelligence for Compliance and GRC Teams

← News
Research2026-04-19

Anthropic and OpenAI Governance Structures Risk Amoral Drift on AI Safety, Harvard Law Review Warns

What happened

A January 2026 article titled Amoral Drift in AI Corporate Governance, published in the Harvard Law Review, examines the corporate governance structures of OpenAI and Anthropic and concludes that both arrangements carry meaningful risk of eroding AI safety commitments as commercial pressures intensify. The analysis focuses in particular on Anthropic's charter, which grants safety-focused Class T trustees the authority to elect three of five board directors either after May 24, 2027, or once the company reaches $6 billion in cumulative investment. The authors argue that mechanisms designed to insulate safety objectives from profit motives are susceptible to gradual weakening over time, a process they label amoral drift. The article situates these concerns within a broader legal and regulatory debate about whether hybrid structures such as public benefit corporations, capped-profit models, and trustee-based oversight arrangements can withstand the sustained financial pressures of large-scale commercial AI deployment. OpenAI's governance crisis in late 2023 and its subsequent shift toward a conventional for-profit structure is cited as an early indicator that such arrangements can change rapidly.

Why it matters

  • ·Regulated industries such as financial services firms subject to SR 11-7 and health sector entities under FDA AI guidance face heightened regulatory exposure if a vendor's safety governance weakens without triggering a formal internal review, potentially leaving organizations reliant on commitments that are no longer enforceable.
  • ·Enterprise procurement and third-party risk teams that treat vendor-published safety commitments as static assurances may face operational disruption if governance changes at Anthropic or OpenAI alter the safety properties of deployed AI systems without advance notice.
  • ·Organizations that have not documented baseline governance structures for their AI vendors, including specific trigger conditions such as Anthropic's May 2027 director-election clause, may be unable to demonstrate due diligence to auditors or regulators if those structures subsequently change.

Governance controls affected

What to do now

  • Document the current governance structures of Anthropic and OpenAI as a vendor risk baseline, recording specific trigger conditions such as Anthropic's May 24, 2027 director-election threshold and the $6 billion cumulative investment trigger.
  • Review and update AI vendor contracts to include provisions requiring notification of material governance changes, board composition shifts, or amendments to published safety charters.
  • Establish a recurring monitoring process, at least semi-annual, to track governance amendments at frontier AI vendors as the May 2027 date approaches and as Anthropic nears the $6 billion investment threshold.
  • Reassess AI risk classifications for systems procured from Anthropic and OpenAI to reflect the possibility that vendor safety governance may weaken, and adjust human oversight and approval requirements accordingly.
  • Brief procurement, legal, and third-party risk stakeholders on the Harvard Law Review findings and incorporate amoral drift risk as a named category in vendor AI risk assessment templates.

What to watch next

Compliance teams should monitor Anthropic's board composition and any charter amendments as the company approaches the May 24, 2027 director-election trigger and the $6 billion cumulative investment threshold, both of which could materially alter the influence of safety-focused trustees. OpenAI's continued structural evolution toward a conventional for-profit model should also be tracked, as further changes could affect the enforceability of its published safety and use policies. Regulatory bodies in financial services and healthcare are likely to scrutinize vendor AI governance arrangements more closely in light of growing academic and legal commentary, so organizations in those sectors should anticipate updated guidance on third-party AI oversight obligations.

Stay ahead of stories like this

Get every US AI governance development like this one, plus the rest of the week's developments. Every Thursday.

Powered by Buttondown.

Related Coverage

Research2026-08-18

Vendor AI Usage Reports Systematically Filter Harmful Behavior, Study Finds

An independent research platform called the AI Observatory, led by researchers from Stanford and MIT, analyzed over 24,000 real AI conversations and found that usage reports published by major AI companies systematically exclude non-work-related interactions. The omission conceals materially higher rates of sensitive behaviors including harassment, hate speech, and adult content. Enterprise compliance programs that rely on vendor-published data for risk assessments are working from a structurally incomplete picture.

Corporate Policy2026-08-18

White House Finalizes Voluntary Frontier AI Safety Testing With Top Labs

The White House has finalized a voluntary safety testing program for advanced U.S. AI models, inviting Meta, Anthropic, Google, and OpenAI to participate in government-coordinated pre-release evaluations. The program covers national-security risk assessment and third-party model evaluation. While participation is voluntary, the framework establishes a de facto pre-deployment review baseline for frontier model developers.

Corporate Policy2026-08-12

Anthropic's 'Project Panama' Exposes Training Data Sourcing as a Supply-Chain Risk

Reports from rare booksellers and a 2025 lawsuit have revealed that Anthropic ran a covert program called 'Project Panama' under which millions of print books were purchased and destroyed to extract training data. The accounts raise concerns about deceptive procurement, irreplaceable cultural loss, and undisclosed data sourcing practices. Enterprise compliance teams that rely on commercially-licensed AI models now face heightened exposure across training data provenance, vendor due diligence, and IP risk programs.