Skip to main content
v2026.11,858 entries · CC-BY 4.0
NIKOLAI elementN2 · Threat models and risk framingProposednikolai-v0.1

Threat Model

NIKOLAI editorial proposal (unsourced): a threat-model record is the structured statement of who could cause which harm, by what means, with what role played by the AI system, at what magnitude of harm, together with the developer's stated rationale for prioritising that threat model over others considered. This is element B1 of the source crosswalk, folded into the already-drafted `threat-model` slug rather than kept separate.

This is CASRAI's own proposed definition, not a definition any named organisation has agreed to. See what NIKOLAI is and is not.

Source of record

Where this definition comes from

Crosswalk

How named organisations use this concept

Every row below is a shadow mapping. It is CASRAI's own reading of a published document. No lab, evaluator or regulator named here has declared, endorsed, or been consulted on this mapping. That will change only when an organisation files its own Mapping Declaration — see the non-endorsement policy.
OrganisationTheir term, as publishedMatchSource
Anthropic
Anthropic Risk Report, August 2026
"CB-1 threat model": "Individuals or small groups with limited resources use AI models to gain access to non-novel chemical or biological (CB) weapons, leading to the risk of catastrophic harm" (§4.1, §4.2.1). Prioritisation criteria: expected damages; "a clear role for AI in creating risk beyond what is created by other technologies and background conditions"; historical sanity checks; generalisability and poor early warning (§6.1).exact
confidence: high
Anthropic Risk Report, August 2026
OpenAI
OpenAI Preparedness Framework v2
"Threat model": for each Tracked Category, "identifying specific risks of severe harms that could arise from the frontier capabilities in that domain and sets corresponding capability thresholds" (§2.2, p.4); "SAG reviews and approves these threat models."close
confidence: high
OpenAI Preparedness Framework v2
Google DeepMind
Gemini 3.7 Flash FSF report
Report method terms: "Threat actor type", "Scenario" ("combinations of threat actor types and agents, weapons, or attacks"), "Harm journey" ("A breakdown of key stages and substages required to carry out such an attack end-to-end"), "Bottleneck sub-stages", "Web-only baseline" (report, p.8).close
confidence: high
Gemini 3.7 Flash FSF report
xAI
xAI Frontier AI Framework (30 Jun 2026)
"xAI has developed systemic risk scenarios that enumerate the causal factors, potential harms, and mitigations" (s.2.1), which are not published.
Source PDF's own metadata /Title reads "Privileged/Confidential DRAFT working FRAMEWORK DOC"; no xAI statement disambiguating draft vs. final was found. Any claim built on this row should carry that caveat forward.
none
confidence: medium
xAI Frontier AI Framework (30 Jun 2026, draft-marked)
Meta
Meta Advanced AI Scaling Framework v2
"Threat modeling: a structured process of identifying how Frontier AI could contribute to specific ... outcomes"; "Threat scenarios: describe the real-world events ... including enabling capabilities, deployment context, and threat actors (as relevant) ... that may be sufficient to produce a catastrophic outcome"; identifiers such as "Cyber 1" and "TS.1.1" (Appendix I; §3.4).exact
confidence: high
Meta Advanced AI Scaling Framework v2
EU
EU GPAI Code of Practice, Safety and Security chapter
Measure 2.2 "Systemic risk scenarios": "Signatories will develop appropriate systemic risk scenarios ... for each identified systemic risk," feeding Measure 3.3 "systemic risk modelling." No named identifier scheme and no publication requirement beyond the Model Report; confirms xAI's own footnote claim that its unpublished scenarios follow this chapter.
Row also cites xAI's Frontier AI Framework, whose PDF metadata is marked "DRAFT working FRAMEWORK DOC" with no disambiguating xAI statement found.
close
confidence: high
EU GPAI Code of Practice, Safety and Security chapter
Frontier Model Forum
FMF Risk Taxonomy and Thresholds
"Threat modeling: a process for systematically anticipating and identifying how various threat actors might leverage frontier AI to achieve harmful outcomes and mapping the potential pathways to those outcomes." "Threat scenarios": scenarios "that specify how adversaries might use frontier AI to achieve severe outcomes, identifying specific tasks, model capabilities to exploit, and complementary tools." (s2.1, pp.7-8)exact
confidence: high
FMF Risk Taxonomy and Thresholds
Safety Framework Cards (discovery)
Safety Framework Cards (SSRN 7061798)
"risk ontology" dimension named in discovery sweep; full text paywalled/unread.
Unverified: source document itself could not open the full text; recorded from discovery snippet only.
none
confidence: low
Discovery sweep — Safety Framework Cards (SSRN 7061798, paywalled/unread)

Gap

Only Meta assigns identifiers to threat scenarios, and Meta deliberately withholds "full details of the constituent steps and tasks within a threat scenario" (§3.4) {META}. NIKOLAI should separate a public identifier/summary from restricted detail.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →