Skip to main content
v2026.11,858 entries · CC-BY 4.0

NIKOLAI’s Track System: A Map of the Frontier AI Safety Landscape (N1-N10)

Not sure which frontier-AI-safety guide covers your question? NIKOLAI, CASRAI’s own dictionary of frontier-AI-safety elements, organizes the whole topic space into 10 tracks (N1-N10). Start here, pick the track closest to your question, and follow the links.

Written and maintained by CASRAI Editorial Board

Last updated

Last verified: September 20, 2026. Frontier AI safety is not one topic — it is a dozen adjacent ones (capability thresholds, dangerous-capability evaluations, safeguards, incident reporting, third-party review, lab governance) that different people search for in different words. If you already know exactly which term you’re after, use CASRAI’s search. If you’re not sure which of CASRAI’s guides actually covers your question, this page is the faster route in: it uses the 10 tracks of NIKOLAI, CASRAI’s own frontier-AI-safety dictionary, as a map of the whole space, and links each track straight to the guides that cover it.

NIKOLAI (current release nikolai-v0.2) is CASRAI’s independent reference work defining 64 elements used across frontier-AI-safety frameworks — things like “capability threshold,” “evaluation run,” “safeguard,” and “incident reporting deadline” — organized into 10 tracks, N1 through N10. It is not affiliated with, run by, or endorsed by any AI lab, evaluator, or regulator: every row in NIKOLAI’s crosswalks is what CASRAI calls a shadow mapping — CASRAI’s own independent reading of what a lab or a statute has published — unless that organization has filed an explicit Mapping Declaration confirming how it actually uses the term. Below, each track gets a plain-language description of its scope and two or three links to the CASRAI guides that go deep on that territory. If your question doesn’t fit neatly under one track, it’s probably a sign the topic itself spans more than one — follow whichever track is the closest starting point.

N1 — Actors, Models and Scope

Before any safety commitment means anything, it has to answer: which developer, which model, on what deployment surface, as of what date, and under which framework version? N1 is where NIKOLAI tracks the scope-setting vocabulary — developer, model identifier, deployment surface, coverage date, framework version, risk domain, and threshold — that Anthropic’s Responsible Scaling Policy, OpenAI’s Preparedness Framework, and Google DeepMind’s Frontier Safety Framework each define slightly differently. CASRAI maps these definitions against each other via NIKOLAI; none of the three labs use NIKOLAI’s own N1 vocabulary internally.

Full track page: N1 — Actors, models and scope.

N2 — Threat Models and Risk Framing

Before a lab can set a capability threshold, it has to name what it’s actually worried about: who could misuse the model, through what mechanism, toward what harm. N2 is where NIKOLAI tracks that vocabulary — threat model, risk pathway, and threat-actor profile — as used across Anthropic, OpenAI, Google DeepMind, xAI, Meta, the EU’s GPAI Code of Practice, and California SB 53. CASRAI maps how each of these sources frames risk via NIKOLAI’s shadow mappings; it is not claiming any of them adopted NIKOLAI’s specific three-term structure.

Full track page: N2 — Threat models and risk framing.

N3 — Thresholds and Checkpoints

The capability threshold is the operational core of a Responsible Scaling Policy: the specific, testable point at which a model is judged to have crossed into a risk tier requiring new safeguards. N3 defines that vocabulary — capability threshold, threshold status, alert threshold, checkpoint rule, halt condition, and reassessment trigger — and CASRAI uses NIKOLAI to map how Anthropic, OpenAI, Google DeepMind, METR, and the US government each define and test against thresholds. A threshold is only as credible as the evaluation evidence behind it, which is why N3 depends directly on N5 below.

Full track page: N3 — Thresholds and checkpoints.

