Source of record
Where this definition comes from
Google DeepMind Frontier Safety Framework v3.1, s.2.1.1
“Security Level 2+ ... uses RAND Security Level 2 (SL2) as a baseline, with additional security measures designed to address risks from insider threats and well-resourced non-state external actors”
https://storage.googleapis.com/deepmind-media/DeepMind.com/Blog/strengthening-our-frontier-safety-framework/frontier-safety-framework_3-1.pdf
Crosswalk
How named organisations use this concept
| Organisation | Their term, as published | Match | Source |
|---|---|---|---|
| Anthropic Anthropic Risk Report, August 2026 | “"ASL-3 protections cover non-state attackers and *un*sophisticated insiders; sophisticated insiders and nation-state attackers remain out of scope"; industry recommendation at CB-2 implies "security roughly in line with RAND SL4"” "ASL" terminology survives here specifically for weight security even though Anthropic retired it for safeguard robustness/coverage elsewhere — see false-friends register. | close confidence: medium | Anthropic Risk Report, August 2026 |
| OpenAI OpenAI Preparedness Framework v2 / Pacing Model Development (Cyber), Aug 2026 | “"High standard (security / misuse / misalignment): referenced as 'meeting High standard (Appendix C.1/C.2/C.3)'"; "Critical standard ... not yet specified"; "the strictest level of security safeguards" (undefined levels)” | close confidence: medium | OpenAI Preparedness Framework v2 |
| Google DeepMind Frontier Safety Framework v3.1 | “"Security Level 2+ ... uses RAND Security Level 2 (SL2) as a baseline, with additional security measures designed to address risks from insider threats and well-resourced non-state external actors"; "Security level 3" and "Security level 4" descriptions; "RAND Security Levels"” | exact confidence: high | Google DeepMind Frontier Safety Framework v3.1 |
| xAI Frontier AI Framework, 30 Jun 2026 | “"Security Goal": "a documented Security Goal that identifies the threat actors against which mitigations are designed to protect against". No level.” xAI's Frontier AI Framework (30 Jun 2026) carries PDF metadata reading "Privileged/Confidential DRAFT working FRAMEWORK DOC" with no xAI statement found disambiguating draft from final; treat this citation as provisional. | narrow confidence: medium | xAI Frontier AI Framework, 30 June 2026 (draft-labeled PDF metadata) |
| Meta Meta Advanced AI Scaling Framework v2 | “"Initiate protocols for heightened access controls to model weights" (High and Critical, Table 1); not mapped to any scale” | narrow confidence: medium | Meta Advanced AI Scaling Framework v2 |
| EU EU GPAI Code of Practice, Safety and Security Chapter | “No graded security *level* scale (unlike GDM's SL2+/SL3/SL4). Instead, Measure 6.1 requires each Signatory to define a documented "Security Goal": "a goal that specifies the threat actors that their security mitigations are intended to protect against ('Security Goal'), including non-state external threats, insider threats, and other expected threat actors, taking into account at least the current and expected capabilities of their models"” Confirms xAI's adoption of this exact chapter term; the linked {FAIF26} carries the draft/final metadata caveat above. | close confidence: medium | EU GPAI Code of Practice, Safety and Security Chapter |
| METR METR (metr.org) | “"Model Weight Security: ... as models develop increasing capabilities of concern, progressively stronger information security measures are recommended"” | close confidence: medium | METR |
| G42 G42 Frontier Safety Framework | “"Security Mitigation Levels (SML)" 1-4” | close confidence: medium | G42 Frontier Safety Framework |
| Microsoft Microsoft Frontier Governance Framework, Feb 2026 | “Cites RAND security levels” | close confidence: medium | Microsoft Frontier Governance Framework, Feb 2026 |
Related, not mapped
Pointers that are not crosswalk claims
These sources mention this concept but do not define or map it clearly enough to count as a crosswalk row — noted here so the research is visible without overstating it as a mapping.
- SB 53 (California)
Framework topic "(7) Cybersecurity practices to secure unreleased model weights from unauthorized modification or transfer by internal or external parties." — related, not a mapping (RL).
California SB 53







