Frontier model safety and security framework
Commits a developer of the most capable general-purpose models to a published, regularly reviewed description of how it identifies catastrophic and systemic risks, decides when a model is safe to train further or release, and protects model weights.
- Duties satisfied
- 5
- done properly, does the work
- Duties supported
- 4
- contributes; the duty needs more
- Jurisdictions
- 3
- Evidence items
- 4
How is it implemented?
The developer writes and publishes a framework that sets capability thresholds of concern, the evaluations used to detect them, the mitigations that must be in place before crossing each threshold, the security measures for weights and infrastructure, and the internal governance that makes go or no-go decisions. Training compute is tracked against regulatory thresholds so that notification duties are met on time. The framework is reviewed at least annually and after significant capability jumps or incidents, changes are recorded in a version log, and summaries of evaluations and mitigations are shared with authorities and downstream providers as required.
Which legal duties does it serve?
Satisfies means the control, operated properly, does the work the duty asks for. Supports means it contributes but the duty needs more. The official text decides; open it before relying on either.
California (United States) 4 duties
-
satisfies Legal requirement confidence highLarge frontier developers must publish a frontier AI framework
California SB 53 · Business and Professions Code, Chapter 25.1 (as added by SB 53) · applies from 1 Jan 2026
The published, annually reviewed framework with a change log.
-
satisfies Legal requirementLarge frontier developers must send periodic summaries of catastrophic-risk assessments to the state
California SB 53 · Business and Professions Code Section 22757.12 (as added by SB 53) · applies from 1 Jan 2026
Framework defines the catastrophic-risk assessment whose summaries are submitted.
-
supports Legal requirementReport critical safety incidents to the Office of Emergency Services
California SB 53 · Business and Professions Code, Chapter 25.1 (as added by SB 53) · applies from 1 Jan 2026
Defines the incident types the framework is meant to prevent.
-
supports Legal requirementFrontier developers must publish a transparency report before deploying a new frontier model
California SB 53 · Business and Professions Code Section 22757.12 (as added by SB 53) · applies from 1 Jan 2026
Report describes steps taken under the framework.
European Union 4 duties
-
satisfies Legal requirementManage systemic risk for high-impact general-purpose models
EU AI Act · Articles 51, 52 and 55 · applies from 2 Aug 2025
Compute tracking, notification and the safety and security framework.
-
satisfies Legal requirement confidence highProviders of GPAI models must notify the Commission within two weeks of meeting the systemic-risk threshold
EU AI Act · Article 52(1) · applies from 2 Aug 2025
Compute tracking and threshold notification are part of the framework.
-
supports Legal requirementProviders of systemic-risk GPAI models must track and report serious incidents to the AI Office
EU AI Act · Article 55(1)(c) · applies from 2 Aug 2025
Framework defines the incident types and escalation.
-
supports Legal requirement confidence highProviders of systemic-risk GPAI models must secure the model and its infrastructure
EU AI Act · Article 55(1)(d) · applies from 2 Aug 2025
Framework commits to the weight-security measures.
South Korea 1 duty
-
satisfies Legal requirementOperators of AI above the compute threshold must run lifecycle risk management and report safety results
Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · Article 32 · applies from 22 Jan 2026
Compute tracking, lifecycle risk assessment and reporting to the authority.
What evidence shows it is operating?
| Evidence | Type | What it shows |
|---|---|---|
| Published frontier safety framework | Policy document | Capability thresholds, evaluations, mitigations, security measures and governance, with a version log. |
| Dangerous-capability evaluation report | Evaluation or test report | |
| Threshold notification to an authority | Regulatory filing or notification | |
| Training compute tracking record | Register entry |
Owner: Head of AI safety. Frequency: annual.
Which risks does it address?
Subdomains of the MIT AI Risk Repository, with the incidents the AI Incident Database has recorded under each. Counts are live; they say how often a risk has materialised, not how well this control prevents it.
- 7.2 AI possessing dangerous capabilities AI system safety, failures, & limitations0 incidents · 78 risk entries
- 7.1 AI pursuing its own goals in conflict with human goals or values AI system safety, failures, & limitations3 incidents · 100 risk entries
- 4.2 Cyberattacks, weapon development or use, and mass harm Malicious actors15 incidents · 82 risk entries
- 6.1 Power centralization and unfair distribution of benefits Socioeconomic & Environmental6 incidents · 54 risk entries
Which standards clauses does it correspond to?
Clause numbers only. A reference means the standard asks for overlapping work, so evidence may be reusable; it never means the standard discharges a legal duty.
| Framework | Reference | Note | Confidence |
|---|---|---|---|
| NIST AI RMF | GOVERN 1.3, 1.4; MAP 5.1; MEASURE 2.6; MANAGE 1.3 | medium | |
| ISO/IEC 42001 | Clause 5.2, 6.1.2; Annex A.6.1.2 | low | |
| MITRE ATLAS | AML.M0001 Limit Model Artifact Release, AML.M0005 Control Access to ML Models and Data at Rest | medium |
Cite this record
AIPolicyTracker (2026). “Frontier model safety and security framework”. https://aipolicytracker.org/controls/frontier-model-safety-framework (accessed 24 September 2026). Data licensed CC BY 4.0.
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.
Frequently asked questions
- Which legal duties does "Frontier model safety and security framework" satisfy?
- It is recorded as satisfying 5 and supporting 4 duties across California (United States), European Union and South Korea. A mapping means the control, operated properly, does the work the duty asks for; the official text decides whether it is enough.
- What evidence shows this control is operating?
- Published frontier safety framework, Dangerous-capability evaluation report, Threshold notification to an authority and Training compute tracking record. Owner: Head of AI safety. Frequency: annual.