Source of record
Where this definition comes from
EU GPAI Code of Practice, Safety and Security Chapter, Appendix 3.4/3.5; Appendix 2.2
“adequate access, information, time, and other resources, including access to model activations, gradients, logits (or other forms of raw model outputs), chains-of-thought, and/or other technical details, and access to the model version(s) with the fewest safety mitigations implemented (such as a helpful-only model version, if it exists); indicative time floor 'at least 20 business days is appropriate for most systemic risks and model evaluation methods.'”
https://ec.europa.eu/newsroom/dae/redirection/document/118119METR, engagement terms
“Each participant provided: Access to their most capable internal model(s) at the time of assessment, including raw chains of thought. Rate limits of at least 4M input tokens per minute, 1M output tokens per minute, and 1K requests per minute; zero data retention.”
https://metr.org/Executive Order 14409
“provide the Federal Government with access to covered frontier models, subject to appropriate confidentiality, cybersecurity, insider-risk, and intellectual-property protection, use, and nondisclosure requirements, for a period of up to 30 days.”
https://www.whitehouse.gov/presidential-actions/2026/06/promoting-advanced-artificial-intelligence-innovation-and-security/
Crosswalk
How named organisations use this concept
| Organisation | Their term, as published | Match & verification | Source |
|---|---|---|---|
| AnthropicShadow mapping Amodei "We Must Pace the Frontier" / alignment-assessment cybersecurity brief / Advanced AI Framework / Risk Report | “"ongoing, employee-like access to a team of embedded third-party evaluators"; access "mostly comparable to what internal risk assessment teams have" (office desks, badges, laptops). METR agreement: "wide-ranging access, including to transcripts beyond the window in which the incidents occurred, and to Anthropic employees, who will be permitted to share confidential information. Our initial agreement runs for eight weeks, with the option to extend by mutual agreement." AAF evaluator access: "access to an unredacted version of the developer's most recent risk report and system cards, access to the developer's most capable models, and the opportunity to ask and receive reasonable responses." Researchers with classifier exemptions must "attest to a list of Anthropic-provided security requirements."” Also cites {ALA}, {AAF}, {RR}. | closeCL confidence: medium | We Must Pace the Frontier (Amodei essay) |
| OpenAIShadow mapping Sam Altman post / GPT-5.6 deployment safety page / METR incident investigation | “Altman: "independent evaluators with employee-like access" is "a great idea" and "OpenAI will do the same." GPT-5.6: UK AISI "extensive grey box access" (s.9.4.6); SecureBio "evaluated two pre-release checkpoints of GPT-5.6 Sol and a railfree version." Incident investigation: "OpenAI attested that the transcripts we reviewed were unredacted."” Also cites {G56}, {METRHF}. | closeCL confidence: medium | Sam Altman post (X) |
| xAIShadow mapping Grok 4.6 model card / Grok 4.20 model card / Elon Musk post | “"We additionally provided an unrestricted configuration of Grok 4.6 to third-party evaluators" (§7); Grok 4.20 early snapshot. Musk: "Peer review of AI by competitors is the right way to start this off."” Also cites {G420}, {MUSK}. | narrowNR confidence: medium | Grok 4.6 model card |
| MetaShadow mapping Meta Advanced AI Scaling Framework v2 | “Preparedness reports describe "details about elicitation, time and resources spent, and access given to internal and external evaluators" (§2.2.1). A disclosure field, not an attestation.” | closeCL confidence: medium | Meta Advanced AI Scaling Framework v2 |
| EUShadow mapping EU GPAI Code of Practice, Safety and Security Chapter | “Appendix 3.4/3.5: independent external evaluators get "adequate access, information, time, and other resources", including "access to model activations, gradients, logits (or other forms of raw model outputs), chains-of-thought, and/or other technical details, and access to the model version(s) with the fewest safety mitigations implemented"; indicative time floor "at least 20 business days"; qualification requires domain expertise, security protocols and a confidentiality agreement. Post-market monitoring (Measure 3.5) separately guarantees "adequate free access" to the most capable deployed version, its CoT and its least-mitigated version, unless "similarly safe or safer" (Appendix 2.2).” | exactEQ confidence: high | EU GPAI Code of Practice, Safety and Security Chapter |
| US Government (Executive Order 14409 / NIST CAISI)Shadow mapping Executive Order 14409 / NIST CAISI bulletin | “"provide the Federal Government with access to covered frontier models, subject to appropriate confidentiality, cybersecurity, insider-risk, and intellectual-property protection, use, and nondisclosure requirements, for a period of up to 30 days." CAISI agreement terms are not public (gap).” Also cites {CAISI}. | closeCL confidence: medium | Executive Order 14409 |
| METRShadow mapping METR (site) | “"Each participant provided: Access to their most capable internal model(s) at the time of assessment, including raw chains of thought." Rate limits "of at least 4M input tokens per minute, 1M output tokens per minute, and 1K requests per minute"; zero data retention. "We believe that there should be full transparency about the terms of the engagement, including at least redaction terms, access provided, time and personnel provided, and agreed upon scope of the investigation."” | exactEQ confidence: high | METR |
| Frontier Model ForumShadow mapping FMF Third-Party Assessments technical report | “"Appropriate access: balances information needs with security considerations ... providing only the minimum information necessary"; "Security readiness: ... third-party assessors must demonstrate their capacity to responsibly handle privileged access before receiving it." No numbered access levels.” | closeCL confidence: medium | FMF Third-Party Assessments |
| AI Evaluator Forum (AEF-1, discovery sweep)Shadow mapping Discovery sweep | “Proposed access levels "AL1 black-box; AL2 grey-box; AL3 white-box" (arXiv 2601.11916); AEF-1 condition "Sufficient Access and Resources" (discovery).” Unverified discovery-stage material, not a primary-source developer commitment. | closeUV confidence: low | AI Evaluator Forum (AEF-1) / arXiv 2601.11916 discovery sweep |
What do these codes mean?
- exact
- The source term is equivalent to this element
- close
- The source term is close but not equivalent to this element
- broad
- The source term is broader than this element
- narrow
- The source term is narrower than this element
- none
- No mapping claim — used for false-friend and declared-but-undefined rows
- EQ
- Equivalent
- CL
- Close
- BR
- Source is broader than the element
- NR
- Source is narrower than the element
- FF
- False friend — same or similar label, different meaning
- DU
- Declared but undefined by the source
- UV
- Unverified
Related, not mapped
Pointers that are not crosswalk claims
These sources mention this concept but do not define or map it clearly enough to count as a crosswalk row — noted here so the research is visible without overstating it as a mapping.
- Google DeepMind
UK AISI MoU: "Sharing access to our proprietary models, data and ideas to accelerate research progress." Access depth and timing unstated -- RL, a pointer not a mapping.
DeepMind / UK AI Security Institute partnership post
Gap
*Gap to record:* METR's call for "full transparency about the terms of the engagement" is the only source that treats access terms as a publishable record. Amodei's commitment adds "access they did or did not receive" as publishable content. No template exists.







