Source of record
Where this definition comes from
Google DeepMind Frontier Safety Framework v3.1, s.2.1.1
“Security Level 2+ ... uses RAND Security Level 2 (SL2) as a baseline, with additional security measures designed to address risks from insider threats and well-resourced non-state external actors”
https://storage.googleapis.com/deepmind-media/DeepMind.com/Blog/strengthening-our-frontier-safety-framework/frontier-safety-framework_3-1.pdf
Crosswalk
How named organisations use this concept
| Organisation | Their term, as published | Match & verification | Source |
|---|---|---|---|
| AnthropicShadow mapping Anthropic Risk Report, August 2026 | “"ASL-3 protections cover non-state attackers and *un*sophisticated insiders; sophisticated insiders and nation-state attackers remain out of scope"; industry recommendation at CB-2 implies "security roughly in line with RAND SL4"” "ASL" terminology survives here specifically for weight security even though Anthropic retired it for safeguard robustness/coverage elsewhere — see false-friends register. | closeCL confidence: medium | Anthropic Risk Report, August 2026 |
| OpenAIShadow mapping OpenAI Preparedness Framework v2 / Pacing Model Development (Cyber), Aug 2026 | “"High standard (security / misuse / misalignment): referenced as 'meeting High standard (Appendix C.1/C.2/C.3)'"; "Critical standard ... not yet specified"; "the strictest level of security safeguards" (undefined levels)” | closeCL confidence: medium | OpenAI Preparedness Framework v2 |
| Google DeepMindShadow mapping Frontier Safety Framework v3.1 | “"Security Level 2+ ... uses RAND Security Level 2 (SL2) as a baseline, with additional security measures designed to address risks from insider threats and well-resourced non-state external actors"; "Security level 3" and "Security level 4" descriptions; "RAND Security Levels"” | exactEQ confidence: high | Google DeepMind Frontier Safety Framework v3.1 |
| xAIShadow mapping Frontier AI Framework, 30 Jun 2026 | “"Security Goal": "a documented Security Goal that identifies the threat actors against which mitigations are designed to protect against". No level.” xAI's Frontier AI Framework (30 Jun 2026) carries PDF metadata reading "Privileged/Confidential DRAFT working FRAMEWORK DOC" with no xAI statement found disambiguating draft from final; treat this citation as provisional. | narrowNR confidence: medium | xAI Frontier AI Framework, 30 June 2026 (draft-labeled PDF metadata) |
| MetaShadow mapping Meta Advanced AI Scaling Framework v2 | “"Initiate protocols for heightened access controls to model weights" (High and Critical, Table 1); not mapped to any scale” | narrowNR confidence: medium | Meta Advanced AI Scaling Framework v2 |
| EUShadow mapping EU GPAI Code of Practice, Safety and Security Chapter | “No graded security *level* scale (unlike GDM's SL2+/SL3/SL4). Instead, Measure 6.1 requires each Signatory to define a documented "Security Goal": "a goal that specifies the threat actors that their security mitigations are intended to protect against ('Security Goal'), including non-state external threats, insider threats, and other expected threat actors, taking into account at least the current and expected capabilities of their models"” Confirms xAI's adoption of this exact chapter term; the linked {FAIF26} carries the draft/final metadata caveat above. | closeCL confidence: medium | EU GPAI Code of Practice, Safety and Security Chapter |
| METRShadow mapping METR (metr.org) | “"Model Weight Security: ... as models develop increasing capabilities of concern, progressively stronger information security measures are recommended"” | closeCL confidence: medium | METR |
| G42Shadow mapping G42 Frontier Safety Framework | “"Security Mitigation Levels (SML)" 1-4” | closeCL confidence: medium | G42 Frontier Safety Framework |
| MicrosoftShadow mapping Microsoft Frontier Governance Framework, Feb 2026 | “Cites RAND security levels” | closeCL confidence: medium | Microsoft Frontier Governance Framework, Feb 2026 |
What do these codes mean?
- exact
- The source term is equivalent to this element
- close
- The source term is close but not equivalent to this element
- broad
- The source term is broader than this element
- narrow
- The source term is narrower than this element
- none
- No mapping claim — used for false-friend and declared-but-undefined rows
- EQ
- Equivalent
- CL
- Close
- BR
- Source is broader than the element
- NR
- Source is narrower than the element
- FF
- False friend — same or similar label, different meaning
- DU
- Declared but undefined by the source
- UV
- Unverified
Related, not mapped
Pointers that are not crosswalk claims
These sources mention this concept but do not define or map it clearly enough to count as a crosswalk row — noted here so the research is visible without overstating it as a mapping.
- SB 53 (California)
Framework topic "(7) Cybersecurity practices to secure unreleased model weights from unauthorized modification or transfer by internal or external parties." — related, not a mapping (RL).
California SB 53







