Source of record
Where this definition comes from
Google DeepMind Frontier Safety Framework v3.1, Glossary, p.18
“"we consider checkpoints and versions the same model if their base capabilities stem primarily from the same foundational training run, but will conduct additional testing on new versions as specified in Section 1.3"”
https://storage.googleapis.com/deepmind-media/DeepMind.com/Blog/strengthening-our-frontier-safety-framework/frontier-safety-framework_3-1.pdfMeta Advanced AI Scaling Framework v2, §4.2, §3.3.1
“"Asset": "the version of the model that we will test" (§4.2, p.26); non-material modifications "are presumed to inherit the same risk threshold as the underlying model" (§3.3.1, p.17).”
https://ai.meta.com/static-resource/Meta_Advanced-AI-Scaling-Framework-v2
Crosswalk
How named organisations use this concept
| Organisation | Their term, as published | Match | Source |
|---|---|---|---|
| Anthropic Risk Report | “"Covered models": the models an assessment section focuses on; in §2 these are "Claude Mythos 5 and Model 2" (para., §2.3). The source brief finds "No identifiers for anything" in the report.” | narrow confidence: medium | Anthropic Risk Report, August 2026 |
| OpenAI Hugging Face incident writeup / GPT-5.6 model card | “Pseudonymous internal model: "an internal-only research model that we will call Internal Model 1 (IM1)". Product tiers named Sol, Terra and Luna in the GPT-5.6 card.” | narrow confidence: medium | OpenAI, "Hugging Face incident and the road ahead" |
| Google DeepMind Frontier Safety Framework v3.1 | “Identity rule: "we consider checkpoints and versions the same model if their base capabilities stem primarily from the same foundational training run, but will conduct additional testing on new versions as specified in Section 1.3" (FSF glossary, p.18).” Falls under the "checkpoint" false-friend label: here it denotes a lifecycle version, distinct from Amodei's policy-rule sense or OpenAI's training-checkpoint sense of the same word. | close confidence: high | Google DeepMind Frontier Safety Framework v3.1 |
| xAI Grok 4.6 / Grok 4.20 model cards | “"Unless stated otherwise, evaluation results are on the final deployed checkpoint of Grok 4.6." (§1.1, p.5). Grok 4.20 modes: "single-agent (Grok 4.2 SA) or multi-agent (Grok 4.2 MA)" (S1).” | narrow confidence: medium | Grok 4.6 model card |
| Meta Advanced AI Scaling Framework v2 | “"Asset": "the version of the model that we will test" (§4.2, p.26). Inheritance rule: non-material modifications "are presumed to inherit the same risk threshold as the underlying model" (§3.3.1, p.17).” | close confidence: high | Meta Advanced AI Scaling Framework v2 |
| California SB 53 SB 53 statute text | “"a new frontier model or a substantially modified version of an existing frontier model" (22757.12(c)(1)). This is a class definition, not an identifier, and "substantially modified" is left undefined.” | broad confidence: medium | California SB 53 |
| US Government (Executive Order 14409) Executive Order 14409 | “"covered frontier model", designated "for the purposes of this order" by the Director of NSA (Sec. 3(a)). A designation class, not an identifier.” | broad confidence: medium | Executive Order 14409 |
Related, not mapped
Pointers that are not crosswalk claims
These sources mention this concept but do not define or map it clearly enough to count as a crosswalk row — noted here so the research is visible without overstating it as a mapping.
- Frontier Model Forum
Access items include "representative model version" and "near-identical model version" -- a pointer to how third-party assessors talk about model identity, not a mapping to a NIKOLAI identifier scheme.
Frontier Model Forum, Third-Party Assessments technical report
Divergence
Where sources materially disagree
"Checkpoint" is a false-friend label across this corpus (see source §4): a policy rule in Amodei's own essay, a training checkpoint in OpenAI's Preparedness Framework, a lifecycle checkpoint/version in GDM and xAI (as used in this element's rows), and the first stage of a two-stage Loss of Control evaluation in Meta's framework. NIKOLAI should not conflate these uses under one term.
Gap
No source publishes a machine-resolvable model identifier. GDM's "same foundational training run" rule and Meta's inheritance rule are the two existing identity rules and should be crosswalked explicitly.








