Source of record
Where this definition comes from
Anthropic Risk Report, August 2026, §2.2.1, §2.13
“Eight "priority risk pathways": "diffuse sandbagging on safety R&D; targeted undermining of safety R&D; code backdoors; training-data poisoning; self-exfiltration; persistent rogue internal deployment; undermining R&D at other developers; undermining decisions within major governments" (§2.2.1). "We aren't able to defend the choice of these pathways rigorously" (§2.13).”
https://www-cdn.anthropic.com/f61d49fa5596956a5dec75fea0e973bf6a6a8378/Redacted%20Risk%20Report%20August%202026%20.pdfGoogle DeepMind Frontier Safety Framework v3.1, s.1.2
“CCLs are "determined by identifying and analyzing the main foreseeable paths through which a model could cause severe harm" (FSF s.1.2).”
https://storage.googleapis.com/deepmind-media/DeepMind.com/Blog/strengthening-our-frontier-safety-framework/frontier-safety-framework_3-1.pdf
Crosswalk
How named organisations use this concept
| Organisation | Their term, as published | Match | Source |
|---|---|---|---|
| Anthropic Anthropic Risk Report, August 2026 | “Eight "priority risk pathways": "diffuse sandbagging on safety R&D; targeted undermining of safety R&D; code backdoors; training-data poisoning; self-exfiltration; persistent rogue internal deployment; undermining R&D at other developers; undermining decisions within major governments" (§2.2.1). "We aren't able to defend the choice of these pathways rigorously" (§2.13).” | exact confidence: high | Anthropic Risk Report, August 2026 |
| OpenAI Preparedness Framework v2 / Path to Astra | “Safeguards Report contents: "Identified ways a risk of severe harm can be realized for the given deployment, each mapped to the associated security controls and safeguards" (PF §4.2). Astra: "Risk pathways (cyber)": "(1) a malicious actor using Astra to develop novel exploits ... or (2) the model itself causing cyber harm when taking an unauthorized (or misaligned) action." (s.10.2)” | close confidence: high | OpenAI Preparedness Framework v2 |
| Google DeepMind Gemini 3.7 Flash FSF report / FSF v3.1 | “CCLs are "determined by identifying and analyzing the main foreseeable paths through which a model could cause severe harm" (report p.2; FSF s.1.2).” | close confidence: high | Google DeepMind Frontier Safety Framework v3.1 |
| xAI xAI Frontier AI Framework (30 Jun 2026) | “"These risk domains describe principal pathways through which severe or systemic harm may arise." (s.2.1). Here "pathway" names the risk domain itself, not a finer-grained causal route beneath it.” PDF metadata /Title reads "Privileged/Confidential DRAFT working FRAMEWORK DOC"; no xAI statement disambiguating draft vs. final was found. This row is also confirmed by the source document's own false-friends register ("pathway": Anthropic's eight fine-grained misalignment routes vs. xAI's risk domains themselves vs. SB 53's three incident mechanisms). | none confidence: high | xAI Frontier AI Framework (30 Jun 2026, draft-marked) |
| Meta Meta Advanced AI Scaling Framework v2 | “Threat modeling "identifies the potential causal pathways for realizing the catastrophic outcome" (Appendix I).” | close confidence: high | Meta Advanced AI Scaling Framework v2 |
| California SB 53 California SB 53 | “Catastrophic risk arises from "a single incident involving a frontier model doing any of the following: (A) ... (B) ... (C) ..." (22757.11(c)) — a broader, outcome-defined construct than a specific causal pathway.” | broad confidence: medium | California SB 53 |
| Frontier Model Forum FMF Risk Taxonomy and Thresholds | “Threat modeling includes "mapping the potential pathways to those outcomes"; "Credibility: There is a credible pathway to extreme harm." (s1.3, s2.1)” | close confidence: high | FMF Risk Taxonomy and Thresholds |
Divergence
Where sources materially disagree
xAI's Frontier AI Framework uses "pathway" as a synonym for its risk domains themselves (s.2.1), not as a finer-grained causal route beneath a domain/threat-model as in Anthropic's eight priority risk pathways, OpenAI's Astra risk pathways, or Meta's causal pathways — a false-friend label collision, confirmed by the source document's own false-friends register ("pathway": Anthropic eight fine-grained misalignment routes vs. xAI's risk domains themselves vs. SB53's three incident mechanisms). {RR} {FAIF26} {SB53}







