Jason Clinton
inaugural CISO, now Deputy CISO (Anthropic)
Roles and dates
Compiled from the sources listed at the foot of this page. Where a date is unconfirmed in the public record, the entry says so.
- Security engineering roles, latterly leading Chrome infrastructure security against advanced persistent threatsGooglec. late 2011 – early 2023 (approximately 11.5 years)
- Inaugural Chief Information Security OfficerAnthropicApril 2023 – September 2025
- Deputy Chief Information Security OfficerAnthropicfrom September/October 2025
Situation and mandate
FACT Clinton spent about eleven and a half years at Google, most recently leading Chrome infrastructure security against advanced persistent threats, with earlier work on ChromeOS build integrity and Android Pay security [10][11][15]. He joined Anthropic in April 2023 as the company's inaugural Chief Information Security Officer [10][15], with a stated remit spanning detection and response, compliance, physical security, security engineering and IT, plus the security organization's implementation of Anthropic's Responsible Scaling Policy [15]. In September 2025 Anthropic hired Vitaly Gudanets — previously the cybersecurity lead at Netflix — as Chief Information Security Officer, with Clinton moving to Deputy CISO [9]. His current bios on the RSAC, SANS and Anthropic/Claude channels read "Deputy CISO, Anthropic" [4][10][11].
This profile contains no outcome evidence, and it cannot. Anthropic is a private company. Whether it has suffered any incident or weight compromise, the size and budget of its security organization, its detection and response metrics, red-team results, insider-risk case volume and the findings behind its certifications are all unobservable from outside [15]. What follows is a record of inputs: stated threat models, named control mechanisms, published decision frameworks. It is here precisely because it is a pure inputs case — the honest limit of what an outsider can learn about a security leader at a private company.
Documented decisions
1. He left an established security organization for an inaugural security chair at a frontier AI lab. Roughly eleven and a half years at Google, then Anthropic's first CISO in April 2023 [10][15]. INTERPRETATION A first-ever security chair differs from succeeding into one: no inherited program to defend and no inherited baseline — which is also why the record has no before-and-after.
2. He organized his own time around a single asset. In VentureBeat, 15 December 2023, then titled Chief Information Security Officer: "I probably spend almost half of my time as a CISO thinking about protecting that one file" — the model-weights file — because "if an attacker got access to the entire file, that's the entire neural network," and weights are "the thing that gets the most attention and prioritization in the organization, and it's where we're putting the most amount of security resources" [1].
3. He stated the threat model in denial terms rather than intellectual-property terms. In the same interview the concern is preventing criminals, terrorists and states from obtaining a powerful model, not protecting a commercial asset [1]. INTERPRETATION A consequential framing decision: it makes the program answerable to a public-harm objective rather than a revenue-loss one, which changes what counts as acceptable residual risk.
4. The program's mechanisms were published. Anthropic's "Activating AI Safety Level 3 Protections" (May 2025) is a company document, not a personal statement, but it records the controls his organization implemented [2]. Named mechanisms include two-party control — "any employee needing access to model weights must authenticate with a physical security key, provide a justification, and obtain authorization from a second party at the time of the request," with automatic timeout; egress bandwidth controls, which "restrict the flow of data out of secure computing environments where AI model weights reside" so that exfiltration is detectable before it completes; binary allowlisting; change management for weight-bearing repositories including mandatory cryptographic commit signatures; hardware-key MFA; role-based least privilege; segmentation and encryption; and centralized logging with intrusion detection [2][15].
5. The controls were published with their limits attached. The same document scopes the ASL-3 Security Standard to a named adversary list — "hacktivists, criminal hacker groups, organized cybercrime groups, terrorist organizations, corporate espionage teams, internal employees, and state-sponsored programs that use broad-based and non-targeted techniques" — and explicitly places out of scope sophisticated state-sponsored attackers using novel attack chains, and non-state groups with state-level resources [2]. Anthropic's Responsible Scaling Policy v3.0 (24 February 2026) records ASL-3 activation in May 2025 and cites a RAND assessment that weight security at the SL5 level is "currently not possible" and "will likely require assistance from the national security community" [3]. INTERPRETATION Publishing a control set together with the class of attacker it does not stop is the most transferable act in this profile, and the rarest.
6. He authored a public decision procedure for agentic AI. "CISO's guide to agentic AI" (claude.com, 17 July 2026), bylined "Jason Clinton, Deputy CISO, Anthropic," sets a governing thesis — "A CISO's responsibility in the age of agentic AI is not to achieve zero risk. Instead, our jobs are to make agentic risk legible and bounded" — and a four-question model: "What untrusted content does it ingest? What actions can it take, and on whose behalf? What is the blast radius if it is misaligned? What observability do I have?" [4]. It states least agency — "grant the narrowest capability that still completes the task" — and admin-paced rollout: "enable a small group, watch the telemetry, and then expand access" [4]. Seven controls follow: IdP identity, connector allowlists as data boundaries, per-tool and per-action approvals, sandboxed execution, egress allowlisting against prompt injection, OpenTelemetry to the SIEM, and an organization-wide off switch [4]. Same material as an Anthropic webinar, 12 May 2026 [5].
7. He made a dated, falsifiable public forecast — and it was publicly scored as wrong. On 22 April 2025, then titled Chief Information Security Officer, he told Axios that Anthropic expected AI-powered "virtual employees" — with their own memories, roles and corporate credentials — to begin operating on corporate networks within roughly a year, naming the unsolved problems as securing those accounts, deciding their network access, and accountability: "In that world, there are so many problems that we haven't solved yet from a security perspective that we need to solve" [6][7]. One year on, on 4 May 2026, John Gruber wrote that the prediction "has fallen flat on its face," argued "this isn't how companies are using AI — or at least they shouldn't," and characterized the original piece as "an advertisement" rather than a security warning [8].
8. Third-party assurance was pursued and published. Anthropic operates a Trust Center [13] and states it holds SOC 2 Type I and Type II, ISO/IEC 27001:2022 and ISO/IEC 42001:2023, with a HIPAA-ready configuration [12]. Process conformance, not outcomes.
Reported results
There are none. This section exists to say so.
No security outcome of any kind is in the public record: no incident history, no breach or non-breach, no detection or response metric, no red-team result, no budget, no headcount, no audit finding [15]. Anthropic reports that ASL-3 safeguards were activated in May 2025 [3] and holds the certifications above [12] — process statements the company makes about itself, not outcomes.
Recognition is speaker- and platform-based rather than award-based: repeat RSAC contributor, SANS external contributor, co-author of an IT Revolution guidance paper [10][11][15]. Awards are not evidence, and here there are barely any to discount.
INTERPRETATION A reader who finishes this profile feeling they know whether the program works has misread it. A well-argued set of inputs produces a strong impression of effectiveness; the impression is not evidence, and noticing that is the point of the profile.
What is contested or thinly documented
The title. The present-tense phrase "Anthropic's CISO" is no longer correct for him and must not be used. April 2023 to approximately September 2025 was his CISO tenure; he is Deputy CISO, and Vitaly Gudanets is CISO [9][15]. Some aggregators still carry the old title.
The transition is unexplained. No public source states why the first CISO became Deputy CISO — scope change, planned scaling hire, or something else [15]. Do not construct a narrative from silence. INTERPRETATION The structural observation that is available is worth more than the missing story: the security chair gets re-scoped as a company scales, and the first CISO is not necessarily the CISO at scale.
Program design is not personally apportioned. The ASL-3 controls are Anthropic's. He led the organization that implemented them; no public source assigns specific design decisions to him [2][15].
The prediction. Dated, attributed, falsifiable, publicly scored as having missed [8]. Treat it as a calibration case, not a character verdict — and separate the second charge from the first: that a security warning issued through a company's own channel may function as marketing [8]. Both matter to any CISO who speaks publicly for a vendor.
One widely circulated quotation is excluded. A 2026 quotation about open-weight capability timelines circulates on social platforms but could not be traced to a primary venue; it is not used anywhere in this curriculum [15].
He is not the company's witness to government. When the House Committee on Homeland Security requested testimony in November 2025, it wrote to CEO Dario Amodei [14].
What it teaches
Trait Dial (INTERPRETATION, inferred from the decisions above)
INTERPRETATION— inferred from documented decisions and published mechanisms only.
Aggression ↔ caution: split by asset, which is the lesson. Maximum caution on model weights — two-party control, egress limits, binary allowlisting (decisions 2, 4) — and a deliberately permissive posture on agentic adoption, bounded rather than blocked (decision 6). One executive, two settings, chosen per asset rather than per personality.
Decisiveness ↔ inquiry: toward inquiry, formalized. The four questions are an inquiry procedure written down so others can run it without him.
Hands-on ↔ delegation: unusually hands-on for the chair. "Almost half of my time" on one asset is a personal allocation statement from an executive (decision 2). INTERPRETATION Defensible where one asset dominates the loss function; a Player-level habit in an otherwise Architect-level chair, and worth naming as a risk rather than a virtue.
Urgency ↔ patience: toward patience on rollout, with a telemetry trigger (decision 6).
Overlays. Control ↔ Enablement: hard control on the crown jewel, enablement everywhere else — "legible and bounded," not zero-risk. Prevention ↔ Resilience: egress bandwidth control is a resilience-flavoured prevention control, accepting that an attempt may start and designed to make completion detectable.
Maturity Model
FRAMEWORK The record illustrates Level 3 — Maturity on one behaviour: accurate self-assessment stated in public. Publishing a control set alongside the class of adversary it does not defeat, and citing an assessment that a higher security level is "currently not possible" (decision 5), is the institutional form of "I cannot do this yet." Very few programs publish their own ceiling. The level the record cannot illustrate is Level 2 — Capability in the outcome sense, which is judged by results, and there are none.
Fit
Reporting line: undisclosed — a useful reminder of how much of the structure that sets a security leader's discretion is invisible from outside.
Regulator. No binding sector regulator in the sense that FINRA or OCR is binding. The substitutes are a self-imposed policy regime (the Responsible Scaling Policy, with published safeguard activation) and customer assurance (SOC 2, ISO 27001, ISO 42001, the Trust Center) [3][12][13]. INTERPRETATION The Governance term of the Fit Equation is filled largely by commitments the company wrote itself — stronger than nothing, weaker than an examiner.
Stage. A hypergrowth private company scaling past its first security chair — the clearest illustration that stage re-scopes the role, not just the workload.
Information environment
For an outsider the information environment is the published document, and this profile is an exercise in noticing how much a well-built document does not tell you. For the practitioner the transferable mechanisms sit inside decision 6: telemetry as the trigger for expanding access, per-action approvals as ground truth about what agents do, and an organization-wide off switch as the precondition for saying yes at all. Each is an information mechanism before it is a control.
Two-Sentence Test and the Risk Corollary
The agentic guide is the Risk Corollary in written form. "Make agentic risk legible and bounded" is "Yes — and here is the risk we are accepting, priced," and the four questions are how you produce the price [4]. Least agency is the other half — "No — and here is what would change my answer": the narrowest capability now, widened when the telemetry says so.
The second sentence of the Two-Sentence Test is where the 2025 prediction earns its place. INTERPRETATION A dated public forecast that missed is not a failure of security leadership; it is an ordinary cost of speaking publicly, and the teaching value is entirely in what comes next. "I was wrong about the timeline, and here is what I now think and why" converts a missed forecast into calibration evidence; quietly dropping the subject converts it into a reason nobody believes the next one. Nothing public settles which happened — the last unobservable in a profile made of them.
Discussion questions
- Write in one sentence what you believed about this program after reading the decisions section, then write what evidence would actually support that belief. How large is the gap?
- Decision 5 publishes the class of attacker the controls do not stop. What is the equivalent sentence for your program, and what would it cost to say it to your board?
- "Almost half my time on one file" is a concentration decision. What is your one file — and does your calendar agree?
- Run the four questions against one agent or automation already live in your environment. Which question have you no answer to?
- Design the mechanism — not the intention — that would force you to score your own predictions in public a year later. Would you install it?
Sources
- VentureBeat, "Why Anthropic and OpenAI are obsessed with securing LLM model weights," 15 December 2023 — https://venturebeat.com/ai/why-anthropic-and-openai-are-obsessed-with-securing-llm-model-weights (quotations verified 2026)
- Anthropic, "Activating AI Safety Level 3 Protections," May 2025 (PDF) — https://www-cdn.anthropic.com/807c59454757214bfd37592d6e048079cd7a7728.pdf (primary, company; control descriptions and threat-actor scoping verified 2026)
- Anthropic, "Responsible Scaling Policy Version 3.0," 24 February 2026 — https://www.anthropic.com/news/responsible-scaling-policy-v3 (primary, company)
- Jason Clinton, "CISO's guide to agentic AI," claude.com blog, 17 July 2026 — https://claude.com/blog/ciso-guide-to-agentic-ai (primary, authored by the subject; byline, thesis, four questions, least agency, seven controls verified 2026)
- Anthropic, "Secure the Advantage: A CISO's Guide to Agentic AI" (webinar), 12 May 2026 — https://www.anthropic.com/webinars/secure-the-advantage-a-cisos-guide-to-agentic-ai
- Axios, "Exclusive: fully AI employees are a year away, Anthropic warns," 22 April 2025 — https://www.axios.com/2025/04/22/ai-anthropic-virtual-employees-security (quotations verified 2026)
- Fortune, "AI employees with 'memories' and company passwords are a year away, says Anthropic chief information security officer," 23 April 2025 — https://fortune.com/article/anthropic-jason-clinton-ai-employees-a-year-away/
- Daring Fireball, "Anthropic Executive, One Year Ago: Fully AI Employees Are a Year Away," 4 May 2026 — https://daringfireball.net/linked/2026/05/04/anthropic-prediction-fully-ai-employees (quotations verified 2026)
- The Stack, "Anthropic brings in new CISO, ramps up security hiring," 30 September 2025 — https://www.thestack.technology/anthropic-new-ciso-claude-cyber-attack/ (Gudanets as CISO; Clinton as deputy; verified 2026)
- SANS Institute, Jason Clinton profile (Deputy CISO; joined Anthropic April 2023 as inaugural CISO) — https://www.sans.org/profiles/jason-clinton
- RSAC Conference, Jason Clinton expert profile (Deputy CISO; Google Chrome infrastructure security) — https://www.rsaconference.com/experts/jason-clinton
- Anthropic Privacy Center, "What certifications has Anthropic obtained?" — https://privacy.claude.com/en/articles/10015870-what-certifications-has-anthropic-obtained
- Anthropic Trust Center — https://trust.anthropic.com/
- House Committee on Homeland Security, letter to Anthropic re request to testify, 26 November 2025 (PDF; addressed to Dario Amodei) — https://homeland.house.gov/wp-content/uploads/2025/11/2025-11-26-CHS-to-Anthropic-re-Request-to-Testify.pdf
research/leaders-addendum.md, §1 (compiled role history; the explicit list of what is not documented; the title correction; the excluded unverifiable quotation) — internal research document
Numbered references match the bracketed markers in the text above. Links open the primary source where one exists; internal research files are named as such.