# Frontier model safety and security framework

- **Record type**: Control
- **Kind**: Policy
- **Owner**: Head of AI safety
- **Frequency**: Annual
- **Duties served**: 9

## What the control achieves

Commits a developer of the most capable general-purpose models to a published, regularly reviewed description of how it identifies catastrophic and systemic risks, decides when a model is safe to train further or release, and protects model weights.

## How it is typically implemented

The developer writes and publishes a framework that sets capability thresholds of concern, the evaluations used to detect them, the mitigations that must be in place before crossing each threshold, the security measures for weights and infrastructure, and the internal governance that makes go or no-go decisions. Training compute is tracked against regulatory thresholds so that notification duties are met on time. The framework is reviewed at least annually and after significant capability jumps or incidents, changes are recorded in a version log, and summaries of evaluations and mitigations are shared with authorities and downstream providers as required.

## Evidence it produces

- Published frontier safety framework (policy_document): Capability thresholds, evaluations, mitigations, security measures and governance, with a version log.
- Dangerous-capability evaluation report (evaluation_report)
- Threshold notification to an authority (regulatory_filing)
- Training compute tracking record (register_entry)

## Legal duties this control serves

- Manage systemic risk for high-impact general-purpose models — EU AI Act, European Union (satisfies): https://aipolicytracker.org/obligations/eu-ai-act-gpai-systemic-risk
- Providers of GPAI models must notify the Commission within two weeks of meeting the systemic-risk threshold — EU AI Act, European Union (satisfies): https://aipolicytracker.org/obligations/eu-ai-act-art-52-systemic-risk-notification
- Providers of systemic-risk GPAI models must track and report serious incidents to the AI Office — EU AI Act, European Union (supports): https://aipolicytracker.org/obligations/eu-ai-act-art-55-systemic-risk-incident-reporting
- Providers of systemic-risk GPAI models must secure the model and its infrastructure — EU AI Act, European Union (supports): https://aipolicytracker.org/obligations/eu-ai-act-art-55-systemic-risk-cybersecurity
- Operators of AI above the compute threshold must run lifecycle risk management and report safety results — Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust, South Korea (satisfies): https://aipolicytracker.org/obligations/south-korea-ai-basic-act-art-32-safety-measures-for-high-performance-ai
- Large frontier developers must publish a frontier AI framework — California SB 53, California (United States) (satisfies): https://aipolicytracker.org/obligations/us-california-sb-53-frontier-ai-framework
- Report critical safety incidents to the Office of Emergency Services — California SB 53, California (United States) (supports): https://aipolicytracker.org/obligations/us-california-sb-53-critical-safety-incident-reporting
- Frontier developers must publish a transparency report before deploying a new frontier model — California SB 53, California (United States) (supports): https://aipolicytracker.org/obligations/us-california-sb-53-transparency-report
- Large frontier developers must send periodic summaries of catastrophic-risk assessments to the state — California SB 53, California (United States) (satisfies): https://aipolicytracker.org/obligations/us-california-sb-53-catastrophic-risk-assessment-summaries

## Standards clauses it corresponds to (clause numbers only)

- NIST AI RMF 1.0: GOVERN 1.3, 1.4; MAP 5.1; MEASURE 2.6; MANAGE 1.3
- ISO/IEC 42001:2023: Clause 5.2, 6.1.2; Annex A.6.1.2
- MITRE ATLAS: AML.M0001 Limit Model Artifact Release, AML.M0005 Control Access to ML Models and Data at Rest

## MIT AI Risk Repository subdomains addressed

7.2, 7.1, 4.2, 6.1

## Provenance

- **Record page**: https://aipolicytracker.org/controls/frontier-model-safety-framework
- **Official source**: none recorded — this record is incomplete, see https://aipolicytracker.org/gaps
- **Review status**: pending review
- **Confidence**: medium
- **Facts last confirmed**: never confirmed against the official source
- **Retrieved**: 2026-09-24
- **Licence**: https://creativecommons.org/licenses/by/4.0/

> This record is a structured summary with a link to the official text. It is not legal advice. Open the official source before relying on any date or duty. How current each record type must be is published at https://aipolicytracker.org/verification; what a record must carry at all is published at https://aipolicytracker.org/coverage.
