Source of record
Where this definition comes from
EU GPAI Code of Practice, Safety and Security Chapter, Appendix 1.4
“Appendix 1.4 "Specified systemic risks": "(1) Chemical, biological, radiological and nuclear ... (2) Loss of control ... (3) Cyber offence ... (4) Harmful manipulation: Risks from enabling the strategic distortion of human behaviour or beliefs by targeting large populations or high-stakes decision-makers through persuasion, deception, or personalised targeting ..." -- the taxonomy xAI's FAIF footnotes say it adopts.”
https://ec.europa.eu/newsroom/dae/redirection/document/118119Anthropic Advanced AI Framework, p.4
“"Enumerated Risk categories": "catastrophic risks related to (a) biological weapons, (b) offensive cyber operations, (c) loss of control, and (d) automated research and development in key domains that could accelerate or amplify risks (a)-(c)."”
https://www-cdn.anthropic.com/files/4zrzovbb/website/0a58d567024a8b448ff15158ebc3625328dfcc1f.pdfFrontier Model Forum, Risk Taxonomy and Thresholds technical report, s2.4, p.9
“"Chemical, Biological, Radiological, and Nuclear (CBRN) Threats", "Advanced Cyber Threats", "Advanced Autonomous Behavior Threats"”
https://www.frontiermodelforum.org/technical-reports/risk-taxonomy-and-thresholds/
Crosswalk
How named organisations use this concept
| Organisation | Their term, as published | Match & verification | Source |
|---|---|---|---|
| AnthropicShadow mapping Risk Report / Advanced AI Framework | “Four threat models in three sections: misalignment in high-stakes settings (Autonomy TM1), automated R&D in key domains (TM2), CB-1 and CB-2 (para.). AAF "Enumerated Risk categories": "catastrophic risks related to (a) biological weapons, (b) offensive cyber operations, (c) loss of control, and (d) automated research and development in key domains that could accelerate or amplify risks (a)-(c)." (p.4)” | exactEQ confidence: high | Anthropic Advanced AI Framework, legislative proposal |
| OpenAIShadow mapping Preparedness Framework v2 / Frontier Governance Framework | “PF "Tracked Categories": Biological and Chemical; Cybersecurity; AI Self-improvement. "Research Categories": Long-range Autonomy; Sandbagging; Autonomous Replication and Adaptation; Undermining Safeguards; Nuclear and Radiological (Tables 1 and 2). FGF risk categories: "Cyber offense", "CBRN", "Harmful manipulation", "Loss of control" (§2.1).” | exactEQ confidence: high | OpenAI Preparedness Framework v2 |
| Google DeepMindShadow mapping Frontier Safety Framework v3.1 | “"CBRN", "Cyber", "Harmful Manipulation", "ML R&D and Misalignment" (glossary, p.18).” | exactEQ confidence: high | Google DeepMind Frontier Safety Framework v3.1 |
| xAIShadow mapping Frontier AI Framework, 30 Jun 2026 | “"CBRN Risks", "Offensive Cybersecurity Risks", "Loss of Control Risks", "Harmful Manipulation Risks" (s.1), with fn 1: "Terminology used in the The Safety and Security Chapter of the General-Purpose AI Code of Practice developed under the EU AI Act." Harmful Manipulation notably has no "Addressing" subsection unlike the other three domains.” This source's PDF metadata /Title reads "Privileged/Confidential DRAFT working FRAMEWORK DOC"; no xAI statement disambiguating draft vs. final status was found (open [VERIFY] item in the source document's register). The EQ score covers the domain-naming match only; the missing "Addressing" subsection for Harmful Manipulation is itself a DU-type gap within this otherwise-EQ row. | exactEQ confidence: high | xAI Frontier AI Framework, 30 Jun 2026 |
| MetaShadow mapping Advanced AI Scaling Framework v2 | “"Chemical & Biological, Cybersecurity, and Loss of Control" (preamble p.2). "Risk domain: is used to describe the thematic grouping that a set of catastrophic outcomes belong to" (Appendix I).” | exactEQ confidence: high | Meta Advanced AI Scaling Framework v2 |
| EUShadow mapping Safety and Security chapter | “Appendix 1.4 "Specified systemic risks", verbatim: "(1) Chemical, biological, radiological and nuclear: Risks from enabling chemical, biological, radiological, and nuclear (CBRN) attacks or accidents ... (2) Loss of control: Risks from humans losing the ability to reliably direct, modify, or shut down a model ... (3) Cyber offence: Risks from enabling large-scale sophisticated cyber-attacks, including on critical systems ... (4) Harmful manipulation: Risks from enabling the strategic distortion of human behaviour or beliefs by targeting large populations or high-stakes decision-makers through persuasion, deception, or personalised targeting ..." -- the taxonomy xAI's FAIF footnotes say it adopts.” | exactEQ confidence: high | EU GPAI Code of Practice, Safety and Security Chapter |
| California SB 53Shadow mapping SB 53 statute text | “Catastrophic-risk pathways: (A) CBRN "expert-level assistance"; (B) conduct "with no meaningful human oversight ... that is either a cyberattack or ... would constitute the crime of murder, assault, extortion, or theft"; (C) "Evading the control of its frontier developer or user" (22757.11(c)).” SB 53 frames these as incident *pathways* (mechanisms), not a domain taxonomy per se; mapped here as close because the pathways cluster along the same CBRN / cyber / loss-of-control lines as the other sources' domains. | closeCL confidence: medium | California SB 53 |
| US Government (Executive Order 14409 / NIST CAISI)Shadow mapping Executive Order 14409 / CAISI bulletin | “EO 14409 addresses only "advanced cyber capabilities" (Sec. 3(a)); CAISI frames its agreements as "Frontier AI National Security Testing".” | narrowNR confidence: medium | Executive Order 14409 |
| Frontier Model ForumShadow mapping Risk Taxonomy and Thresholds technical report | “"Chemical, Biological, Radiological, and Nuclear (CBRN) Threats", "Advanced Cyber Threats", "Advanced Autonomous Behavior Threats" (s2.4, p.9).” | exactEQ confidence: high | Frontier Model Forum, Risk Taxonomy and Thresholds technical report |
| Safety Framework Cards (discovery)Shadow mapping Safety Framework Cards (SSRN 7061798, unread/paywalled) | “"risk ontology" is one of six evaluation dimensions (secondary) [UV].” SFC full text is paywalled on SSRN and could not be read; the {DEV} discovery-sweep tag does not resolve to a single fetchable URL in the provided sources table. | noneUV confidence: low | Discovery sweep: Safety Framework Cards (SSRN 7061798, unread/paywalled) |
| STREAM (discovery sweep)Shadow mapping STREAM pilot (arXiv 2508.09853) | “"ChemBio only" (para.) [UV] -- STREAM's disclosure pilot is scoped to ChemBio benchmarks only, per the discovery sweep.” Cited via the compound {DEV} discovery-sweep tag, which does not resolve to a single fetchable URL in the provided sources table; STREAM's own arXiv id was read directly from the source document's open-VERIFY register (item 6) but no URL for it appears in the provided sources table. | noneUV confidence: low | Discovery sweep: STREAM (arXiv 2508.09853) |
What do these codes mean?
- exact
- The source term is equivalent to this element
- close
- The source term is close but not equivalent to this element
- broad
- The source term is broader than this element
- narrow
- The source term is narrower than this element
- none
- No mapping claim — used for false-friend and declared-but-undefined rows
- EQ
- Equivalent
- CL
- Close
- BR
- Source is broader than the element
- NR
- Source is narrower than the element
- FF
- False friend — same or similar label, different meaning
- DU
- Declared but undefined by the source
- UV
- Unverified
Divergence
Where sources materially disagree
Resolved 2026-09-19 (was an open placement question): risk-domain stays in N1, not N2, on purpose. It names a coarse catastrophic-harm CATEGORY that defines a report's scope (CBRN, cyber-offense, autonomous replication, etc.) -- the same kind of scope-definition question as N1's coverage-scope-threshold and severity-threshold. N2's threat-model, risk-pathway and threat-actor-profile are a different, more specific question: the causal route and actor behind a SPECIFIC risk within a domain, not which domain is in scope at all. A prior draft of this note flagged an unresolved N1-vs-N2 conflict inherited from an earlier 25-element manifest; that manifest's own N2 placement predates NIKOLAI's current N1/N2 split and does not reflect it.
Gap
"Harmful manipulation" is a domain in the FGF, FSF, FAIF and (reportedly) the Code, but it is exploratory or unaddressed in all three lab texts. "AI R&D" is a Tracked Category (OpenAI), part of a merged domain (GDM), a threat model (Anthropic) and an enabling capability under Loss of Control (Meta).







