Source of record
Where this definition comes from
OpenAI Preparedness Framework v2, fn 1, p.1
“"By 'severe harm' in this document, we mean the death or grave injury of thousands of people or hundreds of billions of dollars of economic damage."”
https://cdn.openai.com/pdf/18a02b5d-6b67-4cec-ab64-68cdfbddebcd/preparedness-framework-v2.pdfCalifornia SB 53, 22757.11(c); 22757.16
“materially contribute to the death of, or serious injury to, more than 50 people or more than one billion dollars ($1,000,000,000) in damage to, or loss of, property arising from a single incident"; "The loss of value of equity does not count as damage to or loss of property"”
https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202520260SB53
Crosswalk
How named organisations use this concept
| Organisation | Their term, as published | Match | Source |
|---|---|---|---|
| OpenAI Preparedness Framework v2 / Frontier Governance Framework | “"By 'severe harm' in this document, we mean the death or grave injury of thousands of people or hundreds of billions of dollars of economic damage." (PF fn 1, p.1). FGF: "risks that a model will materially contribute to greater than 50 fatalities or $1 billion of property damages or losses arising from a single incident" (§2.1, p.03).” PF's own "thousands of people" threshold and FGF's "50 fatalities" threshold are two different magnitudes within the same organization's own documents. | exact confidence: high | OpenAI Preparedness Framework v2 |
| Google DeepMind Frontier Safety Framework v3.1 | “"severe" versus "significant" harm are used but not quantified (source brief gap note: "No quantitative definition of 'acceptable' risk, 'severe' versus 'significant' harm, or 'safety buffer'").” | none confidence: medium | Google DeepMind Frontier Safety Framework v3.1 |
| xAI Risk Management Framework, Aug 2025 (superseded) / Frontier AI Framework, 30 Jun 2026 | “Aug 2025 RMF (superseded): "In this RMF, we particularly focus on requests that pose a foreseeable and non-trivial risk of more than one hundred deaths or over $1 billion in damages from weapons of mass destruction or cyberterrorist attacks on critical infrastructure ('catastrophic malicious use events')." The June 2026 FAIF has no magnitude at all.” This row also cites the current {FAIF26} document as the (magnitude-free) successor. {FAIF26}'s PDF metadata /Title reads "Privileged/Confidential DRAFT working FRAMEWORK DOC"; no xAI statement disambiguating draft vs. final status was found (open [VERIFY] item in the source document's register). | close confidence: medium | xAI Risk Management Framework, 20 Aug 2025 (superseded) |
| Meta Advanced AI Scaling Framework v2 | “"Catastrophic outcomes: outcomes that would have large scale, devastating, and potentially irreversible harmful impacts on humanity that could plausibly be realized as a direct result of access to Frontier AI in the future." (Appendix I). No numbers given.” | close confidence: medium | Meta Advanced AI Scaling Framework v2 |
| California SB 53 SB 53 statute text | “"materially contribute to the death of, or serious injury to, more than 50 people or more than one billion dollars ($1,000,000,000) in damage to, or loss of, property arising from a single incident" (22757.11(c)); "The loss of value of equity does not count as damage to or loss of property" (22757.16).” | exact confidence: high | California SB 53 |
| Frontier Model Forum Risk Taxonomy and Thresholds technical report | “"Severity and Scale: ... Although no standardized quantitative definition exists across all AI developers, frontier AI frameworks prioritize risks with catastrophic potential, meaning severe harm to many people or large-scale economic damage (i.e., tens of billions of dollars)." (s1.3, p.4). Also cites UK NRR "more than 1,000 fatalities".” | close confidence: medium | Frontier Model Forum, Risk Taxonomy and Thresholds technical report |
| Amazon Amazon's Frontier Model Safety Framework | “"Critical Capability Thresholds describe model capabilities within specified risk domains that could cause severe public safety risks" (s.1, p.2); the CBRN threshold example speaks of a model that "would enable a non-subject matter expert to reliably produce and deploy a CBRN weapon" (s.1, p.2). No numeric death or dollar magnitude anywhere in the Framework.” | none confidence: medium | Amazon's Frontier Model Safety Framework |
Related, not mapped
Pointers that are not crosswalk claims
These sources mention this concept but do not define or map it clearly enough to count as a crosswalk row — noted here so the research is visible without overstating it as a mapping.
- Anthropic
"Catastrophic risk ... refers generally to risks of the most severe potential harms from advanced AI, such as existential threats or fundamental destabilization of global systems. We use this term in its plain meaning rather than adopting any specific statutory definition." (§1, fn 1). The AAF recommends a definition "in line with the definition provided in California SB 53" (p.4, fn 2) -- a pointer to SB 53's definition rather than an independent magnitude.
Anthropic Risk Report, August 2026 / Advanced AI Framework
Divergence
Where sources materially disagree
"Threshold" itself is a false-friend label across this corpus (see source §4), covering: a capability threshold (PF, FSF, METR, FMF); a risk threshold (Meta); a "systemic risk tier" (EU chapter Measure 4.1); a deployment-acceptance criterion (xAI 2025); a classified designation threshold (EO 14409); an intolerable-risk threshold (Seoul); and an undefined requirement (SB 53). This element specifically concerns the harm-magnitude sense only, not capability or deployment thresholds.
Gap
The figures differ by an order of magnitude or more (more than 50 deaths; more than 100 deaths; "thousands"; more than 1,000). NIKOLAI should record the magnitude as a structured value with units, the "single incident" qualifier and the exclusions, not as prose.







