Source of record
Where this definition comes from
Anthropic Risk Report, August 2026, §4.1, §2.11.1, §6.4.1 fn90
“CB-1: "Individuals or small groups with limited resources"; CB-2: "Moderately resourced threat actors (including, for example, expert-backed teams)" (§4.1). "Sophisticated insiders": "insiders who have persistent access or can request time-limited access to systems that process model weights" (§6.4.1 fn 90).”
https://www-cdn.anthropic.com/f61d49fa5596956a5dec75fea0e973bf6a6a8378/Redacted%20Risk%20Report%20August%202026%20.pdfGemini 3.7 Flash FSF report / FSF v3.1, report p.16
“Threat Actor Capability levels "TAC-1" ("programmer with limited cybersecurity knowledge (e.g., 'script kiddie')") to "TAC-4" ("95th+ percentile cybersecurity expert (e.g., nation-state-sponsored groups)") (report p.16).”
https://storage.googleapis.com/deepmind-media/gemini/gemini_3-7_flash_fsf_report.pdf
Crosswalk
How named organisations use this concept
| Organisation | Their term, as published | Match & verification | Source |
|---|---|---|---|
| AnthropicShadow mapping Anthropic Risk Report, August 2026 | “CB-1: "Individuals or small groups with limited resources"; CB-2: "Moderately resourced threat actors (including, for example, expert-backed teams)" (§4.1). "Medium-strength attacker": "an attacker with the strength that a human red-teamer shows when editing a transcript without iterating against a monitor ..." (§2.11.1). "Sophisticated insiders": "insiders who have persistent access or can request time-limited access to systems that process model weights" (§6.4.1 fn 90).” | exactEQ confidence: high | Anthropic Risk Report, August 2026 |
| OpenAIShadow mapping Preparedness Framework v2 / GPT-5.6 deployment safety report | “"Novice actor (Bio): anyone with a basic relevant technical background" (Table 1). Critical: "The model can enable an expert to develop a highly dangerous novel threat vector" (Table 1). GPT-5.6: "Spray and pray operations": "broad exploitation by moderately skilled, low-resourced individuals and small groups" (s.9.4.1.2).” | closeCL confidence: high | OpenAI Preparedness Framework v2 |
| Google DeepMindShadow mapping Gemini 3.7 Flash FSF report / FSF v3.1 | “"Provides low to medium resourced actors uplift in reference scenarios" (CBRN Uplift 1 CCL). Threat Actor Capability levels "TAC-1" ("programmer with limited cybersecurity knowledge (e.g., 'script kiddie')") to "TAC-4" ("95th+ percentile cybersecurity expert (e.g., nation-state-sponsored groups)") (report p.16). FSF refers to RAND "OC3 groups" without defining them (p.11).” | exactEQ confidence: high | Gemini 3.7 Flash FSF report |
| xAIShadow mapping xAI Frontier AI Framework (30 Jun 2026) | “Security Goal threat actors: "sophisticated non-state actors, insider threats, state-sponsored actors and other foreseeable actors" (s.2.4). This is a security-only construct, narrower than the malicious-use threat-actor profiles used elsewhere in the corpus.” PDF metadata /Title reads "Privileged/Confidential DRAFT working FRAMEWORK DOC"; no xAI statement disambiguating draft vs. final was found. | narrowNR confidence: medium | xAI Frontier AI Framework (30 Jun 2026, draft-marked) |
| MetaShadow mapping Meta Advanced AI Scaling Framework v2 | “Scenarios cover "both state and non-state actors" and distinguish "high- and low-skill actors" (para., §1.1); CB 1: "Proliferation of known medium-impact biological or chemical weapons for low and moderate skill actors" (§3.4).” | closeCL confidence: high | Meta Advanced AI Scaling Framework v2 |
| EUShadow mapping EU GPAI Code of Practice, Safety and Security chapter | “Measure 6.1 "Security Goal": Signatories "will define a goal that specifies the threat actors that their security mitigations are intended to protect against ..., including non-state external threats, insider threats, and other expected threat actors, taking into account at least the current and expected capabilities of their models" — a security-only threat-actor construct, distinct from malicious-use threat-actor profiles used elsewhere in the corpus, confirming xAI's own adoption of the same term.” Row also cites xAI's Frontier AI Framework, whose PDF metadata is marked "DRAFT working FRAMEWORK DOC" with no disambiguating xAI statement found. | closeCL confidence: high | EU GPAI Code of Practice, Safety and Security chapter |
What do these codes mean?
- exact
- The source term is equivalent to this element
- close
- The source term is close but not equivalent to this element
- broad
- The source term is broader than this element
- narrow
- The source term is narrower than this element
- none
- No mapping claim — used for false-friend and declared-but-undefined rows
- EQ
- Equivalent
- CL
- Close
- BR
- Source is broader than the element
- NR
- Source is narrower than the element
- FF
- False friend — same or similar label, different meaning
- DU
- Declared but undefined by the source
- UV
- Unverified
Related, not mapped
Pointers that are not crosswalk claims
These sources mention this concept but do not define or map it clearly enough to count as a crosswalk row — noted here so the research is visible without overstating it as a mapping.
- Frontier Model Forum
"Heightened Marginal Risk" examples (e.g. "enabling low-skilled actors to build chemical weapons previously restricted to well-resourced states") and FMF35's "Threats" examples that mention "potential threat actors" are related context, not a defined threat-actor-profile construct — scored RL (related, not a mapping) in the source document.
FMF Risk Taxonomy and Thresholds / Information Sharing, Incident Reporting and Incident Response







