Source of record
Where this definition comes from
Anthropic Risk Report, August 2026, §4.1, §4.2.1, §6.1
“"CB-1 threat model": "Individuals or small groups with limited resources use AI models to gain access to non-novel chemical or biological (CB) weapons, leading to the risk of catastrophic harm" (§4.1, §4.2.1).”
https://www-cdn.anthropic.com/f61d49fa5596956a5dec75fea0e973bf6a6a8378/Redacted%20Risk%20Report%20August%202026%20.pdfOpenAI Preparedness Framework v2, §2.2, p.4
“"Threat model": for each Tracked Category, "identifying specific risks of severe harms that could arise from the frontier capabilities in that domain and sets corresponding capability thresholds" (§2.2, p.4); "SAG reviews and approves these threat models."”
https://cdn.openai.com/pdf/18a02b5d-6b67-4cec-ab64-68cdfbddebcd/preparedness-framework-v2.pdfMeta Advanced AI Scaling Framework v2, Appendix I; §3.4
“"Threat modeling: a structured process of identifying how Frontier AI could contribute to specific ... outcomes"; identifiers such as "Cyber 1" and "TS.1.1" (Appendix I; §3.4).”
https://ai.meta.com/static-resource/Meta_Advanced-AI-Scaling-Framework-v2
Crosswalk
How named organisations use this concept
| Organisation | Their term, as published | Match & verification | Source |
|---|---|---|---|
| AnthropicShadow mapping Anthropic Risk Report, August 2026 | “"CB-1 threat model": "Individuals or small groups with limited resources use AI models to gain access to non-novel chemical or biological (CB) weapons, leading to the risk of catastrophic harm" (§4.1, §4.2.1). Prioritisation criteria: expected damages; "a clear role for AI in creating risk beyond what is created by other technologies and background conditions"; historical sanity checks; generalisability and poor early warning (§6.1).” | exactEQ confidence: high | Anthropic Risk Report, August 2026 |
| OpenAIShadow mapping OpenAI Preparedness Framework v2 | “"Threat model": for each Tracked Category, "identifying specific risks of severe harms that could arise from the frontier capabilities in that domain and sets corresponding capability thresholds" (§2.2, p.4); "SAG reviews and approves these threat models."” | closeCL confidence: high | OpenAI Preparedness Framework v2 |
| Google DeepMindShadow mapping Gemini 3.7 Flash FSF report | “Report method terms: "Threat actor type", "Scenario" ("combinations of threat actor types and agents, weapons, or attacks"), "Harm journey" ("A breakdown of key stages and substages required to carry out such an attack end-to-end"), "Bottleneck sub-stages", "Web-only baseline" (report, p.8).” | closeCL confidence: high | Gemini 3.7 Flash FSF report |
| xAIShadow mapping xAI Frontier AI Framework (30 Jun 2026) | “"xAI has developed systemic risk scenarios that enumerate the causal factors, potential harms, and mitigations" (s.2.1), which are not published.” Source PDF's own metadata /Title reads "Privileged/Confidential DRAFT working FRAMEWORK DOC"; no xAI statement disambiguating draft vs. final was found. Any claim built on this row should carry that caveat forward. | noneDU confidence: medium | xAI Frontier AI Framework (30 Jun 2026, draft-marked) |
| MetaShadow mapping Meta Advanced AI Scaling Framework v2 | “"Threat modeling: a structured process of identifying how Frontier AI could contribute to specific ... outcomes"; "Threat scenarios: describe the real-world events ... including enabling capabilities, deployment context, and threat actors (as relevant) ... that may be sufficient to produce a catastrophic outcome"; identifiers such as "Cyber 1" and "TS.1.1" (Appendix I; §3.4).” | exactEQ confidence: high | Meta Advanced AI Scaling Framework v2 |
| EUShadow mapping EU GPAI Code of Practice, Safety and Security chapter | “Measure 2.2 "Systemic risk scenarios": "Signatories will develop appropriate systemic risk scenarios ... for each identified systemic risk," feeding Measure 3.3 "systemic risk modelling." No named identifier scheme and no publication requirement beyond the Model Report; confirms xAI's own footnote claim that its unpublished scenarios follow this chapter.” Row also cites xAI's Frontier AI Framework, whose PDF metadata is marked "DRAFT working FRAMEWORK DOC" with no disambiguating xAI statement found. | closeCL confidence: high | EU GPAI Code of Practice, Safety and Security chapter |
| Frontier Model ForumShadow mapping FMF Risk Taxonomy and Thresholds | “"Threat modeling: a process for systematically anticipating and identifying how various threat actors might leverage frontier AI to achieve harmful outcomes and mapping the potential pathways to those outcomes." "Threat scenarios": scenarios "that specify how adversaries might use frontier AI to achieve severe outcomes, identifying specific tasks, model capabilities to exploit, and complementary tools." (s2.1, pp.7-8)” | exactEQ confidence: high | FMF Risk Taxonomy and Thresholds |
| Safety Framework Cards (discovery)Shadow mapping Safety Framework Cards (SSRN 7061798) | “"risk ontology" dimension named in discovery sweep; full text paywalled/unread.” Unverified: source document itself could not open the full text; recorded from discovery snippet only. | noneUV confidence: low | Discovery sweep — Safety Framework Cards (SSRN 7061798, paywalled/unread) |
What do these codes mean?
- exact
- The source term is equivalent to this element
- close
- The source term is close but not equivalent to this element
- broad
- The source term is broader than this element
- narrow
- The source term is narrower than this element
- none
- No mapping claim — used for false-friend and declared-but-undefined rows
- EQ
- Equivalent
- CL
- Close
- BR
- Source is broader than the element
- NR
- Source is narrower than the element
- FF
- False friend — same or similar label, different meaning
- DU
- Declared but undefined by the source
- UV
- Unverified
Gap
Only Meta assigns identifiers to threat scenarios, and Meta deliberately withholds "full details of the constituent steps and tasks within a threat scenario" (§3.4) {META}. NIKOLAI should separate a public identifier/summary from restricted detail.







