Skip to main content
v2026.11,858 entries · CC-BY 4.0
NIKOLAI elementN6 · Mitigations and securityProposednikolai-v0.1

Internal deployment and internal-use risk

NIKOLAI proposes an Internal deployment risk record as: a developer's own use of a model inside the organisation — including agentic research use and training-time use — plus the assessment and any report that covers that use, distinguished from external/public deployment. This is an unsourced NIKOLAI editorial synthesis. Both 2026 incidents recorded in the source corpus originated in internal evaluation infrastructure, and "deploy"/"deployment" is itself a false-friend term across sources (SB 53 excludes access for the primary purpose of developing or evaluating a model from its statutory definition of deployment, while lab frameworks generally treat internal deployment as a form of deployment), which is why NIKOLAI proposes tracking internal deployment as its own record rather than folding it into a generic deployment-surface value.

This is CASRAI's own proposed definition, not a definition any named organisation has agreed to. See what NIKOLAI is and is not.

Source of record

Where this definition comes from

Crosswalk

How named organisations use this concept

Every row below is a shadow mapping. A shadow row is CASRAI's own reading of a published document. No lab, evaluator or regulator named on a shadow row has declared, endorsed, or been consulted on it. That changes only when an organisation files its own Mapping Declaration.
OrganisationTheir term, as publishedMatch & verificationSource
AnthropicShadow mapping
Anthropic Risk Report, August 2026
"We consider all of our models, including those we run only internally, in our assessment." "Note that for most models, including all early snapshots of models intended for eventual broad public release, we do not have strict technical safeguards on internal deployment"exactEQ
confidence: high
Anthropic Risk Report, August 2026
OpenAIShadow mapping
Preparedness Framework v2 / Pacing Model Development (Cyber), Aug 2026
PF covered deployments include significant internal agentic systems; "Misalignment safeguards meeting the High standard (C.2) for large-scale internal deployment"; "Highest-risk workloads: 'internal deployments of frontier models and frontier RL training runs'"closeCL
confidence: medium
OpenAI Preparedness Framework v2
Google DeepMindShadow mapping
Frontier Safety Framework v3.1
"Internal Deployments: represent model releases restricted to Google employees for internal use." "High-Risk Internal Deployments: ... for use cases with the potential to enable severe threat scenarios (e.g. building internal security infrastructure or automating ML R&D)."exactEQ
confidence: high
Google DeepMind Frontier Safety Framework v3.1
MetaShadow mapping
Meta Advanced AI Scaling Framework v2
"Internal deployment: models that are exclusively available to Meta personnel"; "internal-use risk report" provided "as appropriate" to "relevant authorities"; "Loss of Control risks may occur with similar probability with any type of deployment, including internal deployment."exactEQ
confidence: high
Meta Advanced AI Scaling Framework v2
EUShadow mapping
EU GPAI Code of Practice, Safety and Security Chapter / OpenAI Frontier Governance Framework
The chapter applies across "the entire model lifecycle (including during development that occurs before and after a model has been placed on the market)" rather than singling out "internal deployment" as a separate category; Measure 3.2's model evaluations and Commitment 4's acceptance determination must be completed "at least before placing the model on the market" (Measure 1.2), leaving pre-market internal use inside the same process rather than exempted from it
Narrower coverage than OpenAI's FGF citation of this same chapter for internal-use oversight-circumvention risks specifically.
closeCL
confidence: medium
EU GPAI Code of Practice, Safety and Security Chapter
California SB 53Shadow mapping
California SB 53
Framework topic "(10) Assessing and managing catastrophic risk resulting from the internal use of its frontier models"; summaries to OES "every three months or pursuant to another reasonable schedule"; incident field "(4) Whether the incident was associated with internal use of a frontier model." "Internal use" is undefined.
SB 53 requires reporting on internal use but leaves the term "internal use" itself undefined — recorded, not silently dropped.
exactEQ
confidence: high
California SB 53
METRShadow mapping
METR (metr.org)
Frontier Risk Report participants provided "Access to their most capable internal model(s) at the time of assessment, including raw chains of thought"closeCL
confidence: medium
METR
What do these codes mean?
exact
The source term is equivalent to this element
close
The source term is close but not equivalent to this element
broad
The source term is broader than this element
narrow
The source term is narrower than this element
none
No mapping claim — used for false-friend and declared-but-undefined rows
EQ
Equivalent
CL
Close
BR
Source is broader than the element
NR
Source is narrower than the element
FF
False friend — same or similar label, different meaning
DU
Declared but undefined by the source
UV
Unverified

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →