Source of record
Where this definition comes from
Anthropic Risk Report, August 2026, §1
“We consider all of our models, including those we run only internally, in our assessment.”
https://www-cdn.anthropic.com/f61d49fa5596956a5dec75fea0e973bf6a6a8378/Redacted%20Risk%20Report%20August%202026%20.pdfGoogle DeepMind Frontier Safety Framework v3.1, glossary
“Internal Deployments: represent model releases restricted to Google employees for internal use.”
https://storage.googleapis.com/deepmind-media/DeepMind.com/Blog/strengthening-our-frontier-safety-framework/frontier-safety-framework_3-1.pdf
Crosswalk
How named organisations use this concept
| Organisation | Their term, as published | Match & verification | Source |
|---|---|---|---|
| AnthropicShadow mapping Anthropic Risk Report, August 2026 | “"We consider all of our models, including those we run only internally, in our assessment." "Note that for most models, including all early snapshots of models intended for eventual broad public release, we do not have strict technical safeguards on internal deployment"” | exactEQ confidence: high | Anthropic Risk Report, August 2026 |
| OpenAIShadow mapping Preparedness Framework v2 / Pacing Model Development (Cyber), Aug 2026 | “PF covered deployments include significant internal agentic systems; "Misalignment safeguards meeting the High standard (C.2) for large-scale internal deployment"; "Highest-risk workloads: 'internal deployments of frontier models and frontier RL training runs'"” | closeCL confidence: medium | OpenAI Preparedness Framework v2 |
| Google DeepMindShadow mapping Frontier Safety Framework v3.1 | “"Internal Deployments: represent model releases restricted to Google employees for internal use." "High-Risk Internal Deployments: ... for use cases with the potential to enable severe threat scenarios (e.g. building internal security infrastructure or automating ML R&D)."” | exactEQ confidence: high | Google DeepMind Frontier Safety Framework v3.1 |
| MetaShadow mapping Meta Advanced AI Scaling Framework v2 | “"Internal deployment: models that are exclusively available to Meta personnel"; "internal-use risk report" provided "as appropriate" to "relevant authorities"; "Loss of Control risks may occur with similar probability with any type of deployment, including internal deployment."” | exactEQ confidence: high | Meta Advanced AI Scaling Framework v2 |
| EUShadow mapping EU GPAI Code of Practice, Safety and Security Chapter / OpenAI Frontier Governance Framework | “The chapter applies across "the entire model lifecycle (including during development that occurs before and after a model has been placed on the market)" rather than singling out "internal deployment" as a separate category; Measure 3.2's model evaluations and Commitment 4's acceptance determination must be completed "at least before placing the model on the market" (Measure 1.2), leaving pre-market internal use inside the same process rather than exempted from it” Narrower coverage than OpenAI's FGF citation of this same chapter for internal-use oversight-circumvention risks specifically. | closeCL confidence: medium | EU GPAI Code of Practice, Safety and Security Chapter |
| California SB 53Shadow mapping California SB 53 | “Framework topic "(10) Assessing and managing catastrophic risk resulting from the internal use of its frontier models"; summaries to OES "every three months or pursuant to another reasonable schedule"; incident field "(4) Whether the incident was associated with internal use of a frontier model." "Internal use" is undefined.” SB 53 requires reporting on internal use but leaves the term "internal use" itself undefined — recorded, not silently dropped. | exactEQ confidence: high | California SB 53 |
| METRShadow mapping METR (metr.org) | “Frontier Risk Report participants provided "Access to their most capable internal model(s) at the time of assessment, including raw chains of thought"” | closeCL confidence: medium | METR |
What do these codes mean?
- exact
- The source term is equivalent to this element
- close
- The source term is close but not equivalent to this element
- broad
- The source term is broader than this element
- narrow
- The source term is narrower than this element
- none
- No mapping claim — used for false-friend and declared-but-undefined rows
- EQ
- Equivalent
- CL
- Close
- BR
- Source is broader than the element
- NR
- Source is narrower than the element
- FF
- False friend — same or similar label, different meaning
- DU
- Declared but undefined by the source
- UV
- Unverified