N4 — Claims and Argument

A safety case is the structured argument that a model’s risk is acceptably low — the connective layer between evaluation evidence and a go/no-go deployment decision. N4 defines that argument’s vocabulary: claim, safety case, likelihood term, risk level, confidence adjustment, residual risk and risk-acceptance determination, marginal-versus-absolute risk basis, and limitation. CASRAI tracks this vocabulary via NIKOLAI against how Anthropic, OpenAI, Google DeepMind, Meta, xAI, and NVIDIA each construct and publish their own safety arguments, and against the UK AI Security Institute’s own safety-case vocabulary and the 2026 International AI Safety Report.

Full track page: N4 — Claims and argument.

N5 — Evidence and Evaluations

Every capability threshold rests on a dangerous-capability evaluation, and an evaluation’s evidentiary weight depends on how hard the model was pushed to perform (elicitation method) and whether the benchmark still discriminates capability (saturation status). N5 defines that methodology vocabulary — evaluation, evaluation run, elicitation method, saturation status, and evaluation-validity threat — and CASRAI maps it via NIKOLAI against evaluation practice at Anthropic, OpenAI, Google DeepMind, METR, and the Frontier Model Forum, plus the EU GPAI Code of Practice’s own evaluation requirements.

Full track page: N5 — Evidence and evaluations.

N6 — Mitigations and Security

When a model crosses a threshold, something specific has to activate: a safeguard, at a defined robustness level, protected by security controls at a defined security level, with defined coverage and any exemptions documented. N6 covers that vocabulary — monitor, safeguard, robustness level, coverage level, exemption, security level, security control, mitigation change, and internal-deployment/internal-use risk — which CASRAI maps via NIKOLAI against safeguard specifications published by Anthropic, OpenAI, Google DeepMind, xAI, Meta, Amazon, Microsoft, and G42.

Full track page: N6 — Mitigations and security.

N7 — Incidents

Incident reporting is one of the few places frontier AI safety has moved from voluntary framework to binding law: California SB 53 and New York’s RAISE Act both set incident-reporting deadlines with named recipients. N7 defines incident, incident type, discovery method, and incident-reporting deadline and recipient, and CASRAI uses NIKOLAI to crosswalk that vocabulary against those two statutes plus how Anthropic, OpenAI, Google DeepMind, Meta, and xAI each describe their own incident-disclosure practice.

Full track page: N7 — Incidents.

N8 — Transparency and Review

An evaluation is only as credible as the conditions under which it was run: whether the evaluator was actually independent, what access it got, whether it can publish what it found, and what got redacted. N8 covers that infrastructure — evaluator independence and conflict of interest, evaluator access attestation, publication-rights clause, redaction and redaction reason, external review, and AI-model review — and CASRAI maps it via NIKOLAI against vocabulary used by METR, the UK AI Security Institute, and NIST’s CAISI, alongside requirements under California SB 53.

Full track page: N8 — Transparency and review.

N9 — Commitments and Governance

A frontier AI safety commitment only binds an organization if someone is named accountable for it and a defined protocol exists for updating it. N9 covers that governance layer — commitment, framework update protocol, roadmap item, pre-release sharing window, industry-wide recommendation, Mapping Declaration, accountable decision-maker and sign-off, and noncompliance and whistleblower reporting — and CASRAI maps it via NIKOLAI against public safety pledges from Anthropic, OpenAI, and Google DeepMind. This is also the track whose “accountable decision-maker and sign-off” element ties most directly to California SB 53’s named-role requirement.

Full track page: N9 — Commitments and governance.

N10 — Assurance Roles

N10 is different from every other track on this page. Tracks N1 through N9 define vocabulary drawn from what frontier-AI developers and regulators themselves publish. N10 instead describes NIKOLAI’s own governance process — who may file, review, or dispute a Mapping Declaration on this dictionary: declaring representative, CASRAI declaration reviewer, corroborating evaluator, disputant, and declaration accuracy steward. If you’re trying to understand how NIKOLAI’s crosswalks move from an unverified shadow mapping to an organization-confirmed declaration, this is the track that governs that process, not a track about accountability roles inside an AI lab’s own safety program (see N9 above for that).

Full track page: N10 — Assurance roles. To see the declaration process N10 governs in practice, visit NIKOLAI’s Mapping Declarations.

Why This Page Is Organized Around NIKOLAI

This page isn’t a NIKOLAI explainer bolted onto an unrelated list — the ten sections above are NIKOLAI’s own track taxonomy, used as the map. That’s worth being precise about: NIKOLAI is CASRAI’s own dictionary of 64 frontier-AI-safety elements across these 10 tracks (current release nikolai-v0.2), built and maintained independently by CASRAI. It is not a standard that any lab, evaluator, or regulator has adopted, endorsed, or been consulted on — every crosswalk row you’ll find on a NIKOLAI element or track page is a shadow mapping (CASRAI’s own reading of a published document) unless the organization in question has filed an explicit Mapping Declaration confirming how it actually uses that term in its own practice. When a track description above says CASRAI “tracks” or “maps” a concept via NIKOLAI against a specific framework, that is a claim about CASRAI’s independent classification work — not a claim that the framework itself is organized into NIKOLAI’s tracks. NIKOLAI also publishes a public v1 REST API and two MCP tools for programmatic access to the same element and crosswalk data described on this page.

Frequently Asked Questions

What is NIKOLAI?

NIKOLAI is CASRAI’s own dictionary of frontier-AI-safety terminology — 64 elements, organized into 10 tracks (N1 through N10), currently at release nikolai-v0.2. It defines terms like capability threshold, evaluation run, safeguard, and incident-reporting deadline, and crosswalks them against what individual labs and regulators have actually published.

Is NIKOLAI an official or endorsed industry standard?

No. NIKOLAI is CASRAI’s own independent reference work. No lab, evaluator, or regulator has endorsed NIKOLAI, reviewed one of its mappings, or been consulted on the dictionary. Every crosswalk is a shadow mapping — CASRAI’s own reading — unless the organization involved has filed an explicit Mapping Declaration confirming it.

I don’t know which track my question falls under — what should I do?

Read the one-paragraph scope description for each track above and pick whichever is closest; most real questions sit mostly inside one track even if they touch the edges of another (a threshold question, for example, usually also touches N5’s evaluation evidence). If two tracks both seem to fit, that’s a sign the underlying topic genuinely spans both — follow whichever track’s linked guides look closer to your specific question, and use that guide’s own related-reading links to reach the rest.

How is a NIKOLAI track different from a specific lab’s Responsible Scaling Policy?

An RSP (or Preparedness Framework, or Frontier Safety Framework) is a single lab’s own policy document, written in that lab’s own vocabulary. A NIKOLAI track is CASRAI’s independent category spanning multiple labs’ and regulators’ vocabulary at once, so that the same underlying concept — say, a capability threshold — can be compared across RSP v3.4, the Preparedness Framework, and the Frontier Safety Framework side by side.

How often is NIKOLAI updated?

NIKOLAI is versioned; the current release described on this page is nikolai-v0.2. Check the live NIKOLAI dictionary for the current version and element count, since both can change between releases.

Related Reading

Follow CASRAI

Research-administration guidance, standards updates and independent tool reviews.

Ask CASRAI · free to try

Ask about NIKOLAI’s Track System: A Map of the Frontier AI Safety Landscape (N1-N10)

Ask your first 2 questions free below. Subscribers get 150 a day for $29 a month.

Ask CASRAI answers research-administration questions and cites the passages behind every claim. When our sources don't cover a question, it says so.

Answers draw on CASRAI's guides and dictionary plus the federal and funder documents we index: Federal Register, Grants.gov, Regulations.gov and UKRI.

Works on this site and inside Claude, Cursor and the AI tools you already use.

Everything CASRAI publishes — this page, the dictionary, the guides and the news — stays free to read, with no account and no card.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →