Skip to main content
v2026.11,858 entries · CC-BY 4.0
NIKOLAI elementN9 · Commitments and governanceProposednikolai-v0.1

Accountable Decision-Maker and Sign-Off

NIKOLAI proposal: an Accountable Decision-Maker and Sign-Off record captures the named role (and, where published, the named person) who makes or approves a threshold determination, risk-acceptance decision, deployment decision, redaction, or framework change, together with the approval record itself (what was approved, by whom, and when). This wording is a NIKOLAI editorial synthesis, not a quotation from any single source.

This is CASRAI's own proposed definition, not a definition any named organisation has agreed to. See what NIKOLAI is and is not.

Source of record

Where this definition comes from

  • Anthropic Responsible Scaling Policy v3.4, §3.4

    Executive approval: The Risk Report, along with the internal feedback and any available external feedback, will be sent to the CEO and Responsible Scaling Officer (RSO) for final review and approval. The CEO and RSO will make the ultimate determination regarding the adequacy of the risk assessment and any downstream deployment or development plans.

    https://cdn.sanity.io/files/4zrzovbb/website/0bacdc8440ea96e62a8766d99ebe1d4eea6d5f3a.pdf
  • OpenAI Preparedness Framework v2, Appendix B

    OpenAI Leadership, i.e., the CEO or a person designated by them, is responsible for: Making all final decisions, including accepting any residual risks and making deployment go/no-go decisions, informed by SAG's recommendations.

    https://cdn.openai.com/pdf/18a02b5d-6b67-4cec-ab64-68cdfbddebcd/preparedness-framework-v2.pdf
  • EU GPAI Code of Practice, Safety and Security Chapter, Commitment 8, Measure 8.1

    Systemic risk oversight ... Systemic risk ownership ... Systemic risk support and monitoring ... Systemic risk assurance ... allocated across five levels: the management body in its supervisory function; the management body in its executive function; relevant operational teams; internal assurance providers; and external assurance providers.

    https://ec.europa.eu/newsroom/dae/redirection/document/118119

Crosswalk

How named organisations use this concept

Every row below is a shadow mapping. It is CASRAI's own reading of a published document. No lab, evaluator or regulator named here has declared, endorsed, or been consulted on this mapping. That will change only when an organisation files its own Mapping Declaration — see the non-endorsement policy.
OrganisationTheir term, as publishedMatchSource
Anthropic
Anthropic RSP v3.4 / Advanced AI Framework
§3.4 "Executive approval": "The Risk Report ... will be sent to the CEO and Responsible Scaling Officer (RSO) for final review and approval. The CEO and RSO will make the ultimate determination ..." Then "Governance notification": the CEO and RSO share their decision with the Board and the LTBT, and where marginal-risk analysis is central, "explicit approval of the Risk Report by the Board and LTBT (rather than just the CEO and RSO) will be required." RSO duties per §4(1): proposing policy updates, approving deployment/development decisions, reviewing major contracts, overseeing implementation, receiving noncompliance reports, and making interpretation calls. The Risk Report itself names no individual by title or name. AAF: "Identify the corporate officer primarily accountable for the framework's implementation." (p.5)
Also cites {RR} and {AAF}.
exact
confidence: high
Anthropic Responsible Scaling Policy v3.4
OpenAI
OpenAI Preparedness Framework v2 / 'Path to Astra'
"OpenAI Leadership, i.e., the CEO or a person designated by them, is responsible for: Making all final decisions, including accepting any residual risks and making deployment go/no-go decisions, informed by SAG's recommendations." "the SAG does not have the ability to 'filibuster'"; "Where necessary, the Board may reverse a decision" (App. B). Astra: "Safety Advisory Group's recommendation and OpenAI leadership's determination."
Also cites {ASTRA}.
exact
confidence: high
OpenAI Preparedness Framework v2
Google DeepMind
Frontier Safety Framework v3.1 / Gemini 3.7 Flash FSF report
"the appropriate governance function" (not named); Gemini 3.7 Flash CBRN committee "communicated this decision to leadership" (p.7).
Also cites {GF37}. DU: the FSF declares a governance function exists but does not name the role or person.
none
confidence: medium
Google DeepMind Frontier Safety Framework v3.1
xAI
xAI Frontier AI Framework (30 Jun 2026)
"Risk owners" only: "designating risk owners, including assigning responsibility for proactively mitigating identified risks and monitoring for critical incidents or imminent threats" (s.3). The acceptance decision-maker is not named.
{FAIF26} PDF metadata reads 'Privileged/Confidential DRAFT working FRAMEWORK DOC'; draft-vs-final status unresolved (open-VERIFY register item 4). NR: 'risk owner' is a narrower role than the element's full 'accountable decision-maker for acceptance and sign-off'.
narrow
confidence: medium
xAI Frontier AI Framework (30 Jun 2026)
Meta
Meta Advanced AI Scaling Framework v2
§2.1.2: "Based on this pre-mitigation risk assessment, the Chief AI Officer and Director of Alignment and Risk will assign a risk threshold." §2.1.3: "Informed by this analysis, the Chief AI Officer or the Director of Alignment and Risk will determine whether to request further testing or information, require additional mitigations or improvements, or approve the model for deployment" (footnoted to §2.3). §2.3 itself: "with model deployment following appropriate consultation with relevant teams and with the approval of the Chief AI Officer" -- and separately, "Meta's Chief AI Officer oversees the design, implementation, and operation of the entire evaluation and mitigation process. The Chief AI Officer supervises and is supported by the Director of Alignment and Risk, who bears responsibility for executing the lifecycle of risk assessment and mitigation... with model deployment following appropriate consultation with relevant teams and with the approval of the Chief AI Officer."
Confirmed in the source's open-VERIFY register (item 11) as a genuine drafting inconsistency in Meta's own document, resolved in a fourth pass with the PDF re-fetched and fully re-extracted with `pypdf` -- not a paraphrase artefact. §2.1.3 names two possible approvers ('or'); §2.3, which §2.1.3 itself footnotes as the fuller account, names only the Chief AI Officer. NIKOLAI's accountable-decision-maker field for Meta should record 'Chief AI Officer (sole, per §2.3); Director of Alignment and Risk named as an alternate approver only in §2.1.3' rather than silently picking one name.
exact
confidence: high
Meta Advanced AI Scaling Framework v2
EU
EU GPAI Code of Practice, Safety and Security Chapter
Commitment 8, Measure 8.1, verbatim in full: four responsibilities -- "(1) Systemic risk oversight ... (2) Systemic risk ownership ... (3) Systemic risk support and monitoring ... (4) Systemic risk assurance ..." -- allocated across five levels: "(1) the management body in its supervisory function ...; (2) the management body in its executive function; (3) relevant operational teams; (4) if available, internal assurance providers ...; and (5) if available, external assurance providers ...." Illustrative titles: oversight → "a specific committee ... (e.g. a risk committee or audit committee)"; ownership → executive-function members "(e.g. Head of Research or Head of Product)"; support and monitoring → "at least one member of the management body in its executive function (e.g. a Chief Risk Officer or a Vice President, Safety & Security Framework)", who "must not also be responsible for the Signatory's core business activities"; assurance → "a relevant party (e.g. a Chief Audit Executive, a Head of Internal Audit, or a relevant sub-committee)".exact
confidence: high
EU GPAI Code of Practice, Safety and Security Chapter
California SB 53
California SB 53
Deployment decision point without a named signatory: "(4) Reviewing assessments and adequacy of mitigations as part of the decision to deploy" and "(9) Instituting internal governance practices to ensure implementation of these processes" (22757.12(a)).none
confidence: medium
California SB 53
US Government (Executive Order 14409)
Executive Order 14409 / OpenAI 'A Blueprint for a Federal Framework'
EO 14409: designation "shall be made by the Director of NSA, in consultation with the National Cyber Director, the APST, the Director of CISA, and other representatives of the Department of War." OpenAI proposal: "Developers should remain responsible for deployment decisions" (blueprint p.6).
Also cites {BLUE}. NR: EO 14409's role is a narrower, security-clearance-specific designation authority, not a general accountable decision-maker for a safety framework.
narrow
confidence: medium
Executive Order 14409
METR
METR
Accountability element includes "oversight mechanisms defining who is responsible for implementing the safety policy."close
confidence: medium
METR
Safety Framework Cards (discovery)
Safety Framework Cards (SSRN 7061798)
"governance triggers" [UV].
SFC paywalled/unread; discovery-snippet only. No resolvable primary URL supplied for this tag.
none
confidence: low
Discovery sweep (evaluator ecosystem; Safety Framework Cards, unread/paywalled)
Microsoft
Microsoft Frontier Governance Framework (Feb 2026)
"Executive Officers responsible for Microsoft's AI governance program (or their delegates)" make the final decision.exact
confidence: high
Microsoft Frontier Governance Framework (Feb 2026)
G42
G42 Frontier Safety Framework
"Frontier AI Governance Board" (four named roles) proposes; Executive Leadership Committee approves.
The source's open-VERIFY register (item 16) flags 'G42 DML 2 row assignment' as unresolved -- treat the specific role-to-decision mapping as provisional pending that check.
exact
confidence: medium
G42 Frontier Safety Framework
Amazon
Amazon Frontier Model Safety Framework
"The team performing the Critical Capability Threshold evaluations will report to Amazon senior leadership any evaluation that exceeds the Critical Capability Threshold. The report will be directed to the SVP for the model development team, the Chief Security Officer, and legal counsel." "Amazon's senior leadership will review the plan for applying risk mitigations ... and approve the mitigations prior to deployment. Amazon's senior leadership will likewise review the safeguards evaluation report as part of a go/no-go decision." (s.4, p.5)
Named report-recipient roles, but the specific decision-maker within 'senior leadership' is not identified.
exact
confidence: high
Amazon Frontier Model Safety Framework
Cohere
Cohere Secure AI Frontier Model Framework
"The final authority to determine if our products are safe, secure, and ready to be made available to our customers is delegated by Cohere's CEO to Cohere's Chief Scientist. This decision is made on the basis of final, multi-faceted evaluations and testing." (p.15) A "bright line" acceptance test follows: "no significant regressions compared to our previously launched model versions" (p.16).exact
confidence: high
Cohere Secure AI Frontier Model Framework
NVIDIA
NVIDIA Frontier AI Risk Assessment
Sign-off level is tied directly to a numeric 1-5 model-risk (MR) score rather than to a named office -- "A detailed risk assessment should be complete and approved by an independent committee e.g. NVIDIA's AI ethics committee" at MR5, and "complete and business unit leader approval is required" at MR4 (p.2); the MR score "should not be reduced through typical risk mitigation measures," and "a frontier model would be classified as MR5" (p.3).close
confidence: medium
NVIDIA Frontier AI Risk Assessment

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →