Source of record
Where this definition comes from
Anthropic Risk Report, August 2026, §6.4.2
“including egress bandwidth controls, multi-party (2PC) access approval, binary allowlisting, hardware security keys, device authorisation, hourly re-authentication for privileged cloud identities, and network source policies”
https://www-cdn.anthropic.com/f61d49fa5596956a5dec75fea0e973bf6a6a8378/Redacted%20Risk%20Report%20August%202026%20.pdfEU GPAI Code of Practice, Safety and Security Chapter, Appendix 4.1-4.5
“protection of unreleased model parameters (a "secure internal registry", encryption "with at least 256-bit security" with keys "stored securely on a Trusted Platform Module (TPM)", confidential computing via "hardware-based, and attested trusted execution environments")”
https://ec.europa.eu/newsroom/dae/redirection/document/118119
Crosswalk
How named organisations use this concept
| Organisation | Their term, as published | Match | Source |
|---|---|---|---|
| Anthropic Anthropic Risk Report, August 2026 | “Ten notable controls "including egress bandwidth controls, multi-party (2PC) access approval, binary allowlisting, hardware security keys, device authorisation, hourly re-authentication for privileged cloud identities, and network source policies"; 2PC: "Requires a second employee to approve access requests for model weights and other sensitive resources"” | exact confidence: high | Anthropic Risk Report, August 2026 |
| OpenAI OpenAI Preparedness Framework v2 / Frontier Governance Framework | “C.3 practice families: "Security Threat Modeling and Risk Management; Defense in Depth; Access Management; Secure Development and Supply Chain; Operational Security; Auditing and Transparency"; FGF categories: "Protection of unreleased model weights; Hardening interface-access to unreleased model parameters; Insider threats; Security assurance"” | exact confidence: high | OpenAI Preparedness Framework v2 |
| Google DeepMind Frontier Safety Framework v3.1 | “SL2+ measures: "dedicated insider risk teams; background checks and ID verification for personnel with sensitive access; review of model training data for signs of tampering; mandating that the processing of untrusted inputs occurs within sandboxed environments; advanced red-teaming that simulates well-resourced adversaries ...; and proactive threat hunting with 24/7 incident response capabilities"” | exact confidence: high | Google DeepMind Frontier Safety Framework v3.1 |
| xAI Frontier AI Framework, 30 Jun 2026 | “"xAI has implemented appropriate information security standards, adopted based on the NIST 800-171 Rev.3 framework and supported by SOC 2 Type II evaluations." Measures include weight encryption, RBAC and anti-distillation” xAI's Frontier AI Framework (30 Jun 2026) carries PDF metadata reading "Privileged/Confidential DRAFT working FRAMEWORK DOC" with no xAI statement found disambiguating draft from final; treat this citation as provisional. | close confidence: medium | xAI Frontier AI Framework, 30 June 2026 (draft-labeled PDF metadata) |
| Meta Meta Advanced AI Scaling Framework v2 | “Weight access controls only (Table 1)” | narrow confidence: medium | Meta Advanced AI Scaling Framework v2 |
| California SB 53 California SB 53 | “Framework topic "(7) Cybersecurity practices to secure unreleased model weights from unauthorized modification or transfer by internal or external parties."” | broad confidence: medium | California SB 53 |
| METR METR (metr.org) | “"Model Weight Security" (element level)” | broad confidence: medium | METR |
| EU EU GPAI Code of Practice, Safety and Security Chapter | “Appendix 4.1-4.5 lists specific, numbered security-mitigation objectives and measures: general security (MFA, zero-trust, phishing defences); protection of unreleased model parameters (a "secure internal registry", encryption "with at least 256-bit security" with keys "stored securely on a Trusted Platform Module (TPM)", confidential computing via "hardware-based, and attested trusted execution environments"); hardening interface access (access reviews "at least every six months"); insider threats (background checks, sandboxing against self-exfiltration, training-data tamper checks); and security assurance (independent external security reviews, red-teaming, bug bounties, EDR/IDS tooling, a security team for incident handling)” | exact confidence: high | EU GPAI Code of Practice, Safety and Security Chapter |
| Amazon Amazon, Frontier Model Safety Framework | “Secure compute (EC2 Nitro, isolated VPCs; "Zero Operator Access" services where "AWS has entirely eliminated all human access to service hosts", validated by an NCC Group third-party design review), data protection (AES-256 GCM, FIPS 140-2 Level 3 KMS, "Critical Permission Groups" that are "regularly audited"), two-person rules governing "all code check-ins", and a mandatory central-team "full security and safety review" for "all software and AI projects"” | exact confidence: high | Amazon, Frontier Model Safety Framework |
Related, not mapped
Pointers that are not crosswalk claims
These sources mention this concept but do not define or map it clearly enough to count as a crosswalk row — noted here so the research is visible without overstating it as a mapping.
- Frontier Model Forum
"Threats" information category includes "cyber-threat indicators" (Table 2) — related, not a mapping (RL).
Frontier Model Forum, Information Sharing / Incident Reporting Issue Brief







