Written and maintained by CASRAI Editorial Board
Last updated
Last verified: September 20, 2026. Frontier AI safety is not one topic — it is a dozen adjacent ones (capability thresholds, dangerous-capability evaluations, safeguards, incident reporting, third-party review, lab governance) that different people search for in different words. If you already know exactly which term you’re after, use CASRAI’s search. If you’re not sure which of CASRAI’s guides actually covers your question, this page is the faster route in: it uses the 10 tracks of NIKOLAI, CASRAI’s own frontier-AI-safety dictionary, as a map of the whole space, and links each track straight to the guides that cover it.
NIKOLAI (current release nikolai-v0.2) is CASRAI’s independent reference work defining 64 elements used across frontier-AI-safety frameworks — things like “capability threshold,” “evaluation run,” “safeguard,” and “incident reporting deadline” — organized into 10 tracks, N1 through N10. It is not affiliated with, run by, or endorsed by any AI lab, evaluator, or regulator: every row in NIKOLAI’s crosswalks is what CASRAI calls a shadow mapping — CASRAI’s own independent reading of what a lab or a statute has published — unless that organization has filed an explicit Mapping Declaration confirming how it actually uses the term. Below, each track gets a plain-language description of its scope and two or three links to the CASRAI guides that go deep on that territory. If your question doesn’t fit neatly under one track, it’s probably a sign the topic itself spans more than one — follow whichever track is the closest starting point.
N1 — Actors, Models and Scope
Before any safety commitment means anything, it has to answer: which developer, which model, on what deployment surface, as of what date, and under which framework version? N1 is where NIKOLAI tracks the scope-setting vocabulary — developer, model identifier, deployment surface, coverage date, framework version, risk domain, and threshold — that Anthropic’s Responsible Scaling Policy, OpenAI’s Preparedness Framework, and Google DeepMind’s Frontier Safety Framework each define slightly differently. CASRAI maps these definitions against each other via NIKOLAI; none of the three labs use NIKOLAI’s own N1 vocabulary internally.
- What Is a Frontier AI Model? — the baseline definition question this track exists to standardize around.
- Frontier AI Labs: Who They Are and What Safety Frameworks They Publish — the “which developer” side of N1’s scope elements.
Full track page: N1 — Actors, models and scope.
N2 — Threat Models and Risk Framing
Before a lab can set a capability threshold, it has to name what it’s actually worried about: who could misuse the model, through what mechanism, toward what harm. N2 is where NIKOLAI tracks that vocabulary — threat model, risk pathway, and threat-actor profile — as used across Anthropic, OpenAI, Google DeepMind, xAI, Meta, the EU’s GPAI Code of Practice, and California SB 53. CASRAI maps how each of these sources frames risk via NIKOLAI’s shadow mappings; it is not claiming any of them adopted NIKOLAI’s specific three-term structure.
- AI Risk Assessment Framework and Risk Register: A Practical Starting Point — turning threat models into a working risk register.
- “Concrete Problems in AI Safety”: The 2016 Paper Explained — the foundational risk-framing paper much of this vocabulary traces back to.
Full track page: N2 — Threat models and risk framing.
N3 — Thresholds and Checkpoints
The capability threshold is the operational core of a Responsible Scaling Policy: the specific, testable point at which a model is judged to have crossed into a risk tier requiring new safeguards. N3 defines that vocabulary — capability threshold, threshold status, alert threshold, checkpoint rule, halt condition, and reassessment trigger — and CASRAI uses NIKOLAI to map how Anthropic, OpenAI, Google DeepMind, METR, and the US government each define and test against thresholds. A threshold is only as credible as the evaluation evidence behind it, which is why N3 depends directly on N5 below.
- Responsible Scaling Policy (RSP): What It Is and How the Major Labs Compare — the framework category N3’s vocabulary was built to compare.
- The SB 53 Material-Change Trigger: When a Frontier AI Framework Must Be Updated — what happens when a threshold itself has to change.
Full track page: N3 — Thresholds and checkpoints.
N4 — Claims and Argument
A safety case is the structured argument that a model’s risk is acceptably low — the connective layer between evaluation evidence and a go/no-go deployment decision. N4 defines that argument’s vocabulary: claim, safety case, likelihood term, risk level, confidence adjustment, residual risk and risk-acceptance determination, marginal-versus-absolute risk basis, and limitation. CASRAI tracks this vocabulary via NIKOLAI against how Anthropic, OpenAI, Google DeepMind, Meta, xAI, and NVIDIA each construct and publish their own safety arguments, and against the UK AI Security Institute’s own safety-case vocabulary and the 2026 International AI Safety Report.
- How to Grade a Frontier AI Safety Framework: The SaferAI Rubric — an independent rubric for judging how well a safety case actually holds up.
- International AI Safety Report 2026: What It Found — the report N4’s vocabulary is cross-checked against.
Full track page: N4 — Claims and argument.
N5 — Evidence and Evaluations
Every capability threshold rests on a dangerous-capability evaluation, and an evaluation’s evidentiary weight depends on how hard the model was pushed to perform (elicitation method) and whether the benchmark still discriminates capability (saturation status). N5 defines that methodology vocabulary — evaluation, evaluation run, elicitation method, saturation status, and evaluation-validity threat — and CASRAI maps it via NIKOLAI against evaluation practice at Anthropic, OpenAI, Google DeepMind, METR, and the Frontier Model Forum, plus the EU GPAI Code of Practice’s own evaluation requirements.
- What Is METR? How Its AI Safety Evaluations Work — one of the independent evaluators N5’s vocabulary is mapped against.
- AI Red Teaming: Definition and How It Works in Frontier AI Safety — a specific elicitation method covered by this track.
- Third-Party AI Evaluator Standards: Independence, Access, and Methodology — the standards question behind who runs these evaluations.
Full track page: N5 — Evidence and evaluations.
N6 — Mitigations and Security
When a model crosses a threshold, something specific has to activate: a safeguard, at a defined robustness level, protected by security controls at a defined security level, with defined coverage and any exemptions documented. N6 covers that vocabulary — monitor, safeguard, robustness level, coverage level, exemption, security level, security control, mitigation change, and internal-deployment/internal-use risk — which CASRAI maps via NIKOLAI against safeguard specifications published by Anthropic, OpenAI, Google DeepMind, xAI, Meta, Amazon, Microsoft, and G42.
- AI Safety vs. AI Security: What the Distinction Actually Means — the safety/security boundary N6’s vocabulary sits on.
- ISO/IEC 42001 Certification: Path, Timeline, and Annex A Controls — a formal controls framework covering much of the same ground.
Full track page: N6 — Mitigations and security.
N7 — Incidents
Incident reporting is one of the few places frontier AI safety has moved from voluntary framework to binding law: California SB 53 and New York’s RAISE Act both set incident-reporting deadlines with named recipients. N7 defines incident, incident type, discovery method, and incident-reporting deadline and recipient, and CASRAI uses NIKOLAI to crosswalk that vocabulary against those two statutes plus how Anthropic, OpenAI, Google DeepMind, Meta, and xAI each describe their own incident-disclosure practice.
- SB 53 Critical Safety Incident Reporting: What Counts, Deadlines, and Who to Notify — the binding deadline this track’s vocabulary maps against.
- Building an Internal AI Safety Incident Response Program — turning N7’s vocabulary into an operational program.
Full track page: N7 — Incidents.
N8 — Transparency and Review
An evaluation is only as credible as the conditions under which it was run: whether the evaluator was actually independent, what access it got, whether it can publish what it found, and what got redacted. N8 covers that infrastructure — evaluator independence and conflict of interest, evaluator access attestation, publication-rights clause, redaction and redaction reason, external review, and AI-model review — and CASRAI maps it via NIKOLAI against vocabulary used by METR, the UK AI Security Institute, and NIST’s CAISI, alongside requirements under California SB 53.
- California SB 53 (Transparency in Frontier Artificial Intelligence Act): The Foundational Explainer — the statute that put transparency obligations into binding law.
- The EU AI Act GPAI Code of Practice: What It Is and Who Signed It — a separate transparency mechanism this track’s vocabulary is mapped against.
Full track page: N8 — Transparency and review.
N9 — Commitments and Governance
A frontier AI safety commitment only binds an organization if someone is named accountable for it and a defined protocol exists for updating it. N9 covers that governance layer — commitment, framework update protocol, roadmap item, pre-release sharing window, industry-wide recommendation, Mapping Declaration, accountable decision-maker and sign-off, and noncompliance and whistleblower reporting — and CASRAI maps it via NIKOLAI against public safety pledges from Anthropic, OpenAI, and Google DeepMind. This is also the track whose “accountable decision-maker and sign-off” element ties most directly to California SB 53’s named-role requirement.
- Accountable Decision-Makers Under SB 53: What the Statute Actually Requires — the binding version of N9’s sign-off element.
- Seoul Frontier AI Safety Commitments: The Signatory List and What They Pledged — a voluntary, cross-lab example of the commitment vocabulary this track defines.
- AI Governance Framework Template: Councils, Risk Tiers, and Escalation Paths — turning N9’s governance vocabulary into an internal program.
Full track page: N9 — Commitments and governance.
N10 — Assurance Roles
N10 is different from every other track on this page. Tracks N1 through N9 define vocabulary drawn from what frontier-AI developers and regulators themselves publish. N10 instead describes NIKOLAI’s own governance process — who may file, review, or dispute a Mapping Declaration on this dictionary: declaring representative, CASRAI declaration reviewer, corroborating evaluator, disputant, and declaration accuracy steward. If you’re trying to understand how NIKOLAI’s crosswalks move from an unverified shadow mapping to an organization-confirmed declaration, this is the track that governs that process, not a track about accountability roles inside an AI lab’s own safety program (see N9 above for that).
- Building an Internal Audit Function for Frontier AI Safety — the closest lab-side analogue to N10’s independent-review roles.
- Third-Party AI Auditing: What It Is and Who Does It — external assurance roles outside NIKOLAI’s own process.
Full track page: N10 — Assurance roles. To see the declaration process N10 governs in practice, visit NIKOLAI’s Mapping Declarations.
Why This Page Is Organized Around NIKOLAI
This page isn’t a NIKOLAI explainer bolted onto an unrelated list — the ten sections above are NIKOLAI’s own track taxonomy, used as the map. That’s worth being precise about: NIKOLAI is CASRAI’s own dictionary of 64 frontier-AI-safety elements across these 10 tracks (current release nikolai-v0.2), built and maintained independently by CASRAI. It is not a standard that any lab, evaluator, or regulator has adopted, endorsed, or been consulted on — every crosswalk row you’ll find on a NIKOLAI element or track page is a shadow mapping (CASRAI’s own reading of a published document) unless the organization in question has filed an explicit Mapping Declaration confirming how it actually uses that term in its own practice. When a track description above says CASRAI “tracks” or “maps” a concept via NIKOLAI against a specific framework, that is a claim about CASRAI’s independent classification work — not a claim that the framework itself is organized into NIKOLAI’s tracks. NIKOLAI also publishes a public v1 REST API and two MCP tools for programmatic access to the same element and crosswalk data described on this page.
Frequently Asked Questions
What is NIKOLAI?
NIKOLAI is CASRAI’s own dictionary of frontier-AI-safety terminology — 64 elements, organized into 10 tracks (N1 through N10), currently at release nikolai-v0.2. It defines terms like capability threshold, evaluation run, safeguard, and incident-reporting deadline, and crosswalks them against what individual labs and regulators have actually published.
Is NIKOLAI an official or endorsed industry standard?
No. NIKOLAI is CASRAI’s own independent reference work. No lab, evaluator, or regulator has endorsed NIKOLAI, reviewed one of its mappings, or been consulted on the dictionary. Every crosswalk is a shadow mapping — CASRAI’s own reading — unless the organization involved has filed an explicit Mapping Declaration confirming it.
I don’t know which track my question falls under — what should I do?
Read the one-paragraph scope description for each track above and pick whichever is closest; most real questions sit mostly inside one track even if they touch the edges of another (a threshold question, for example, usually also touches N5’s evaluation evidence). If two tracks both seem to fit, that’s a sign the underlying topic genuinely spans both — follow whichever track’s linked guides look closer to your specific question, and use that guide’s own related-reading links to reach the rest.
How is a NIKOLAI track different from a specific lab’s Responsible Scaling Policy?
An RSP (or Preparedness Framework, or Frontier Safety Framework) is a single lab’s own policy document, written in that lab’s own vocabulary. A NIKOLAI track is CASRAI’s independent category spanning multiple labs’ and regulators’ vocabulary at once, so that the same underlying concept — say, a capability threshold — can be compared across RSP v3.4, the Preparedness Framework, and the Frontier Safety Framework side by side.
How often is NIKOLAI updated?
NIKOLAI is versioned; the current release described on this page is nikolai-v0.2. Check the live NIKOLAI dictionary for the current version and element count, since both can change between releases.







