Source of record
Where this definition comes from
Amodei, "We Must Pace the Frontier" / Anthropic Advanced AI Framework, AAF p.8
“Evaluators may publish key findings on risk levels, incidents, practices and access received or not received 'without editorial control by Anthropic.' AAF: evaluators are 'bound by obligations not to copy, retain, or disclose confidential information ..., but beyond that should generally not be restricted in what they can publish, including concerns about the risk report or the developer's conduct in connection with the review process.'”
https://darioamodei.com/post/we-must-pace-the-frontierEU GPAI Code of Practice, Safety and Security Chapter, Measure 3.5; Commitment 7/Measure 7.4
“Signatories will not take any legal or technical retaliation against the independent external evaluators as a consequence of their testing and/or publication of findings ... the Signatory's 'publicly available procedure for responsible vulnerability disclosure ... will specify at least that the Signatory cannot delay or block publication for more than 30 business days from the date that the Signatory is made aware of the findings, unless a longer timeline is exceptionally necessary.'”
https://ec.europa.eu/newsroom/dae/redirection/document/118119
Crosswalk
How named organisations use this concept
| Organisation | Their term, as published | Match | Source |
|---|---|---|---|
| Anthropic Amodei "We Must Pace the Frontier" / Advanced AI Framework | “Evaluators may publish key findings on risk levels, incidents, practices and access received or not received "without editorial control by Anthropic." AAF: evaluators are "bound by obligations not to copy, retain, or disclose confidential information ..., but beyond that should generally not be restricted in what they can publish, including concerns about the risk report or the developer's conduct in connection with the review process." (p.8)” Also cites {AAF}. | exact confidence: high | We Must Pace the Frontier (Amodei essay) |
| EU EU GPAI Code of Practice, Safety and Security Chapter | “Measure 3.5 (post-market monitoring): Signatories "will not take any legal or technical retaliation against the independent external evaluators as a consequence of their testing and/or publication of findings" as long as the evaluator meets five conditions, including adherence to "the Signatory's publicly available procedure for responsible vulnerability disclosure, which will specify at least that the Signatory cannot delay or block publication for more than 30 business days from the date that the Signatory is made aware of the findings, unless a longer timeline is exceptionally necessary." Commitment 7/Measure 7.4: evaluators "maintain control over the publication of their findings, without implicit endorsement by the Signatories of the content of such reports."” | exact confidence: high | EU GPAI Code of Practice, Safety and Security Chapter |
| METR METR (site) / OpenAI-Hugging Face incident investigation | “"Publish all research and risk assessments 'where possible'"; Frontier Risk Report: "participants gave written approval for the final text of these appendices."” | close confidence: medium | METR |
| AI Evaluator Forum (AEF-1, discovery sweep) Discovery sweep | “AEF-1 sub-elements "editorial control", "disclosure rights", "no contingent release", "timely disclosure" (discovery).” Unverified discovery-stage material. | close confidence: low | AI Evaluator Forum (AEF-1) discovery sweep |
Related, not mapped
Pointers that are not crosswalk claims
These sources mention this concept but do not define or map it clearly enough to count as a crosswalk row — noted here so the research is visible without overstating it as a mapping.
- OpenAI
No clause in PF or FGF; Altman's post gives no publication terms (brief gap). In the METR investigation: "OpenAI was able to redact any non-public information from this post. We worked with OpenAI to find mutually agreeable language to describe redactions." GPT-5.6 card: "The following is OpenAI's summary of the report" (METR section) -- RL, a pointer not a mapping.
Sam Altman post (X); METR OpenAI-Hugging Face incident investigation; GPT-5.6 deployment safety page - Google DeepMind
UK AISI partnership includes "Joint reports and publications sharing findings with the research community"; whether AISI has independent publication rights is unstated -- RL, a pointer not a mapping.
DeepMind / UK AI Security Institute partnership post
Gap
*Note added on revision (source document):* the EU chapter's Measure 3.5 safe-harbour/non-retaliation clause, with its numbered evaluator conditions and a 30-business-day disclosure-delay ceiling, is the single most concrete publication-rights text found anywhere in this corpus -- more concrete than Amodei's essay or Anthropic's Advanced AI Framework, neither of which gives a numeric disclosure clock. Separately, the Frontier Model Forum's Third-Party Assessments report is noted as explicitly setting out no publication-rights regime at all, an informative absence rather than a mapping.







