Source of record
Where this definition comes from
Anthropic Risk Report, August 2026, §4.5, §4.5.2.2
“Coverage — the domain of usage a classifier is trained to catch”
https://www-cdn.anthropic.com/f61d49fa5596956a5dec75fea0e973bf6a6a8378/Redacted%20Risk%20Report%20August%202026%20.pdfGemini 3.7 Flash FSF Report, p.29
“Coverage: 'assuming threat actors don't try to circumvent these safeguards, how much assistance would they get from the model'”
https://storage.googleapis.com/deepmind-media/gemini/gemini_3-7_flash_fsf_report.pdf
Crosswalk
How named organisations use this concept
| Organisation | Their term, as published | Match | Source |
|---|---|---|---|
| Anthropic Anthropic Risk Report, August 2026 | “"Coverage — the domain of usage a classifier is trained to catch"; Fable 5's classifier covers "the vast majority of potentially dual use usage relevant to research biology"; "100% of a generated research-biology probe set versus 17% for the narrower classifier"” | exact confidence: high | Anthropic Risk Report, August 2026 |
| Google DeepMind Gemini 3.7 Flash FSF Report | “"Coverage: 'assuming threat actors don't try to circumvent these safeguards, how much assistance would they get from the model'"” | close confidence: medium | Gemini 3.7 Flash FSF Report |
| Frontier Model Forum FMF Third-Party Assessments | “"Evaluation coverage: 'identifying test categories, particular workflows, or user skill levels.'" This is coverage of an *evaluation*, not a safeguard.” False friend: FMF's "coverage" here names what an evaluation tests, not what a safeguard blocks. See divergence_note. | none confidence: medium | Frontier Model Forum, Third-Party Assessments |
Related, not mapped
Pointers that are not crosswalk claims
These sources mention this concept but do not define or map it clearly enough to count as a crosswalk row — noted here so the research is visible without overstating it as a mapping.
- OpenAI
Tier-one "fast, topical classifier model that determines whether or not the content is related to one of the two areas where we have deployed Preparedness Safeguards" — related, not a mapping (RL).
OpenAI GPT-5.6 System Card / Deployment Safety - xAI
Filters for "CRBN [sic] risks" — related, not a mapping (RL).
xAI Frontier AI Framework, 30 June 2026 (draft-labeled PDF metadata)
Divergence
Where sources materially disagree
FMF's "Evaluation coverage" is a false friend for this element: it describes the scope of an *evaluation* (which test categories, workflows, or user skill levels are probed), not the scope of a *safeguard* (what content or behavior a classifier is trained to catch). NIKOLAI's coverage-level element tracks safeguard scope only; evaluation coverage is a distinct concept that belongs under the evaluation record-type (N5), and the two must not be crosswalked to each other. See ALIGNMENT-MATRIX.md §3 E4, FMF row {FMF32}.
Gap
Anthropic and GDM independently separate coverage from robustness, which supports making them two elements. Anthropic's disclosed year-long gap (human-feedback vendor traffic "ran without blocking biological classifiers") was a coverage failure by deployment surface, not a robustness failure {RR}.







