Skip to main content
v2026.11,858 entries · CC-BY 4.0
NIKOLAI elementN6 · Mitigations and securityProposednikolai-v0.1

Security control

NIKOLAI proposes a Security control record as: an individual security measure (e.g. multi-party access approval, hardware security keys, weight encryption), identified by name and, where possible, mapped to an external control catalogue or standard (NIST 800-171, SOC 2, RAND). This is an unsourced NIKOLAI editorial synthesis distinguishing individual controls from the graded security-level axis they roll up into.

This is CASRAI's own proposed definition, not a definition any named organisation has agreed to. See what NIKOLAI is and is not.

Source of record

Where this definition comes from

Crosswalk

How named organisations use this concept

Every row below is a shadow mapping. A shadow row is CASRAI's own reading of a published document. No lab, evaluator or regulator named on a shadow row has declared, endorsed, or been consulted on it. That changes only when an organisation files its own Mapping Declaration.
OrganisationTheir term, as publishedMatch & verificationSource
AnthropicShadow mapping
Anthropic Risk Report, August 2026
Ten notable controls "including egress bandwidth controls, multi-party (2PC) access approval, binary allowlisting, hardware security keys, device authorisation, hourly re-authentication for privileged cloud identities, and network source policies"; 2PC: "Requires a second employee to approve access requests for model weights and other sensitive resources"exactEQ
confidence: high
Anthropic Risk Report, August 2026
OpenAIShadow mapping
OpenAI Preparedness Framework v2 / Frontier Governance Framework
C.3 practice families: "Security Threat Modeling and Risk Management; Defense in Depth; Access Management; Secure Development and Supply Chain; Operational Security; Auditing and Transparency"; FGF categories: "Protection of unreleased model weights; Hardening interface-access to unreleased model parameters; Insider threats; Security assurance"exactEQ
confidence: high
OpenAI Preparedness Framework v2
Google DeepMindShadow mapping
Frontier Safety Framework v3.1
SL2+ measures: "dedicated insider risk teams; background checks and ID verification for personnel with sensitive access; review of model training data for signs of tampering; mandating that the processing of untrusted inputs occurs within sandboxed environments; advanced red-teaming that simulates well-resourced adversaries ...; and proactive threat hunting with 24/7 incident response capabilities"exactEQ
confidence: high
Google DeepMind Frontier Safety Framework v3.1
xAIShadow mapping
Frontier AI Framework, 30 Jun 2026
"xAI has implemented appropriate information security standards, adopted based on the NIST 800-171 Rev.3 framework and supported by SOC 2 Type II evaluations." Measures include weight encryption, RBAC and anti-distillation
xAI's Frontier AI Framework (30 Jun 2026) carries PDF metadata reading "Privileged/Confidential DRAFT working FRAMEWORK DOC" with no xAI statement found disambiguating draft from final; treat this citation as provisional.
closeCL
confidence: medium
xAI Frontier AI Framework, 30 June 2026 (draft-labeled PDF metadata)
MetaShadow mapping
Meta Advanced AI Scaling Framework v2
Weight access controls only (Table 1)narrowNR
confidence: medium
Meta Advanced AI Scaling Framework v2
California SB 53Shadow mapping
California SB 53
Framework topic "(7) Cybersecurity practices to secure unreleased model weights from unauthorized modification or transfer by internal or external parties."broadBR
confidence: medium
California SB 53
METRShadow mapping
METR (metr.org)
"Model Weight Security" (element level)broadBR
confidence: medium
METR
EUShadow mapping
EU GPAI Code of Practice, Safety and Security Chapter
Appendix 4.1-4.5 lists specific, numbered security-mitigation objectives and measures: general security (MFA, zero-trust, phishing defences); protection of unreleased model parameters (a "secure internal registry", encryption "with at least 256-bit security" with keys "stored securely on a Trusted Platform Module (TPM)", confidential computing via "hardware-based, and attested trusted execution environments"); hardening interface access (access reviews "at least every six months"); insider threats (background checks, sandboxing against self-exfiltration, training-data tamper checks); and security assurance (independent external security reviews, red-teaming, bug bounties, EDR/IDS tooling, a security team for incident handling)exactEQ
confidence: high
EU GPAI Code of Practice, Safety and Security Chapter
AmazonShadow mapping
Amazon, Frontier Model Safety Framework
Secure compute (EC2 Nitro, isolated VPCs; "Zero Operator Access" services where "AWS has entirely eliminated all human access to service hosts", validated by an NCC Group third-party design review), data protection (AES-256 GCM, FIPS 140-2 Level 3 KMS, "Critical Permission Groups" that are "regularly audited"), two-person rules governing "all code check-ins", and a mandatory central-team "full security and safety review" for "all software and AI projects"exactEQ
confidence: high
Amazon, Frontier Model Safety Framework
What do these codes mean?
exact
The source term is equivalent to this element
close
The source term is close but not equivalent to this element
broad
The source term is broader than this element
narrow
The source term is narrower than this element
none
No mapping claim — used for false-friend and declared-but-undefined rows
EQ
Equivalent
CL
Close
BR
Source is broader than the element
NR
Source is narrower than the element
FF
False friend — same or similar label, different meaning
DU
Declared but undefined by the source
UV
Unverified

Related, not mapped

Pointers that are not crosswalk claims

These sources mention this concept but do not define or map it clearly enough to count as a crosswalk row — noted here so the research is visible without overstating it as a mapping.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →