Source of record
Where this definition comes from
EU GPAI Code of Practice, Safety and Security Chapter, Appendix 1.4
“Appendix 1.4 "Specified systemic risks": "(1) Chemical, biological, radiological and nuclear ... (2) Loss of control ... (3) Cyber offence ... (4) Harmful manipulation: Risks from enabling the strategic distortion of human behaviour or beliefs by targeting large populations or high-stakes decision-makers through persuasion, deception, or personalised targeting ..." -- the taxonomy xAI's FAIF footnotes say it adopts.”
https://ec.europa.eu/newsroom/dae/redirection/document/118119Anthropic Advanced AI Framework, p.4
“"Enumerated Risk categories": "catastrophic risks related to (a) biological weapons, (b) offensive cyber operations, (c) loss of control, and (d) automated research and development in key domains that could accelerate or amplify risks (a)-(c)."”
https://www-cdn.anthropic.com/files/4zrzovbb/website/0a58d567024a8b448ff15158ebc3625328dfcc1f.pdfFrontier Model Forum, Risk Taxonomy and Thresholds technical report, s2.4, p.9
“"Chemical, Biological, Radiological, and Nuclear (CBRN) Threats", "Advanced Cyber Threats", "Advanced Autonomous Behavior Threats"”
https://www.frontiermodelforum.org/technical-reports/risk-taxonomy-and-thresholds/
Crosswalk
How named organisations use this concept
| Organisation | Their term, as published | Match | Source |
|---|---|---|---|
| Anthropic Risk Report / Advanced AI Framework | “Four threat models in three sections: misalignment in high-stakes settings (Autonomy TM1), automated R&D in key domains (TM2), CB-1 and CB-2 (para.). AAF "Enumerated Risk categories": "catastrophic risks related to (a) biological weapons, (b) offensive cyber operations, (c) loss of control, and (d) automated research and development in key domains that could accelerate or amplify risks (a)-(c)." (p.4)” | exact confidence: high | Anthropic Advanced AI Framework, legislative proposal |
| OpenAI Preparedness Framework v2 / Frontier Governance Framework | “PF "Tracked Categories": Biological and Chemical; Cybersecurity; AI Self-improvement. "Research Categories": Long-range Autonomy; Sandbagging; Autonomous Replication and Adaptation; Undermining Safeguards; Nuclear and Radiological (Tables 1 and 2). FGF risk categories: "Cyber offense", "CBRN", "Harmful manipulation", "Loss of control" (§2.1).” | exact confidence: high | OpenAI Preparedness Framework v2 |
| Google DeepMind Frontier Safety Framework v3.1 | “"CBRN", "Cyber", "Harmful Manipulation", "ML R&D and Misalignment" (glossary, p.18).” | exact confidence: high | Google DeepMind Frontier Safety Framework v3.1 |
| xAI Frontier AI Framework, 30 Jun 2026 | “"CBRN Risks", "Offensive Cybersecurity Risks", "Loss of Control Risks", "Harmful Manipulation Risks" (s.1), with fn 1: "Terminology used in the The Safety and Security Chapter of the General-Purpose AI Code of Practice developed under the EU AI Act." Harmful Manipulation notably has no "Addressing" subsection unlike the other three domains.” This source's PDF metadata /Title reads "Privileged/Confidential DRAFT working FRAMEWORK DOC"; no xAI statement disambiguating draft vs. final status was found (open [VERIFY] item in the source document's register). The EQ score covers the domain-naming match only; the missing "Addressing" subsection for Harmful Manipulation is itself a DU-type gap within this otherwise-EQ row. | exact confidence: high | xAI Frontier AI Framework, 30 Jun 2026 |
| Meta Advanced AI Scaling Framework v2 | “"Chemical & Biological, Cybersecurity, and Loss of Control" (preamble p.2). "Risk domain: is used to describe the thematic grouping that a set of catastrophic outcomes belong to" (Appendix I).” | exact confidence: high | Meta Advanced AI Scaling Framework v2 |
| EU Safety and Security chapter | “Appendix 1.4 "Specified systemic risks", verbatim: "(1) Chemical, biological, radiological and nuclear: Risks from enabling chemical, biological, radiological, and nuclear (CBRN) attacks or accidents ... (2) Loss of control: Risks from humans losing the ability to reliably direct, modify, or shut down a model ... (3) Cyber offence: Risks from enabling large-scale sophisticated cyber-attacks, including on critical systems ... (4) Harmful manipulation: Risks from enabling the strategic distortion of human behaviour or beliefs by targeting large populations or high-stakes decision-makers through persuasion, deception, or personalised targeting ..." -- the taxonomy xAI's FAIF footnotes say it adopts.” | exact confidence: high | EU GPAI Code of Practice, Safety and Security Chapter |
| California SB 53 SB 53 statute text | “Catastrophic-risk pathways: (A) CBRN "expert-level assistance"; (B) conduct "with no meaningful human oversight ... that is either a cyberattack or ... would constitute the crime of murder, assault, extortion, or theft"; (C) "Evading the control of its frontier developer or user" (22757.11(c)).” SB 53 frames these as incident *pathways* (mechanisms), not a domain taxonomy per se; mapped here as close because the pathways cluster along the same CBRN / cyber / loss-of-control lines as the other sources' domains. | close confidence: medium | California SB 53 |
| US Government (Executive Order 14409 / NIST CAISI) Executive Order 14409 / CAISI bulletin | “EO 14409 addresses only "advanced cyber capabilities" (Sec. 3(a)); CAISI frames its agreements as "Frontier AI National Security Testing".” | narrow confidence: medium | Executive Order 14409 |
| Frontier Model Forum Risk Taxonomy and Thresholds technical report | “"Chemical, Biological, Radiological, and Nuclear (CBRN) Threats", "Advanced Cyber Threats", "Advanced Autonomous Behavior Threats" (s2.4, p.9).” | exact confidence: high | Frontier Model Forum, Risk Taxonomy and Thresholds technical report |
| Safety Framework Cards (discovery) Safety Framework Cards (SSRN 7061798, unread/paywalled) | “"risk ontology" is one of six evaluation dimensions (secondary) [UV].” SFC full text is paywalled on SSRN and could not be read; the {DEV} discovery-sweep tag does not resolve to a single fetchable URL in the provided sources table. | none confidence: low | Discovery sweep: Safety Framework Cards (SSRN 7061798, unread/paywalled) |
| STREAM (discovery sweep) STREAM pilot (arXiv 2508.09853) | “"ChemBio only" (para.) [UV] -- STREAM's disclosure pilot is scoped to ChemBio benchmarks only, per the discovery sweep.” Cited via the compound {DEV} discovery-sweep tag, which does not resolve to a single fetchable URL in the provided sources table; STREAM's own arXiv id was read directly from the source document's open-VERIFY register (item 6) but no URL for it appears in the provided sources table. | none confidence: low | Discovery sweep: STREAM (arXiv 2508.09853) |
Divergence
Where sources materially disagree
Slug/track note: this element reuses the pre-existing "risk-domain" slug from the 25-element manifest, which was previously filed under track N2 ("Threat models and risk framing"). This cluster's explicit A-to-N1 track mapping instruction is followed here (track recorded as N1), but the mismatch with the slug's existing N2 placement should be reconciled at merge time, not silently overwritten.
Gap
"Harmful manipulation" is a domain in the FGF, FSF, FAIF and (reportedly) the Code, but it is exploratory or unaddressed in all three lab texts. "AI R&D" is a Tracked Category (OpenAI), part of a merged domain (GDM), a threat model (Anthropic) and an enabling capability under Loss of Control (Meta).







