Skip to main content
v2026.11,858 entries · CC-BY 4.0
NIKOLAI elementN2 · Threat models and risk framingProposednikolai-v0.1

Risk Pathway

NIKOLAI editorial proposal (unsourced): a risk-pathway record is a specific causal route from model behaviour or misuse to harm, finer-grained than a threat model, capturing the concrete steps or stages by which a threat model's harm could actually occur. This is element B2 of the source crosswalk.

This is CASRAI's own proposed definition, not a definition any named organisation has agreed to. See what NIKOLAI is and is not.

Source of record

Where this definition comes from

Crosswalk

How named organisations use this concept

Every row below is a shadow mapping. A shadow row is CASRAI's own reading of a published document. No lab, evaluator or regulator named on a shadow row has declared, endorsed, or been consulted on it. That changes only when an organisation files its own Mapping Declaration.
OrganisationTheir term, as publishedMatch & verificationSource
AnthropicShadow mapping
Anthropic Risk Report, August 2026
Eight "priority risk pathways": "diffuse sandbagging on safety R&D; targeted undermining of safety R&D; code backdoors; training-data poisoning; self-exfiltration; persistent rogue internal deployment; undermining R&D at other developers; undermining decisions within major governments" (§2.2.1). "We aren't able to defend the choice of these pathways rigorously" (§2.13).exactEQ
confidence: high
Anthropic Risk Report, August 2026
OpenAIShadow mapping
Preparedness Framework v2 / Path to Astra
Safeguards Report contents: "Identified ways a risk of severe harm can be realized for the given deployment, each mapped to the associated security controls and safeguards" (PF §4.2). Astra: "Risk pathways (cyber)": "(1) a malicious actor using Astra to develop novel exploits ... or (2) the model itself causing cyber harm when taking an unauthorized (or misaligned) action." (s.10.2)closeCL
confidence: high
OpenAI Preparedness Framework v2
Google DeepMindShadow mapping
Gemini 3.7 Flash FSF report / FSF v3.1
CCLs are "determined by identifying and analyzing the main foreseeable paths through which a model could cause severe harm" (report p.2; FSF s.1.2).closeCL
confidence: high
Google DeepMind Frontier Safety Framework v3.1
xAIShadow mapping
xAI Frontier AI Framework (30 Jun 2026)
"These risk domains describe principal pathways through which severe or systemic harm may arise." (s.2.1). Here "pathway" names the risk domain itself, not a finer-grained causal route beneath it.
PDF metadata /Title reads "Privileged/Confidential DRAFT working FRAMEWORK DOC"; no xAI statement disambiguating draft vs. final was found. This row is also confirmed by the source document's own false-friends register ("pathway": Anthropic's eight fine-grained misalignment routes vs. xAI's risk domains themselves vs. SB 53's three incident mechanisms).
noneFF
confidence: high
xAI Frontier AI Framework (30 Jun 2026, draft-marked)
MetaShadow mapping
Meta Advanced AI Scaling Framework v2
Threat modeling "identifies the potential causal pathways for realizing the catastrophic outcome" (Appendix I).closeCL
confidence: high
Meta Advanced AI Scaling Framework v2
California SB 53Shadow mapping
California SB 53
Catastrophic risk arises from "a single incident involving a frontier model doing any of the following: (A) ... (B) ... (C) ..." (22757.11(c)) — a broader, outcome-defined construct than a specific causal pathway.broadBR
confidence: medium
California SB 53
Frontier Model ForumShadow mapping
FMF Risk Taxonomy and Thresholds
Threat modeling includes "mapping the potential pathways to those outcomes"; "Credibility: There is a credible pathway to extreme harm." (s1.3, s2.1)closeCL
confidence: high
FMF Risk Taxonomy and Thresholds
What do these codes mean?
exact
The source term is equivalent to this element
close
The source term is close but not equivalent to this element
broad
The source term is broader than this element
narrow
The source term is narrower than this element
none
No mapping claim — used for false-friend and declared-but-undefined rows
EQ
Equivalent
CL
Close
BR
Source is broader than the element
NR
Source is narrower than the element
FF
False friend — same or similar label, different meaning
DU
Declared but undefined by the source
UV
Unverified

Divergence

Where sources materially disagree

xAI's Frontier AI Framework uses "pathway" as a synonym for its risk domains themselves (s.2.1), not as a finer-grained causal route beneath a domain/threat-model as in Anthropic's eight priority risk pathways, OpenAI's Astra risk pathways, or Meta's causal pathways — a false-friend label collision, confirmed by the source document's own false-friends register ("pathway": Anthropic eight fine-grained misalignment routes vs. xAI's risk domains themselves vs. SB53's three incident mechanisms). {RR} {FAIF26} {SB53}

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →