AIPolicyTracker
Policy Owner: Head of AI safety Annual

Frontier model safety and security framework

Commits a developer of the most capable general-purpose models to a published, regularly reviewed description of how it identifies catastrophic and systemic risks, decides when a model is safe to train further or release, and protects model weights.

Duties satisfied
5
done properly, does the work
Duties supported
4
contributes; the duty needs more
Jurisdictions
3
Evidence items
4

How is it implemented?

The developer writes and publishes a framework that sets capability thresholds of concern, the evaluations used to detect them, the mitigations that must be in place before crossing each threshold, the security measures for weights and infrastructure, and the internal governance that makes go or no-go decisions. Training compute is tracked against regulatory thresholds so that notification duties are met on time. The framework is reviewed at least annually and after significant capability jumps or incidents, changes are recorded in a version log, and summaries of evaluations and mitigations are shared with authorities and downstream providers as required.

Which legal duties does it serve?

Satisfies means the control, operated properly, does the work the duty asks for. Supports means it contributes but the duty needs more. The official text decides; open it before relying on either.

California (United States) 4 duties

European Union 4 duties

South Korea 1 duty

What evidence shows it is operating?

Evidence this control produces
EvidenceTypeWhat it shows
Published frontier safety frameworkPolicy documentCapability thresholds, evaluations, mitigations, security measures and governance, with a version log.
Dangerous-capability evaluation reportEvaluation or test report
Threshold notification to an authorityRegulatory filing or notification
Training compute tracking recordRegister entry

Owner: Head of AI safety. Frequency: annual.

Which risks does it address?

Subdomains of the MIT AI Risk Repository, with the incidents the AI Incident Database has recorded under each. Counts are live; they say how often a risk has materialised, not how well this control prevents it.

Which standards clauses does it correspond to?

Clause numbers only. A reference means the standard asks for overlapping work, so evidence may be reusable; it never means the standard discharges a legal duty.

Framework references
FrameworkReferenceNoteConfidence
NIST AI RMFGOVERN 1.3, 1.4; MAP 5.1; MEASURE 2.6; MANAGE 1.3medium
ISO/IEC 42001Clause 5.2, 6.1.2; Annex A.6.1.2low
MITRE ATLASAML.M0001 Limit Model Artifact Release, AML.M0005 Control Access to ML Models and Data at Restmedium

Cite this record

AIPolicyTracker (2026). “Frontier model safety and security framework”. https://aipolicytracker.org/controls/frontier-model-safety-framework (accessed 24 September 2026). Data licensed CC BY 4.0.

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.

Frequently asked questions

Which legal duties does "Frontier model safety and security framework" satisfy?
It is recorded as satisfying 5 and supporting 4 duties across California (United States), European Union and South Korea. A mapping means the control, operated properly, does the work the duty asks for; the official text decides whether it is enough.
What evidence shows this control is operating?
Published frontier safety framework, Dangerous-capability evaluation report, Threshold notification to an authority and Training compute tracking record. Owner: Head of AI safety. Frequency: annual.