Skip to main content
v2026.11,858 entries · CC-BY 4.0
NIKOLAI elementN6 · Mitigations and securityProposednikolai-v0.1

Internal deployment and internal-use risk

NIKOLAI proposes an Internal deployment risk record as: a developer's own use of a model inside the organisation — including agentic research use and training-time use — plus the assessment and any report that covers that use, distinguished from external/public deployment. This is an unsourced NIKOLAI editorial synthesis. Both 2026 incidents recorded in the source corpus originated in internal evaluation infrastructure, and "deploy"/"deployment" is itself a false-friend term across sources (SB 53 excludes access for the primary purpose of developing or evaluating a model from its statutory definition of deployment, while lab frameworks generally treat internal deployment as a form of deployment), which is why NIKOLAI proposes tracking internal deployment as its own record rather than folding it into a generic deployment-surface value.

This is CASRAI's own proposed definition, not a definition any named organisation has agreed to. See what NIKOLAI is and is not.

Source of record

Where this definition comes from

Crosswalk

How named organisations use this concept

Every row below is a shadow mapping. It is CASRAI's own reading of a published document. No lab, evaluator or regulator named here has declared, endorsed, or been consulted on this mapping. That will change only when an organisation files its own Mapping Declaration — see the non-endorsement policy.
OrganisationTheir term, as publishedMatchSource
Anthropic
Anthropic Risk Report, August 2026
"We consider all of our models, including those we run only internally, in our assessment." "Note that for most models, including all early snapshots of models intended for eventual broad public release, we do not have strict technical safeguards on internal deployment"exact
confidence: high
Anthropic Risk Report, August 2026
OpenAI
Preparedness Framework v2 / Pacing Model Development (Cyber), Aug 2026
PF covered deployments include significant internal agentic systems; "Misalignment safeguards meeting the High standard (C.2) for large-scale internal deployment"; "Highest-risk workloads: 'internal deployments of frontier models and frontier RL training runs'"close
confidence: medium
OpenAI Preparedness Framework v2
Google DeepMind
Frontier Safety Framework v3.1
"Internal Deployments: represent model releases restricted to Google employees for internal use." "High-Risk Internal Deployments: ... for use cases with the potential to enable severe threat scenarios (e.g. building internal security infrastructure or automating ML R&D)."exact
confidence: high
Google DeepMind Frontier Safety Framework v3.1
Meta
Meta Advanced AI Scaling Framework v2
"Internal deployment: models that are exclusively available to Meta personnel"; "internal-use risk report" provided "as appropriate" to "relevant authorities"; "Loss of Control risks may occur with similar probability with any type of deployment, including internal deployment."exact
confidence: high
Meta Advanced AI Scaling Framework v2
EU
EU GPAI Code of Practice, Safety and Security Chapter / OpenAI Frontier Governance Framework
The chapter applies across "the entire model lifecycle (including during development that occurs before and after a model has been placed on the market)" rather than singling out "internal deployment" as a separate category; Measure 3.2's model evaluations and Commitment 4's acceptance determination must be completed "at least before placing the model on the market" (Measure 1.2), leaving pre-market internal use inside the same process rather than exempted from it
Narrower coverage than OpenAI's FGF citation of this same chapter for internal-use oversight-circumvention risks specifically.
close
confidence: medium
EU GPAI Code of Practice, Safety and Security Chapter
California SB 53
California SB 53
Framework topic "(10) Assessing and managing catastrophic risk resulting from the internal use of its frontier models"; summaries to OES "every three months or pursuant to another reasonable schedule"; incident field "(4) Whether the incident was associated with internal use of a frontier model." "Internal use" is undefined.
SB 53 requires reporting on internal use but leaves the term "internal use" itself undefined — recorded, not silently dropped.
exact
confidence: high
California SB 53
METR
METR (metr.org)
Frontier Risk Report participants provided "Access to their most capable internal model(s) at the time of assessment, including raw chains of thought"close
confidence: medium
METR

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →