Skip to main content
v2026.11,858 entries · CC-BY 4.0

The Access Record No Lab Currently Publishes

NIKOLAI’s Evaluator Access Attestation element says so itself: it is CASRAI’s own editorial synthesis, unsourced from any single document, because no developer currently publishes a record in this shape. This page assembles the eight fragments that exist — and finds the one place a lab volunteers to go further than the rest.

Written and maintained by CASRAI Editorial Board

Last updated

Last verified: September 20, 2026. NIKOLAI’s own definition for this record type is blunt about what it is not. The element reads: “a record, jointly attested by the developer and the evaluator, of what access an evaluator was granted and denied” — covering model versions, safeguards, reasoning traces, weights, documents, personnel, and systems, plus duration and confidentiality terms. Directly beneath that definition sits an editorial note stating plainly that this is “NIKOLAI’s own editorial synthesis, unsourced from any single document; no developer currently publishes a record in this shape.” That is an unusually direct thing for a dictionary entry to say about itself, and it is the actual subject of this page. Not a crosswalk of eight labs’ access-attestation records — no lab has one to crosswalk — but an attempt to answer a narrower, more honest question: what would a complete evaluator-access record look like, assembled from the fragments that do exist, if any developer decided to publish one in this shape?

The short version: eight organizations each publish a fragment of what such a record would need — a personal essay, a model card, an executive order, a technical report, a framework document — and no two fragments are the same kind of document, let alone the same schema. Read together, they cover most of what NIKOLAI’s element asks for: what access was granted, to which model version, under what confidentiality terms, for how long. Read separately, none of them is an attestation. And exactly one of the eight goes further than “what was granted” to also address what NIKOLAI’s definition asks for and nothing else attempts: documenting access that was requested and denied, not only access that was given.

What NIKOLAI Means by “Evaluator Access Attestation”

NIKOLAI, CASRAI’s own independent, unendorsed dictionary of frontier-AI-safety elements, defines Evaluator Access Attestation as element N8.4, part of the Transparency and Review track. The element is currently tagged proposed in NIKOLAI’s schema (release nikolai-v0.1, inside the broader nikolai-v0.2 dictionary) — a status that matters more here than it does for most NIKOLAI elements, because “proposed” is doing real work in the sentence: this is not a vocabulary NIKOLAI observed developers already using and gave a name to. It is a vocabulary NIKOLAI is proposing, precisely because nothing like it currently exists in the field.

The track it sits in explains why the gap matters. N8’s own stated rationale, applied to its neighboring elements, is that “external review only means something if the evaluator is independent and a developer can’t quietly redact an inconvenient finding” — and access sits upstream of both of those guarantees. An evaluator’s independence is hard to assess without knowing what it was allowed to see; a redaction is hard to evaluate without knowing what was available to redact from. NIKOLAI’s companion guide to third-party evaluator standards puts the practical version of the problem directly: “the access an evaluator was actually given is rarely visible from the published report alone.” N8.4 is NIKOLAI’s proposed fix for that — a discrete, checkable field for what got granted and what got withheld, instead of leaving both implicit in an evaluator’s prose.

Eight Fragments, No Assembled Record

None of the eight rows below is an evaluator-access attestation in the shape NIKOLAI defines. Each is something else — a founder’s essay, a model card, a presidential order, an evaluator’s own published terms — that happens to say something about access as a side effect of being about something else. Verified directly against NIKOLAI’s live Evaluator Access Attestation element page on September 20, 2026, and cross-checked against primary sources where those documents are public and legible; match type and evidence tier are NIKOLAI’s own labels for how closely each fragment maps to the element it proposes, not CASRAI’s judgment of how good any organization’s access practice is.

Organization Source Match What it actually documents about access
Anthropic “We Must Pace the Frontier” (Dario Amodei essay); Advanced AI Framework; METR agreement Close “Ongoing, employee-like access to a team of embedded third-party evaluators,” including transcripts beyond the incident window under an 8-week (extendable) confidential-sharing term — and, uniquely among these eight, a stated right for reviewers to publish “the access they received or didn’t receive.”
OpenAI Sam Altman public statement; GPT-5.6 deployment safety materials Close Calls “independent evaluators with employee-like access” a good model; UK AISI’s own assessment describes being given “extensive grey box access” to pre-release checkpoints.
xAI Grok 4.6 model card Narrow States it provided “an unrestricted configuration of Grok 4.6” to third-party evaluators, plus an early Grok 4.20 snapshot — access described in one sentence, with no duration or confidentiality terms attached.
Meta Advanced AI Scaling Framework v2 Close Its preparedness-report format commits to including “details about elicitation, time and resources spent, and access given” to internal reviewers — access as report content, not as a standing attestation an outside evaluator co-signs.
EU GPAI Code of Practice, Safety and Security Chapter Exact Requires “adequate access, information, time, and other resources, including access to model activations, gradients, logits,” a floor of at least 20 business days, and access to the least-mitigated model version — the most granular access specification of the eight, though it is a regulatory obligation, not a jointly attested record of what one evaluator actually got.
US Government Executive Order 14409, §3(b)(ii) Close Requires covered developers to “provide the Federal Government with access to covered frontier models, subject to appropriate confidentiality, cybersecurity, insider-risk, and intellectual-property protection, use, and nondisclosure requirements, for a period of up to 30 days” before release to other trusted partners.
METR metr.org; standard engagement terms Exact Its own published terms specify access to “their most capable internal model(s) at the time of assessment, including raw chains of thought,” minimum throughput (4M input / 1M output tokens per minute), zero data retention, and “full transparency about the terms of the engagement, including at least redaction terms, access provided, time.”
Frontier Model Forum Third-Party Assessments technical report Close Defines “appropriate access” as balancing “information needs with security considerations,” “providing only the minimum information necessary,” with the level of access varying by assessment function — a principle, not a per-engagement record.

The One Place a Lab Goes Further: Denied Access

NIKOLAI’s own definition asks for what an evaluator “was granted and denied.” Read the eight rows above again with that phrase in mind, and seven of them describe only what was given. Anthropic’s essay is the exception, and it is explicit about it. Dario Amodei’s “We Must Pace the Frontier” states: “External reviewers should have the right to publish key findings about risk levels, incidents, practices, and the access they received or didn’t receive — without editorial control by Anthropic.” That is not a redaction policy or a publication-rights clause layered on top of an access grant; it is a proposal that the evaluator’s account of what it was refused becomes part of the public record alongside what it was given.

The same essay pairs that commitment with a narrow limit on how much of it Anthropic can take back: “We will have the narrow ability to redact security-sensitive, legally privileged, commercially sensitive, or third-party confidential information, but we can’t redact findings just because they are unfavorable. The reviewers can say publicly if a redaction removed something important to their conclusions.” A denial-of-access disclosure that the developer could quietly veto would not be much of a disclosure; pairing the two clauses is what makes the denied-access commitment more than a sentence.

No other organization in the crosswalk above proposes this. OpenAI’s “employee-like access” language and UK AISI’s “extensive grey box access” describe what was granted. xAI’s “unrestricted configuration” describes what was granted. The EU’s activations-gradients-logits requirement, the US government’s 30-day window, METR’s rate limits, and the Frontier Model Forum’s minimum-necessary principle all specify terms for access that is given, not a mechanism for recording access that was asked for and refused. This is the one substantive divergence this research pass found across all eight sources, and it is worth stating precisely: it is a single essay’s proposal, not a shipped policy with a track record, and Anthropic itself has not yet published an instance of a reviewer exercising that right to disclose a denial. But among eight organizations, it is the only place the idea appears in writing at all.

Why the Gap Persists

Lay the eight rows next to NIKOLAI’s proposed fields — model version, safeguards, reasoning traces, weights, documents, personnel, systems, duration, confidentiality terms, and now denial — and the shortfall is not that developers say nothing about access. It is that none of them say it in a form built to be checked. A model card’s access sentence is written for readers of that model card, not for comparison against a developer’s own past statements or another developer’s terms. An executive order’s 30-day window is a regulatory floor, not a record of what any specific evaluator actually received during that window. METR’s published terms are the closest thing to an attestation on this list — specific numbers, specific rights — but they describe METR’s standard ask across engagements, not a jointly signed record of one particular engagement’s outcome. Nothing here is a lie or an evasion; access language is scattered across essays, model cards, statutes, and technical reports because each of those documents was written to do something other than attest to access, and attestation was never the job any of them were assigned.

That is the case NIKOLAI’s element is making by existing in “proposed” status rather than by claiming an adoption it doesn’t have. The honest description of N8.4 is not “the standard eight labs already follow” — it is a specific, checkable shape that a developer and an evaluator could jointly sign if either of them decided the current scatter of essays and model-card sentences wasn’t good enough. As of this writing, none has.

Where NIKOLAI Fits In

This page is CASRAI’s own exploration of NIKOLAI’s Evaluator Access Attestation element, N8.4 in the Transparency and Review track of CASRAI’s frontier-AI-safety dictionary. NIKOLAI is not affiliated with, run by, or endorsed by any of the eight organizations referenced above, and none of them has been consulted on how NIKOLAI classifies their language or on the element’s proposed shape. Unlike most NIKOLAI crosswalk pages, this one is not asserting eight independent shadow mappings of a term every organization already uses — N8.4’s own editorial note says the opposite: the definition is CASRAI’s synthesis, “unsourced from any single document,” built by combining what evaluator-access language does exist into the shape a genuine attestation would need. Every row above is still labeled with NIKOLAI’s own confidence tier (Exact/Close/Narrow), because even a fragment can match NIKOLAI’s proposed fields closely or loosely — but no row claims to BE the attestation, because none of the eight sources is one. If any of these organizations files an explicit Mapping Declaration adopting this element’s shape, or publishes a record that actually fits it, that would be a materially different page than this one.

N8.4 sits next to the other six elements in N8 that, together, describe how an AI system review can be trusted rather than merely claimed: Evaluator Independence and Conflict of Interest (N8.1) records who ran the review and what ties it had to the developer; Publication Rights Clause (N8.3) records whether the evaluator could publish an inconvenient finding at all; Redaction (N8.7) records that something was removed from what got published. Access attestation is the piece underneath all three — independence and publication rights matter less if nobody can check what the evaluator was actually shown in the first place. Read together with CASRAI’s guides to third-party evaluator standards and methodology and evaluator independence across the AI safety ecosystem, this page is the narrowest possible cut through that same territory: not how evaluation works in general, but the single missing record type that would make every other transparency claim in this track easier to verify.

Frequently Asked Questions

What does NIKOLAI mean by “Evaluator Access Attestation”?

NIKOLAI’s Evaluator Access Attestation element (N8.4) is a proposed record, jointly attested by a developer and an evaluator, of exactly what access — model versions, safeguards, reasoning traces, weights, documents, personnel, systems — an evaluator was granted and denied, plus the duration and confidentiality terms attached. NIKOLAI itself labels the definition an editorial synthesis, not a quotation or observation from any single existing document.

Does any AI lab currently publish an evaluator-access-attestation record?

No. NIKOLAI’s own element page states this directly: no developer currently publishes a record in this shape. What exists instead is a scatter of partial access language across model cards, essays, executive orders, and technical reports — eight fragments, none of them a joint, checkable attestation.

Which organization documents access most completely?

By NIKOLAI’s own match-type labels, the EU’s GPAI Code of Practice and METR’s published engagement terms score Exact — the EU for specifying access down to model activations, gradients, and logits with a 20-business-day floor, METR for specific throughput numbers and a zero-data-retention term. Neither is a jointly attested record; both are the developer’s or evaluator’s own standing terms.

What is the one real divergence this research found?

Only Anthropic, via Dario Amodei’s essay “We Must Pace the Frontier,” proposes that evaluators should be able to publish “the access they received or didn’t receive” — covering denied access, not just granted access. No other organization in this crosswalk makes that specific commitment in writing.

Is NIKOLAI’s crosswalk here an official or endorsed mapping?

No. As with every NIKOLAI page, nothing here is confirmed by the organizations named unless one has filed an explicit Mapping Declaration. This page goes a step further than that standard caveat: the element itself is not claiming the eight organizations already use this vocabulary. It is CASRAI’s own proposed synthesis of what a complete record would contain, built because no existing document currently does.

Related Reading

Follow CASRAI

Research-administration guidance, standards updates and independent tool reviews.

Ask CASRAI · free to try

Ask about The Access Record No Lab Currently Publishes

Ask your first 2 questions free below. Subscribers get 150 a day for $29 a month.

Ask CASRAI answers research-administration questions and cites the passages behind every claim. When our sources don't cover a question, it says so.

Answers draw on CASRAI's guides and dictionary plus the federal and funder documents we index: Federal Register, Grants.gov, Regulations.gov and UKRI.

Works on this site and inside Claude, Cursor and the AI tools you already use.

Everything CASRAI publishes — this page, the dictionary, the guides and the news — stays free to read, with no account and no card.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →