Frontier AI Safety Framework and Transparency Report
In brief
The Frontier AI Safety Framework and Transparency Report is a free DOCX and XLSX kit for EU AI Act. For developers of the most capable models: an outline of a published safety framework and a model transparency report, a capability-threshold sheet, a safety incident log and the frontier-model duties on record.
- Format
- DOCX and XLSX · Kit
- Version
- v1, built 5 Oct 2026
- Duties cited
- 10 from 5 instruments
- Rows from the records
- 13
- Frameworks
- EU AI Act
- Written for
- General-purpose AI model provider, Provider / developer, Deployer / user organisation
- Price and licence
- Free · CC BY 4.0
What's inside
- Risk thresholds sheet for four catastrophic-risk areas
- Critical safety incident log
- Document: framework, transparency report and whistleblower sections
- Frontier model duties across jurisdictions
Preview
The sheets and sections of version v1, as built. Columns marked ▾ have a dropdown; ƒ is a formula.
Sheet: Risk thresholds
| Catastrophic or severe risk area | Capability threshold | Evaluation used | Latest result | Mitigation required at threshold | Assessed |
|---|---|---|---|---|---|
| Chemical, biological, radiological or nuclear uplift | |||||
| Cyber offence | |||||
| Loss of control or autonomous replication | |||||
| Large-scale manipulation or deception |
The risk areas the framework covers, the capability level that triggers extra safeguards, and how each is tested.
Sheet: Safety incidents
| ID | Discovered | Model | What happened | Critical safety incident ▾ | Reported to authority on | Actions taken |
|---|---|---|---|---|---|---|
| Rows are yours to fill; the dropdowns, formulas and colour rules are already in place. | ||||||
Every safety incident with a frontier model, and whether and when it was reported.
Sheet: Frontier model duties
| Duty | Category | Instrument | Jurisdiction | Who it binds | Nature | Source reference | Applies from | What it requires | Evidence a reviewer expects | ISO/IEC 42001 | NIST AI RMF | Verification | Record |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Large frontier developers must publish a frontier AI framework | Safety testing and evaluation | California SB 53 | California (United States) | General-purpose AI model provider | Legal requirement | Business and Professions Code, Chapter 25.1 (as added by SB 53) | 2026-01-01 | Large frontier developers must publish and maintain a framework describing how they incorporate national and international standards, assess catastrophic risk, | Published frontier AI framework | GOVERN 1.x; NIST AI 600-1 | Source-linked | https://aipolicytracker.org/obligations/us-california-sb-53-frontier-ai-framework | |
| Report critical safety incidents to the Office of Emergency Services | Incident reporting and handling | California SB 53 | California (United States) | General-purpose AI model provider, Provider / developer | Legal requirement | Business and Professions Code, Chapter 25.1 (as added by SB 53) | 2026-01-01 | Frontier developers must report critical safety incidents to the California Office of Emergency Services within the statutory time limit after discovery, and th | Incident classification and reporting procedure | MANAGE 4.3 | Source-linked | https://aipolicytracker.org/obligations/us-california-sb-53-critical-safety-incident-reporting | |
| Frontier developers must publish a transparency report before deploying a new frontier model | Transparency and disclosure | California SB 53 | California (United States) | General-purpose AI model provider, Provider / developer | Legal requirement | Business and Professions Code Section 22757.12 (as added by SB 53) | 2026-01-01 | Before or at the time a frontier developer deploys a new frontier model, or a substantially modified version, it must publish a transparency report on its websi | Published model transparency report; Redaction justification log | Annex A.8.2, A.8.3 | GOVERN 4.2, MAP 5.1, MEASURE 2.6 | Verified against the official source 26 Sep 2026 | https://aipolicytracker.org/obligations/us-california-sb-53-transparency-report |
| Large frontier developers must send periodic summaries of catastrophic-risk assessments to the state | Safety testing and evaluation | California SB 53 | California (United States) | General-purpose AI model provider | Legal requirement | Business and Professions Code Section 22757.12 (as added by SB 53) | 2026-01-01 | A large frontier developer must transmit to the California Office of Emergency Services, on the periodic schedule the statute sets, a summary of any assessment | Internal-use catastrophic risk assessment summary sent to the Office of Emergency Services | Clause 9.1; Annex A.8.3 | MEASURE 2.6, MANAGE 1.2, GOVERN 4.3 | Verified against the official source 26 Sep 2026 | https://aipolicytracker.org/obligations/us-california-sb-53-catastrophic-risk-assessment-summaries |
| Manage systemic risk for high-impact general-purpose models | Safety testing and evaluation | EU AI Act | European Union | General-purpose AI model provider | Legal requirement | Articles 51, 52 and 55 | 2025-08-02 | A general-purpose model is presumed to have systemic risk when the cumulative compute used for training exceeds 10^25 floating-point operations, or when the Com | Model evaluation and red-teaming reports; Commission notification record | MEASURE 2.x; NIST AI 600-1 | Source-linked | https://aipolicytracker.org/obligations/eu-ai-act-gpai-systemic-risk | |
| Providers of GPAI models must notify the Commission within two weeks of meeting the systemic-risk threshold | Governance and accountability | EU AI Act | European Union | General-purpose AI model provider | Legal requirement | Article 52(1) | 2025-08-02 | A provider whose general-purpose AI model meets the Article 51(1)(a) high-impact capability condition, which is presumed once cumulative training compute exceed | Training compute tracking record; Notification to the Commission | Clause 4.2; Annex A.8.3 | GOVERN 1.1, MAP 1.1 | Verified against the official source 26 Sep 2026 | https://aipolicytracker.org/obligations/eu-ai-act-art-52-systemic-risk-notification |
The recorded duties served by a frontier model safety framework, across every jurisdiction on record.
Document outline (DOCX)
- Frontier AI safety framework and transparency report
- Framework
- Transparency report for a new model
- Whistleblower channel
- Duties on record
- Large frontier developers must publish a frontier AI framework
- Report critical safety incidents to the Office of Emergency Services
- Frontier developers must publish a transparency report before deploying a new frontier model
- Large frontier developers must send periodic summaries of catastrophic-risk assessments to the state
- Manage systemic risk for high-impact general-purpose models
- Providers of GPAI models must notify the Commission within two weeks of meeting the systemic-risk threshold
- Providers of systemic-risk GPAI models must track and report serious incidents to the AI Office
- Providers of systemic-risk GPAI models must secure the model and its infrastructure
- Operators of AI above the compute threshold must run lifecycle risk management and report safety results
How to use it
- 1Request the files. Enter your name, company and work email in the form on this page. The DOCX and XLSX download links arrive by email and work for 7 days.
- 2Read the README page. It states the version (v1), the dataset it was built from and the licence, so anyone reviewing your copy knows which records it reflects.
- 3Fill in your rows. Complete the "Risk thresholds" and "Safety incidents" sheets for your own systems. Dropdowns, formulas and colour rules are already set.
- 4Check the duties against your situation. The "Risk thresholds" and "Frontier model duties" sheets list the recorded duties with their source references. Mark which apply to you and follow each link to the official text.
- 5Complete the document. Work through the DOCX sections (Frontier AI safety framework and transparency report, Duties on record) and replace each placeholder with your organisation's answer.
- 6Keep the evidence and watch for new versions. Link each completed row to the evidence that supports it. When the law on record changes, this template gets a new version and a changelog on this page.
Duties this template covers (10)
Each is cited in the file with its source reference and a link back to the record.
- Large frontier developers must publish a frontier AI framework
- Report critical safety incidents to the Office of Emergency Services
- Large frontier developers must send periodic summaries of catastrophic-risk assessments to the state
- Manage systemic risk for high-impact general-purpose models
- Report serious incidents to market surveillance authorities
- Providers must take corrective action and inform the supply chain about non-conforming high-risk AI
- Providers of systemic-risk GPAI models must track and report serious incidents to the AI Office
- Implement reasonable security safeguards and notify breaches
- Operators of AI above the compute threshold must run lifecycle risk management and report safety results
- Measure and test trustworthiness characteristics (Measure)
Legal basis
Version history
| Version | Built | Dataset | What changed |
|---|---|---|---|
| v1 | c6967b988bb5 | First version, built from dataset c6967b988bb5. |
Only the latest version is served. A rebuild that changes the content adds a version; a rebuild that does not is skipped.
Frequently asked questions
What is in the Frontier AI Safety Framework and Transparency Report?
Risk thresholds sheet for four catastrophic-risk areas. Critical safety incident log. Document: framework, transparency report and whistleblower sections. Frontier model duties across jurisdictions.
Which duties does it cite?
10 recorded duties from California SB 53, EU AI Act, India DPDP Act and Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust, including Business and Professions Code, Chapter 25.1 (as added by SB 53), Business and Professions Code Section 22757.12 (as added by SB 53), Articles 51, 52 and 55, Article 73, Article 20 and Article 55(1)(c). Each row links to the record, and the record to the official source.
Who is it for?
The duties it cites fall on general-purpose ai model provider, provider / developer and deployer / user organisation. Whoever owns AI governance for those roles usually completes it, with the system owner supplying the facts.
Is it free?
Yes. Request the DOCX and XLSX with your work email on this page; the download links arrive by email, valid for 7 days. No account and no charge. Licensed CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.
How will I know when it changes?
Version v1 was built on 5 October 2026. The library is rebuilt daily; when a change to the records reaches this template it gets the next version, a changelog below and an entry in the templates feed.
Does completing it make us compliant?
No. It is an informational resource, not legal advice; it helps produce the evidence a regulator, customer or auditor asks for. Whether a duty applies to you is a judgement the template cannot make.
Disclaimer: informational only, not legal advice. Verify every claim against the linked official sources and consult a qualified lawyer before acting.