Written and maintained by CASRAI Editorial Board
Last updated
“Frontier AI lab” is not a marketing label — it is increasingly a regulatory category. California’s SB 53 and the EU AI Act’s general-purpose-AI-with-systemic-risk designation both single out a small group of developers building the most capable models for extra obligations: publishing a frontier AI framework, running dangerous-capability evaluations, and reporting critical safety incidents. This page is a map, not a deep-dive: it lists the developers generally recognised as frontier labs under these regimes and, for each one, points to what safety framework or policy document they publish and where CASRAI already covers that framework in depth. For the underlying question of what makes a model itself “frontier,” see What Is a Frontier AI Model?
Who counts as a frontier AI lab
There is no single global list. Instead, several overlapping regimes each draw their own line, usually anchored to training compute, revenue, or a model’s assessed capability:
- California SB 53 (the Transparency in Frontier Artificial Intelligence Act) applies duties — including publishing a frontier AI framework and reporting critical safety incidents — to “large frontier developers” above a compute and revenue threshold. See California SB 53: The Frontier AI Transparency Act, Explained.
- The EU AI Act applies extra obligations to providers of a “general-purpose AI model with systemic risk” (GPAI-with-systemic-risk), a designation triggered primarily by training compute above 10^25 FLOP or a European Commission determination. See the EU AI Act’s GPAI Code of Practice, explained.
In practice, the developers that show up under both regimes — and that voluntarily publish their own safety commitments regardless of a specific legal trigger — are the same handful of companies training the largest general-purpose models. The sections below cover the ones most consistently named: OpenAI, Anthropic, Google DeepMind, Meta, and xAI.
The labs, and what each one publishes
Anthropic — Responsible Scaling Policy (RSP)
Anthropic publishes the Responsible Scaling Policy, the document that gave the whole category its informal name. The current version, RSP v3.4, took effect July 8, 2026. It defines capability thresholds (AI Safety Levels) and the safeguards that must be in place before Anthropic will train or deploy a model that crosses one. CASRAI covers it in full at Responsible Scaling Policy (RSP): What It Is and How the Major Labs Compare — that page also walks through the mechanism (capability thresholds, safeguard tiers, safety cases) shared across all three published frameworks below, so it isn’t repeated here.
OpenAI — Preparedness Framework
OpenAI publishes the Preparedness Framework, its own version of the same capability-threshold model: tracked risk categories, defined risk levels, and required safeguards before a model that crosses a threshold can ship. OpenAI has revised the framework more than once since its original 2023 publication. CASRAI’s cross-lab breakdown of how it lines up against Anthropic’s RSP and Google DeepMind’s Frontier Safety Framework is at RSP vs. Preparedness Framework vs. Frontier Safety Framework.
Google DeepMind — Frontier Safety Framework
Google DeepMind publishes the Frontier Safety Framework, described in its own announcement as “a set of protocols for proactively identifying future AI capabilities that could cause severe harm and putting in place mechanisms to detect and mitigate them.” It organises risk into four domains — autonomy, biosecurity, cybersecurity, and machine learning R&D — and pairs each with critical capability levels and early-warning evaluations. See the same three-way comparison page above for how it maps against the other two.
xAI — Risk Management Framework (Draft)
xAI publishes a document it calls the Risk Management Framework, currently in draft form and dated February 20, 2025: x.ai/documents/2025.02.20-RMF-Draft.pdf. Unlike the three frameworks above, xAI’s has not been finalized, and independent third-party review has been critical of it in its current form: the Future of Life Institute’s AI Safety Index (Summer 2025) graded xAI’s overall safety practices D (1.23/4.0) — fourth of the seven companies assessed — including a D+ specifically on published safety frameworks and an F on risk assessment, with reviewers recommending xAI “boost current draft safety framework to match the efforts by Anthropic and OpenAI.” CASRAI was not able to confirm the framework’s internal risk-domain structure (i.e., the specific risk categories and capability thresholds it defines, comparable to the detail available for the three frameworks above) from a source we could verify, and could not confirm whether a finalized, non-draft version has since been published — treat the primary document as authoritative over this summary, and check x.ai directly for anything more recent before citing it in a compliance review.
Meta — Advanced AI Scaling Framework (formerly the Frontier AI Framework)
Meta publishes the Advanced AI Scaling Framework: ai.meta.com/static-resource/Meta_Advanced-AI-Scaling-Framework-v2, now in its second iteration (Version 2) after Meta renamed it from its original title, the Frontier AI Framework, which Meta first published February 3, 2025 (announced at about.fb.com/news/2025/02/meta-approach-frontier-ai). Version 2 defines catastrophic outcomes and threat scenarios across three risk domains — Cybersecurity, Chemical & Biological, and Loss of Control (newly added versus the original v1/v1.1 Frontier AI Framework, which covered only the first two) — and assigns a model to one of three risk thresholds: Critical (stop development), High (do not release), or Moderate (release, subject to mitigations), based on whether the model would uniquely enable, or provide significant uplift toward, one of the identified threat scenarios. Meta says it will review the Framework at least annually.
How to read the comparison
All four verified frameworks above are voluntary, self-published policies, not law — SB 53 and the EU AI Act require that a framework exist and be disclosed, not that it take any particular form. That’s why the frameworks differ in vocabulary (AI Safety Levels vs. risk categories vs. critical capability levels vs. risk thresholds) while sharing the same underlying mechanism: define a capability threshold, evaluate for it, and commit to a safeguard before crossing it. CASRAI’s full side-by-side comparison walks through where Anthropic, OpenAI, and Google DeepMind’s three frameworks genuinely diverge; the SaferAI-based rubric at How to Grade a Frontier AI Safety Framework is the place to go if you need to assess how rigorous any one of them actually is, rather than just what it says.
Frontier labs also coordinate through industry bodies rather than only publishing solo policies — see Frontier Model Forum, Explained for the industry consortium several of these labs (including OpenAI, Anthropic, and Google DeepMind) co-founded to develop shared safety standards.
Why this matters for compliance teams
A research-compliance or vendor-risk team evaluating exposure to frontier-model risk — whether that’s procurement due diligence, an internal AI governance policy, or SB 53/EU AI Act mapping — runs into the same practical problem repeatedly: the labs don’t use the same vocabulary for the same underlying commitments, and not every lab has a framework a reviewer can actually find and cite. Knowing which developers are treated as “frontier” under which regime, which of them have a specific, named, currently-verifiable framework document, and where CASRAI’s own deep-dives already cover the substance of each one, is the first step before writing a framework into a vendor questionnaire or an internal policy as though its existence and content are settled facts. Treat a framework name you can’t independently verify the same way you’d treat any other unverified vendor claim — confirm it against the developer’s own current materials before relying on it.
How CASRAI’s NIKOLAI tracks this
The problem this page keeps running into — that SB 53, the EU AI Act, and each lab’s own framework define “frontier developer” and the compute or revenue line that triggers coverage in slightly different words for the same underlying idea — is exactly the gap CASRAI’s own NIKOLAI project exists to map. NIKOLAI’s Track N1 (Actors, Models and Scope) breaks that problem into named elements, including a Developer element (the legal person responsible for a model or safety artefact, defined per jurisdiction) and a Coverage Scope Threshold element (the compute-or-revenue-style if-then test deciding whether a given framework or statute applies to a developer at all) — the same kind of threshold SB 53 and the EU AI Act each draw above. NIKOLAI is CASRAI’s own independent, unendorsed reference dictionary; a crosswalk entry there is a shadow mapping unless a lab or regulator has filed its own Mapping Declaration confirming how its terms line up. Browse the track at NIKOLAI Track N1: Actors, Models and Scope, or the full dictionary at casrai.org/nikolai.
Frequently asked questions
What makes a developer a “frontier AI lab” rather than just an AI company?
Under SB 53 and the EU AI Act, it’s a function of the scale of what they train and release — compute thresholds, in most cases — not a subjective judgment about how advanced or risky their products seem. See What Is a Frontier AI Model? for how “frontier” is defined at the model level, which is what drives the developer-level designation.
Do all frontier labs publish a named safety framework?
Anthropic, OpenAI, Google DeepMind, and Meta each publish one CASRAI can name and link to a primary source for (see the sections above). xAI publishes a document called the Risk Management Framework, but as of this writing it remains in draft form and has been graded poorly by independent third-party review (see the xAI section above) — treat it as identifiable but not yet comparable in rigor to the four finalized frameworks. Always confirm directly with the developer before citing a specific framework name in a compliance document.
Are these frameworks legally binding?
No — they’re voluntary, self-published commitments. What SB 53 and the EU AI Act make mandatory is that a covered developer have and disclose some framework and report qualifying safety incidents; the content of the framework itself is the developer’s own choice, which is exactly why the three published frameworks above differ in structure and vocabulary despite covering the same underlying problem.







