What the frameworks are, and what moved
Anthropic, OpenAI, Google DeepMind, Meta, and xAI each publish a voluntary document that sets capability thresholds, evaluation commitments, and conditions for deployment. These are among the more developed self-governance instruments in any industry. They are also the operative constraint on frontier model release, since binding regulation is only now arriving.
Every one of these documents has been revised. Anthropic has published nine versions of its Responsible Scaling Policy since September 2023, four of them between February and July 2026. Google DeepMind is on version 3.1. Meta rewrote and renamed its framework in April 2026. The revisions carry information that the first drafts do not: what a company changed while operating under competitive and regulatory pressure describes its posture more precisely than what it wrote before shipping anything.
Four movements show up across the set.
- Pause language became conditional. Anthropic's version 3.0 dropped the general pause commitment and separated what it will do alone from what it recommends the industry adopt. Meta's Critical tier action changed from stop development to develop with mitigations.
- Competitor-conditional clauses spread. Anthropic, OpenAI, and Google DeepMind each hold a provision permitting relaxed safeguards if another developer proceeds without comparable ones. Meta holds no such clause in either version.
- Manipulation moved in three directions at once. OpenAI removed persuasion as a tracked category in April 2025. DeepMind added a harmful manipulation threshold in September 2025. Anthropic and Meta have never tracked it.
- Transparency machinery grew as commitments loosened. Named risk reports, external review rights, and board oversight all expanded in the same versions that softened the hard tripwires.
Until the EU AI Act's systemic-risk obligations take effect on 2 August 2026 and California's SB 53 disclosure regime matures, these documents are the primary published description of how a frontier developer decides whether a model is safe to release. They are the closest available proxy for operational risk discipline at companies whose valuations assume continued unrestricted deployment.
How the comparison was built
Primary documents were retrieved from company domains and content delivery networks, and cross-checked against the METR Frontier AI Safety Policies index for version numbers and dates. Secondary sources establish that a version exists or attribute named commentary. They are never presented as document text.
Each version is compared against its predecessor on the same nine dimensions, so the cross-company read is possible. Quotations are held under 15 words and attributed to document and version. Claims that could not be confirmed against a primary document were moved to the anomalies section rather than left asserted.
View data as a table
| Dimension | Name | Question it answers |
|---|---|---|
| D1 | Capability thresholds | What level of capability triggers a response, and on what measurement basis |
| D2 | Evaluation categories | Which risk domains are in scope |
| D3 | Commitment modality | The grammar of obligation: will, will provided that, intend to, aim to |
| D4 | Triggering and timing | When evaluations run relative to training and release |
| D5 | Response and mitigation | What happens once a threshold is crossed, and who judges sufficiency |
| D6 | Governance | Named decision authority, board involvement, escalation, reporting |
| D7 | Conditional withdrawal | Language releasing the company from commitments if competitors proceed |
| D8 | Security | Weights protection, insider threat, mapping to an external standard |
| D9 | Definitional scope | What counts as a covered model: compute floors, open weights, fine-tunes |
Twenty-eight versions, three years
The set below covers every published version located as of 18 July 2026. Retrieval status records whether the document itself was read, whether an archive capture stood in, or whether existence rests on an index entry.
View data as a table
| Company | Version | Date | Note |
|---|---|---|---|
| Anthropic | v1.0 | 19 Sep 2023 | First framework of its kind |
| Anthropic | v2.0 | 15 Oct 2024 | Restructured around capability thresholds |
| Anthropic | v2.1 | 31 Mar 2025 | State-programme CBRN threshold added |
| Anthropic | v2.2 | 14 May 2025 | Insider threat exclusion widened |
| Anthropic | v3.0 | 24 Feb 2026 | Rewrite. Pause commitment dropped |
| Anthropic | v3.1 | 2 Apr 2026 | Pausing retained as discretionary option |
| Anthropic | v3.2 | 29 Apr 2026 | Trust gains external review powers |
| Anthropic | v3.3 | 26 May 2026 | CB weapons threshold revised |
| Anthropic | v3.4 | 8 Jul 2026 | Risk report sharing set to 200 staff |
| OpenAI | Beta | 18 Dec 2023 | Four tracked categories |
| OpenAI | v2 | 15 Apr 2025 | Persuasion removed. Marginal-risk clause added |
| OpenAI | FGF | 28 May 2026 | Companion regulatory mapping document |
| Google DeepMind | v1.0 | 17 May 2024 | Critical Capability Levels introduced |
| Google DeepMind | v2.0 | 4 Feb 2025 | CCLs mapped to security levels |
| Google DeepMind | v3.0 | 22 Sep 2025 | Harmful manipulation CCL added |
| Google DeepMind | v3.1 | 17 Apr 2026 | Tracked Capability Levels added |
| Meta | v1.0 | 3 Feb 2025 | Uniquely enable standard. Stop development tier |
| Meta | v2.0 | 8 Apr 2026 | Renamed. Substantially contribute to standard |
| xAI | Draft | 20 Feb 2025 | Watermarked draft at the Seoul deadline |
| xAI | v1.0 | 20 Aug 2025 | MASK dishonesty criterion |
| xAI | v2.0 | 30 Dec 2025 | Renamed, two days before SB 53 in force |
| xAI | rev | 30 Jun 2026 | Quantitative criteria removed |
| Regulatory | Seoul commitments | May 2024 | 16 companies commit at the AI Seoul Summit |
| Regulatory | Paris summit | Feb 2025 | AI Action Summit |
| Regulatory | SB 53 signed | 29 Sep 2025 | California Transparency in Frontier AI Act |
| Regulatory | SB 53 in force | 1 Jan 2026 | Obligations commence |
| Regulatory | US executive order | 2 Jun 2026 | Voluntary pre-release government access framework |
Corpus table
| Company | Framework | Version | Date | Source | Status |
|---|---|---|---|---|---|
| Anthropic | Responsible Scaling Policy | v1.0 | 19 Sep 2023 | www-cdn.anthropic.com | Primary |
| Anthropic | RSP | v2.0 | 15 Oct 2024 | www-cdn.anthropic.com | Primary |
| Anthropic | RSP | v2.1 | 31 Mar 2025 | www-cdn.anthropic.com | Primary |
| Anthropic | RSP | v2.2 | 14 May 2025 | www-cdn.anthropic.com | Primary |
| Anthropic | RSP | v3.0 | 24 Feb 2026 | anthropic.com | Primary |
| Anthropic | RSP | v3.1 | 2 Apr 2026 | www-cdn.anthropic.com | Primary |
| Anthropic | RSP | v3.2 | 29 Apr 2026 | cdn.sanity.io | Primary |
| Anthropic | RSP | v3.3 | 26 May 2026 | cdn.sanity.io | Primary |
| Anthropic | RSP | v3.4 | 8 Jul 2026 | cdn.sanity.io | Current |
| OpenAI | Preparedness Framework | Beta | 18 Dec 2023 | cdn.openai.com | Primary |
| OpenAI | Preparedness Framework | v2 | 15 Apr 2025 | cdn.openai.com | Current |
| OpenAI | Frontier Governance Framework | 28 May 2026 | n/a | cdn.openai.com | Companion |
| Google DeepMind | Frontier Safety Framework | v1.0 | 17 May 2024 | storage.googleapis.com | Primary |
| Google DeepMind | FSF | v2.0 | 4 Feb 2025 | storage.googleapis.com | Primary |
| Google DeepMind | FSF | v3.0 | 22 Sep 2025 | storage.googleapis.com | Primary |
| Google DeepMind | FSF | v3.1 | 17 Apr 2026 | storage.googleapis.com | Current |
| Meta | Frontier AI Framework | v1.0 | 3 Feb 2025 | web.archive.org | Archive |
| Meta | Advanced AI Scaling Framework | v2.0 | 8 Apr 2026 | ai.meta.com | Current |
| xAI | Risk Management Framework | Draft | 20 Feb 2025 | data.x.ai | Primary |
| xAI | Risk Management Framework | v1.0 | 20 Aug 2025 | data.x.ai | Primary |
| xAI | Frontier AI Framework | v2.0 | 30 Dec 2025 | data.x.ai | Primary |
| xAI | Frontier AI Framework | rev. | 30 Jun 2026 | media.x.ai | Current |
| Microsoft | Frontier Governance Framework | v1.0 | Feb 2025 | microsoft.com | Primary |
| Microsoft | Frontier Governance Framework | update | Feb 2026 | microsoft.com | Diff open |
| Amazon | Frontier Model Safety Framework | v1.0 | 9 Feb 2025 | amazon.science | Primary |
| Nvidia | Frontier AI Risk Assessment | 17 Feb 2025 | n/a | images.nvidia.com | Index |
| Magic | AGI Readiness Policy | v1.0 | 2 Jul 2024 | magic.dev | Index |
| NAVER | AI Safety Framework | 7 Aug 2024 | n/a | clova.ai | Index |
| G42 | Frontier AI Safety Framework | 6 Feb 2025 | n/a | g42.ai | Index |
| Cohere | Secure AI Frontier Model Framework | 7 Feb 2025 | n/a | cohere.com | Index |
A page-count column was omitted. Counts could be confirmed for only 6 of the 30 entries, and a column that is mostly empty asserts less than it implies. The unresolved counts are recorded in the anomalies section. Amazon's document states 9 February 2025; the METR index labels it 10 February 2025.
Responsible Scaling Policy
The RSP was the first document of its kind, published September 2023. It sets AI Safety Levels, assessment procedures, and required safeguards, and governs decisions on training and deployment. Anthropic maintains a public changelog and publishes redline comparisons for point releases, a practice no other developer in the set matches.
Version history
Nine versions: v1.0 (19 September 2023), v2.0 (effective 15 October 2024), v2.1 (31 March 2025), v2.2 (14 May 2025), v3.0 (24 February 2026), v3.1 (2 April 2026), v3.2 (29 April 2026), v3.3 (26 May 2026), v3.4 (8 July 2026). Four revisions landed in roughly four months in 2026.
Diff by dimension
D3 · Commitment modality
Version 3.0 is the substantive shift in the entire corpus. Anthropic separates what it commits to unilaterally from what it recommends the industry adopt, and names the reason.
driven by a collective action problemRSP v3.0 announcement, February 2026
The most demanding measures now sit in a recommendations tier that Anthropic will strive to advance
but cannot commit to following ... unilaterally
. Frontier Safety Roadmap goals are described as nonbinding but publicly-declared
targets.
View data as a table
| Version | Tier | Contents |
|---|---|---|
| v2.x, to May 2025 | Unilateral commitments (single tier) | Required safeguards, with pause if the standard cannot be met |
| v3.x, from Feb 2026 | Industry-wide recommendations | RAND SL4 and the strongest measures. Nonbinding, publicly declared |
| v3.x, from Feb 2026 | Unilateral commitments | ASL-3 security, risk reports, trust oversight |
D5 · Response and mitigation commitments
The general pause commitment was dropped in v3.0. Version 3.1 then clarified that the option remains available without the obligation.
D4 · Triggering and timing
Version 3.0 extended the routine evaluation interval from three months to six. Anthropic acknowledges in the same document that its most recent evaluations were completed 3 days later
than the three-month interval, and that it identified instances where it fell short of meeting the full letter
of its requirements.
D8 · Security commitments
Anthropic continues to commit unilaterally to the ASL-3 security standard. The more demanding RAND Security Level 4, which addresses state-level weight theft, moved into the industry-wide recommendations tier. The v3.0 announcement describes RAND's SL5 as currently not possible
.
D6 · Governance and accountability
Governance expanded while substantive commitments loosened. Version 3.2 authorises the Long-Term Benefit Trust to request external review of Risk Reports, approve external reviewers, and receive regular briefings. Version 3.4 changed the internal disclosure requirement.
D1, D2, D7, D9 · In brief
- D1 thresholds. Version 3.0 reframes the AI research and development threshold around compressing
two years of 2018 - 2024 AI progress into a single year
. Version 3.1 clarified this means rate of progress, not researcher productivity. Versions 3.3 and 3.4 each revised a thresholdto better track the threat model of concern
. - D2 categories. Centred on CBRN and autonomous AI research and development. Cyber operations sits under ongoing assessment in v2.0 rather than as a committed threshold. No persuasion or manipulation category has appeared in any version.
- D7 conditional withdrawal. Version 3 relocates competitor provisions into an appendix titled Commitments Related to Competitors.
- D9 scope. Risk Reports cover all publicly deployed models and, where risk warrants, internal models.
Reading
The RSP moved from a document of pre-committed unilateral tripwires to one that distinguishes unilateral action from industry recommendation, paired with new transparency instruments and expanded trust oversight. Anthropic names the collective action problem as the driver and acknowledges past shortfalls against the letter of prior requirements. Whether the trade is favourable depends on whether the reporting and external review provisions bind as firmly in practice as the pause commitment they partly replaced.
Preparedness Framework
Published in beta on 18 December 2023 and revised once, on 15 April 2025. A separate Frontier Governance Framework followed on 28 May 2026, which OpenAI states does not replace the Preparedness Framework. Two full versions makes this the least-revised framework among the four primary subjects.
Diff by dimension
D1, D2 · Thresholds and categories
The beta used four tracked categories on a four-level scale, gating deployment at medium or below post-mitigation and halting development at critical. Version 2 collapsed the scale to two operative thresholds and reduced the tracked set to three categories.
View data as a table
| Beta category (Dec 2023) | Disposition in version 2 (Apr 2025) |
|---|---|
| Cybersecurity | Tracked. Carried forward unchanged |
| CBRN | Split. Biological and chemical remain tracked; nuclear and radiological move to a research tier |
| Model autonomy | Renamed and narrowed to AI self-improvement |
| Persuasion | Removed. Handled outside the Preparedness Framework |
do not fit the criteria for inclusionand are handled outside the Preparedness Framework.
Version 2 defines High capability as capability that could amplify existing pathways to severe harm
and Critical as capability that could introduce unprecedented new pathways to severe harm
. The biological and chemical High threshold is tied to meaningful counterfactual assistance to novice actors
.
D7 · Conditional withdrawal
Absent in the beta. Version 2 introduced a marginal-risk clause under which OpenAI may adjust our requirements
if another developer releases a high-risk system without comparable safeguards, provided it confirms the change does not net increase severe-harm risk, acknowledges the adjustment publicly, and keeps safeguards more protective
.
D3, D4, D5 · Modality, triggering, mitigation
Version 2 applies a five-part test to what qualifies as a tracked risk: risks must be plausible, measurable, severe, net new
and instantaneous or irremediable. It formalises Capabilities Reports and Safeguards Reports reviewed by the Safety Advisory Group, and states that reducing risk generally does not require reducing capability
. The beta's commitment to test fine-tuned versions of models was removed.
Shyam Krishna of RAND Europe told Fortune on 16 April 2025 that OpenAI appears to be shifting its approach
. Former OpenAI safety researcher Steven Adler wrote on X on 15 April 2025 that OpenAI is quietly reducing its safety commitments
, flagging the removal of the fine-tuned model testing requirement.
D6 · Governance
The beta gave the board the right to reverse leadership safety decisions, and version 2 preserves it: the Board may reverse a decision
and mandate a revised course of action. The Safety Advisory Group recommends to leadership, with the chief executive or a designee holding final authority.
Reading
Version 2 narrowed the tracked set from four categories to three, simplified four risk levels to two operative thresholds, and added an explicit conditional relaxation clause. OpenAI frames these as sharper focus and better measurability. The May 2026 Frontier Governance Framework is a compliance mapping layer to California SB 53 and the EU code of practice rather than a tightening of the underlying thresholds.
Frontier Safety Framework
Four versions since May 2024. The framework is built on Critical Capability Levels, thresholds at which a model could cause severe harm without mitigation, matched to recommended security levels and deployment mitigations. It is the most process-oriented document in the set, specifying what will be measured and reviewed more than what action follows.
Version history
v1.0 (17 May 2024), v2.0 (4 February 2025), v3.0 (22 September 2025), v3.1 (17 April 2026). The current document states Version 3.1 (April 17, 2026)
.
View data as a table
| Version | Date | Added in that version | Cumulative elements |
|---|---|---|---|
| v1.0 | May 2024 | Critical Capability Levels | 1 |
| v2.0 | Feb 2025 | Security level mapping, deceptive alignment | 3 |
| v3.0 | Sep 2025 | Harmful manipulation CCL, internal deployment safety cases | 5 |
| v3.1 | Apr 2026 | Tracked Capability Levels | 6 |
D2 · Evaluation categories
Version 3.0 added a Critical Capability Level for harmful manipulation, covering models with capabilities that could be misused to systematically and substantially change beliefs and behaviors
in identified high-stakes contexts. The 22 September 2025 announcement was authored by John Flynn, Helen King, and Anca Dragan.
D4, D6 · Triggering and governance
Evaluations run at a regular cadence and after a significant capability jump
. Version 3.0 extended safety case review to large-scale internal deployments, stating that for advanced machine learning research and development levels, large-scale internal deployments can also pose risk
. The framework commits to sharing model information, evaluation results, and mitigation plans with governments where a model reaches a level posing material risk. Review runs through internal bodies including the AGI Safety Council. As an Alphabet division, DeepMind has no independent board structure of its own.
D7 · Conditional withdrawal
Version 3.1 states that the social value of certain mitigations is significantly reduced if not broadly applied
, and that recommended security levels may be adjusted if our understanding of the risks changes
, for example where a model does not possess capabilities meaningfully different from other publicly available models. DeepMind judges when the condition is met.
D3 · Commitment modality
Manipulation and misalignment research is described as nascent
, and the associated level and risk assessment as exploratory and subject to further research
. These qualifiers carry across versions and are the framework's principal source of flexibility.
Reading
DeepMind's framework expanded across 2025 and 2026, adding a manipulation threshold, an early warning tier, and internal deployment safety cases. It buys flexibility through process language and exploratory qualifiers rather than through weakened commitments, and it couples this with an explicit statement that the value of some mitigations depends on industry-wide adoption.
Frontier AI Framework, now Advanced AI Scaling Framework
Meta published the Frontier AI Framework on 3 February 2025, ahead of the Paris AI Action Summit, and replaced it in April 2026 with a renamed second iteration. The framework operates in the context of open-weight release, which makes its adversary modelling and its trigger language the load-bearing choices.
Version history
v1.0 (3 February 2025) and v2.0 (8 April 2026 per the announcement, 7 April 2026 per the document change log). The framework describes itself as the second iteration, previously titled the Frontier AI Framework.
D1, D3 · Threshold language and modality
The primary standard changed, and so did the consequence attached to the highest tier. These two changes run in opposite directions.
View data as a table
| Risk tier | v1.0 action (Feb 2025) | v2.0 action (Apr 2026) |
|---|---|---|
| Moderate | Release | Release |
| High | Do not release | Develop with mitigations |
| Critical | Stop development | Develop with mitigations |
D2 · Evaluation categories
Version 1 covered cybersecurity and chemical and biological risk. Version 2 adds Loss of Control as a third domain, decomposed into autonomous AI research and development, evaluation awareness (whether a model can identify when it is being evaluated and selectively adapt its outputs), monitor interference, and autonomous replication as an emerging concern. No persuasion or manipulation domain appears in either version.
D6 · Governance
Version 1 located the release decision with an unnamed leadership team. Version 2 names the Chief AI Officer and the Director of Alignment and Risk as the decision-makers who assign risk thresholds and approve deployment, and adds a published Model Spec listing intended propensities including acquiescence to shutdown and lack of coercive power-seeking behavior
.
D7 · Conditional withdrawal
Neither version contains a competitor-conditional relaxation clause. This is a confirmed absence against the retrieved version 2 text and the archived version 1, and it distinguishes Meta from the other three primary subjects.
D9 · Definitional scope
Version 2 expands the deployment taxonomy to internal deployment, limited deployment, controlled deployment, closed release, or open release
, and states that Loss of Control risks may occur with similar probability with any type of deployment
, including internal deployment. The four-part inclusion test is plausible, catastrophic, net new, and instantaneous or irremediable.
Reading
Version 2 broadens scope and lowers the trigger while converting the top-tier consequence from a halt to a mitigation pathway, and it names individual officers as accountable decision-makers. The governance additions are specific and auditable. Meta remains the only primary subject with no competitor-conditional clause.
xAI, Microsoft, Amazon, and the rest of the signatory set
xAI
xAI published a draft Risk Management Framework watermarked DRAFT on 20 February 2025, the Seoul commitment deadline, promising an updated version within three months. Version 1.0 followed on 20 August 2025, roughly six months past that deadline. It states a quantitative deployment criterion: maintaining a dishonesty rate of less than 1 out of 2 on MASK
.
xAI released Grok Code Fast 1 on 28 August 2025, eight days later. The model card reported a 71.9 percent dishonesty rate on the same benchmark. AI Lab Watch's Zach Stein-Perlman described the framework as dreadful
and profoundly unserious
. This is named external commentary, cited to establish the criticism rather than as document text.
A renamed Frontier Artificial Intelligence Framework version 2.0 followed on 30 December 2025, two days before California's Transparency in Frontier Artificial Intelligence Act came into force. A further revision dated 30 June 2026 is a distinct document at a separate address, resolving the question of whether these are two revisions or a relabelling. The Midas Project reports that the June 2026 revision removed both quantitative risk acceptance criteria and whistleblower protection language; this is secondary reporting.
Microsoft
Microsoft published its Frontier Governance Framework in February 2025. It sets qualitative capability thresholds, scales security safeguards to pre-mitigation risk levels across four bands, and integrates with Microsoft's wider AI governance programme. A February 2026 update exists as a distinct primary document. What changed between the two could not be established from a primary comparison in this pass and is carried as an open item.
Amazon
Amazon published its Frontier Model Safety Framework on 9 February 2025, tied to the Paris summit and its endorsement of the Korea Frontier AI Safety Commitments. It defines Critical Capability Thresholds across CBRN, offensive cyber operations, and automated AI research and development, and commits not to deploy models exceeding thresholds without safeguards. The document commits to review at least annually. No second version appears as of 18 July 2026. Amazon has instead published model-specific evaluations under the framework, including for Nova Premier and Nova 2.0 Lite.
The remainder of the signatory set
Cohere, G42, NAVER, Nvidia, and Magic remain at their first published versions with no second version indexed. Nvidia's and Cohere's documents emphasise domain-specific rather than catastrophic risk. No published second version was found for Zhipu or Samsung, neither of which appears on METR's published-policy list.
METR's December 2025 update records that sixteen companies agreed to the Seoul commitments with an additional four companies joining since then
, and that twelve companies have published frontier AI safety policies. As of 18 July 2026 the public index still reflects that count.
Where the documents converge and where they part
Convergent movement
All five major developers now use a capability threshold structure paired with pre-committed responses. Loss of control and misalignment has become a shared domain: DeepMind through misalignment levels, Meta through Loss of Control as a third domain, OpenAI through the Frontier Governance Framework, and Anthropic through an affirmative misalignment case at its research and development thresholds. Named risk-reporting artefacts now exist at all four primary subjects.
Competitor-conditional clauses are the second convergence. Three of the four primary subjects hold one. Anthropic elevated the concept from an emergency provision to the organising logic of version 3.
View data as a table
| Company | Clause | Form |
|---|---|---|
| Anthropic | Present | Organising logic of version 3. Competitor provisions in a dedicated appendix |
| OpenAI | Present | Marginal-risk clause in version 2, subject to public acknowledgement |
| Google DeepMind | Present | Broad-application clause. Recommended security levels may be adjusted |
| Meta | Absent | No clause in either version |
| xAI | Absent | Relies on quantitative benchmark criteria instead |
Divergent movement
The clearest divergence is manipulation. Within roughly fourteen months the four primary frameworks moved in three different directions on the same capability.
View data as a table
| Company | Period | Status |
|---|---|---|
| OpenAI | Dec 2023 to Apr 2025 | Persuasion tracked as one of four categories |
| OpenAI | Apr 2025 to May 2026 | Not tracked |
| OpenAI | From May 2026 | Harmful manipulation reintroduced in the companion governance document |
| Google DeepMind | From Sep 2025 | Harmful manipulation Critical Capability Level |
| Anthropic | All versions | Never tracked |
| Meta | All versions | Never tracked |
Modality diverges as well. Anthropic separated unilateral commitments from industry recommendations and dropped its pause commitment. OpenAI added a conditional relaxation clause. Meta lowered its trigger but holds no competitor clause. DeepMind expanded scope at every revision. xAI relies on quantitative benchmark thresholds that no other developer uses.
View data as a table
| Company | D1 | D2 | D3 | D4 | D5 | D6 | D7 | D8 | D9 |
|---|---|---|---|---|---|---|---|---|---|
| Anthropic (v3.3 to v3.4) | Mixed | No change | Softened | Softened | Softened | Widened | Softened | Softened | Widened |
| OpenAI (Beta to v2) | Mixed | Narrowed | Mixed | Widened | Mixed | No change | Softened | Mixed | Narrowed |
| Google DeepMind (v3.0 to v3.1) | Widened | Widened | No change | Widened | Widened | Widened | Softened | Mixed | No change |
| Meta (v1.0 to v2.0) | Mixed | Widened | Softened | Widened | Softened | Widened | No change | Widened | Widened |
Terminology drift
The four now describe similar constructs in language that no longer maps cleanly. Cross-company comparison on any single capability requires translation, which is itself a finding.
| Construct | Anthropic | OpenAI | Google DeepMind | Meta |
|---|---|---|---|---|
| Threshold unit | Capability Threshold, ASL standard | High, Critical capability | Critical Capability Level | Moderate, High, Critical risk |
| Early warning | Checkpoint | Not separately named | Tracked Capability Level | Capability checkpoint |
| Deployment test | Required Safeguards sufficiency | Sufficiently minimise | Safety case at level | Substantially contribute to |
| Risk artefact | Risk Report | Capabilities and Safeguards Reports | FSF report | Safety and Preparedness Report |
| Levels in scale | ASL-2, ASL-3, ASL-4 | 2 operative | 2 tiers from v3.1 | 3 tiers |
Revision timing against external events
Revision dates cluster around summit and regulatory milestones. The pattern is correlation and is stated as such; companies give multiple reasons for revisions, including learning from implementation.
- February 2025. Meta v1.0, DeepMind v2.0, Microsoft v1.0, Amazon, G42, Cohere, Nvidia, and the xAI draft all land in the weeks around the Paris AI Action Summit.
- 30 December 2025. xAI publishes version 2.0 two days before California's Transparency in Frontier Artificial Intelligence Act takes effect.
- February 2026. The India AI Impact Summit produces the New Delhi Frontier AI Impact Commitments, signed by thirteen developers, and a declaration endorsed by 92 countries and international organisations. These address usage insights and multilingual evaluation rather than catastrophic-risk thresholds.
- May and June 2026. OpenAI's Frontier Governance Framework and Microsoft's update map to SB 53 and the EU code of practice. A US executive order of 2 June 2026 creates a voluntary pre-release government access framework for covered frontier models, with an access window of up to 30 days, and expressly prohibits mandatory licensing or preclearance.
- 2 August 2026. EU AI Act systemic-risk obligations for general purpose AI take effect, ahead of which the 2026 revision wave sits.
What did not resolve cleanly
Items below did not confirm against a primary document in this pass, or produced conflicting evidence. They are recorded rather than resolved.
| # | Item | Status |
|---|---|---|
| 01 | Anthropic v1.0 autonomy trigger. The quantitative 50 percent aggregate success rate phrasing attributed to v1.0 was not reverified word for word. The existence of an autonomy-based ASL-3 trigger is not disputed. | Unconfirmed |
| 02 | Anthropic v2 competitor clause section number. Cited elsewhere as section 7.1.7. Section number and exact wording not reverified against the PDF. Substance corroborated by GovAI; v3.1 confirms a relocated appendix on competitor commitments. | Unconfirmed |
| 03 | Anthropic ASL-4 definition. v2.0 retained a forward commitment to define further thresholds mandating ASL-4 safeguards. Whether v3.x defines any, and whether the original 2023 commitment was removed without changelog acknowledgement, needs a word-for-word comparison not completed here. | Open |
| 04 | Anthropic insider footnote text. Substance verified via changelog. Exact footnote text and numbering in the v2.1 and v2.2 PDFs not extracted. | Partial |
| 05 | Karnofsky quotation on regulation. Verified through GovAI's rendering rather than the original post. | Secondary |
| 06 | Meta compute threshold. The figure of at least 1026 operations and the open-weight adversary phrasing were not located in the retrieved sections of version 2. | Unconfirmed |
| 07 | Meta version 1.1. Listed in the ETO AGORA catalogue. No Meta-published v1.1 was found. Appears to be a third-party cataloguing artefact. | Resolved as artefact |
| 08 | Meta v2.0 date. Change log 7 April, blog 8 April, a social post 20 April. Reading: 7 April is the document effective date, 8 April the public announcement, 20 April a re-post. | Resolved |
| 09 | Microsoft February 2026 update. Exists as a primary document. Diff against version 1.0 not established. | Open |
| 10 | OpenAI Frontier Governance Framework specifics. The ISO 27001 and SOC 2 Type II references and the Ireland entity oversight assignment rest on trade press in this pass. | Secondary |
| 11 | Page and word counts. Confirmed for 6 of 30 entries only. The corpus table omits the column rather than carrying mostly empty cells. | Partial |
| 12 | Amazon publication date. The document states 9 February 2025. The METR index labels it 10 February 2025. Both preserved. | Conflict noted |
Corpus close
No framework activity was found later than 8 July 2026. Anthropic's policy page states last updated 8 July 2026. No OpenAI Preparedness Framework version 3 exists. DeepMind's current version remains 3.1. Meta has published no revision after version 2.0.
Documents analysed
All access dates 18 July 2026. Primary documents were read directly except where noted in the corpus table.
Anthropic
Responsible Scaling Policy pages and update log; RSP PDFs v1.0 through v3.4 on www-cdn.anthropic.com and cdn.sanity.io; the version 3 announcement; Frontier Compliance Framework. GovAI analysis of RSP v3.0 cited as secondary.
OpenAI
Preparedness Framework beta and version 2 PDFs on cdn.openai.com; the version 2 announcement; Frontier Governance Framework PDF and announcement. Fortune, 16 April 2025, and Steven Adler on X, 15 April 2025, cited as named commentary.
Google DeepMind
Frontier Safety Framework PDFs v2.0, v3.0, and v3.1 on storage.googleapis.com; the strengthening and updating announcements on deepmind.google; Gemini model cards.
Meta
Advanced AI Scaling Framework version 2 on ai.meta.com and the accompanying blog; version 1.0 through a web.archive.org capture; Frontier Model Forum summary; ETO AGORA catalogue entry.
xAI, Microsoft, Amazon
xAI framework PDFs on data.x.ai and media.x.ai and the Grok Code Fast 1 release note; Microsoft Frontier Governance Framework PDFs for 2025 and February 2026; Amazon Frontier Model Safety Framework and Nova evaluation reports on amazon.science. AI Lab Watch, SaferAI, and the Midas Project cited as named commentary.
Cross-cutting
METR Frontier AI Safety Policies index and Common Elements report; whitehouse.gov presidential action of 2 June 2026; law firm client alerts on that order; Brookings and Lawfare on SB 53; Press Information Bureau and Carnegie Endowment on the India AI Impact Summit.
Shrestha, S. (2026) "Frontier safety frameworks read as a version diff."
Intelligence, Technology desk, entry 01. Published 18 July 2026.
https://intelligence.sushantshrestha.com/technology/frontier-safety/01-version-diff.html
02 · Frontier safety frameworks, read against what the models actually did. In preparation.