Source of record
Where this definition comes from
Anthropic Risk Report, August 2026, §4.1, §2.11.1, §6.4.1 fn90
“CB-1: "Individuals or small groups with limited resources"; CB-2: "Moderately resourced threat actors (including, for example, expert-backed teams)" (§4.1). "Sophisticated insiders": "insiders who have persistent access or can request time-limited access to systems that process model weights" (§6.4.1 fn 90).”
https://www-cdn.anthropic.com/f61d49fa5596956a5dec75fea0e973bf6a6a8378/Redacted%20Risk%20Report%20August%202026%20.pdfGemini 3.7 Flash FSF report / FSF v3.1, report p.16
“Threat Actor Capability levels "TAC-1" ("programmer with limited cybersecurity knowledge (e.g., 'script kiddie')") to "TAC-4" ("95th+ percentile cybersecurity expert (e.g., nation-state-sponsored groups)") (report p.16).”
https://storage.googleapis.com/deepmind-media/gemini/gemini_3-7_flash_fsf_report.pdf
Crosswalk
How named organisations use this concept
| Organisation | Their term, as published | Match | Source |
|---|---|---|---|
| Anthropic Anthropic Risk Report, August 2026 | “CB-1: "Individuals or small groups with limited resources"; CB-2: "Moderately resourced threat actors (including, for example, expert-backed teams)" (§4.1). "Medium-strength attacker": "an attacker with the strength that a human red-teamer shows when editing a transcript without iterating against a monitor ..." (§2.11.1). "Sophisticated insiders": "insiders who have persistent access or can request time-limited access to systems that process model weights" (§6.4.1 fn 90).” | exact confidence: high | Anthropic Risk Report, August 2026 |
| OpenAI Preparedness Framework v2 / GPT-5.6 deployment safety report | “"Novice actor (Bio): anyone with a basic relevant technical background" (Table 1). Critical: "The model can enable an expert to develop a highly dangerous novel threat vector" (Table 1). GPT-5.6: "Spray and pray operations": "broad exploitation by moderately skilled, low-resourced individuals and small groups" (s.9.4.1.2).” | close confidence: high | OpenAI Preparedness Framework v2 |
| Google DeepMind Gemini 3.7 Flash FSF report / FSF v3.1 | “"Provides low to medium resourced actors uplift in reference scenarios" (CBRN Uplift 1 CCL). Threat Actor Capability levels "TAC-1" ("programmer with limited cybersecurity knowledge (e.g., 'script kiddie')") to "TAC-4" ("95th+ percentile cybersecurity expert (e.g., nation-state-sponsored groups)") (report p.16). FSF refers to RAND "OC3 groups" without defining them (p.11).” | exact confidence: high | Gemini 3.7 Flash FSF report |
| xAI xAI Frontier AI Framework (30 Jun 2026) | “Security Goal threat actors: "sophisticated non-state actors, insider threats, state-sponsored actors and other foreseeable actors" (s.2.4). This is a security-only construct, narrower than the malicious-use threat-actor profiles used elsewhere in the corpus.” PDF metadata /Title reads "Privileged/Confidential DRAFT working FRAMEWORK DOC"; no xAI statement disambiguating draft vs. final was found. | narrow confidence: medium | xAI Frontier AI Framework (30 Jun 2026, draft-marked) |
| Meta Meta Advanced AI Scaling Framework v2 | “Scenarios cover "both state and non-state actors" and distinguish "high- and low-skill actors" (para., §1.1); CB 1: "Proliferation of known medium-impact biological or chemical weapons for low and moderate skill actors" (§3.4).” | close confidence: high | Meta Advanced AI Scaling Framework v2 |
| EU EU GPAI Code of Practice, Safety and Security chapter | “Measure 6.1 "Security Goal": Signatories "will define a goal that specifies the threat actors that their security mitigations are intended to protect against ..., including non-state external threats, insider threats, and other expected threat actors, taking into account at least the current and expected capabilities of their models" — a security-only threat-actor construct, distinct from malicious-use threat-actor profiles used elsewhere in the corpus, confirming xAI's own adoption of the same term.” Row also cites xAI's Frontier AI Framework, whose PDF metadata is marked "DRAFT working FRAMEWORK DOC" with no disambiguating xAI statement found. | close confidence: high | EU GPAI Code of Practice, Safety and Security chapter |
Related, not mapped
Pointers that are not crosswalk claims
These sources mention this concept but do not define or map it clearly enough to count as a crosswalk row — noted here so the research is visible without overstating it as a mapping.
- Frontier Model Forum
"Heightened Marginal Risk" examples (e.g. "enabling low-skilled actors to build chemical weapons previously restricted to well-resourced states") and FMF35's "Threats" examples that mention "potential threat actors" are related context, not a defined threat-actor-profile construct — scored RL (related, not a mapping) in the source document.
FMF Risk Taxonomy and Thresholds / Information Sharing, Incident Reporting and Incident Response







