Frontier AI Safety Framework
Published February 2025 · The cover prints only the month, 'February 2025'. The PDF's embedded creation date is 2025-02-06, the G42 Publications index lists the entry as 05 Feb 2025, and METR's index dates it February 6, 2025. The ISO date is set to the first of the printed month by convention.
Not law. This is a company's own public position on AI regulation. It is not law, and it carries no legal force.
What it argues for
This is the rulebook the Abu Dhabi technology group G42 applies to its own most capable models. It governs G42 itself and makes no argument about what governments should do. It describes itself as "a comprehensive set of protocols designed to safeguard G42’s advanced AI initiatives" and says it "was developed with input from SaferAI and METR". At its centre is a threshold-and-level mechanism. G42 monitors two hazardous capabilities, biological threats and offensive cybersecurity, and names autonomous operation and advanced manipulation only as possible future additions. Each threshold is tied to a required Deployment Mitigation Level (DML) and Security Mitigation Level (SML), which must be in place before the threshold is reached, and both current thresholds require level 2 on each scale. The consequence is spelled out: "If a necessary Deployment Mitigation Level cannot be achieved, then the model’s deployment must be restricted; if a necessary Security Mitigation Level cannot be achieved, then further capabilities development of the model must be paused." Evaluation has two stages. First come cheap preliminary benchmarks, with a presumption that a G42 model scoring below an outside model already judged to be under the threshold is itself under it. Where those results cannot rule a capability out, in-depth evaluations with capability elicitation follow. Governance rests with a Frontier AI Governance Board of four officeholders, backed by independent internal audits, "annual external audits to verify compliance with the Framework", an annual external review of the framework and an annual transparency report. Governments appear in only two places. On incidents, "non-sensitive incident information should be shared with applicable government bodies". On disclosure, G42 says "We will share more detailed information with the UAE Government and relevant policy stakeholders." Its one statement of policy intent is that "G42 will proactively engage with government agencies, academic institutions, and other regulatory bodies to help shape emerging standards for frontier AI safety, aligning G42’s practices with evolving global frameworks."
Stated positions (15)
- Monitors only two hazardous capabilities today: biological threats and offensive cybersecurity. They were chosen with METR and SaferAI by "prioritizing capabilities based on their potential impact and how feasibly they can be measured and monitored". Autonomous operation and advanced manipulation are put off to a later date, introduced only with "We may also add thresholds for".
- Defines the biological threshold as "Enabling an individual with only introductory biology experience in developing a biological weapon", or helping design novel, more damaging biological weapons. The cyber threshold is "Automating powerful cyber offensive operations against unsecured or secured targets, in a way that could cause critical damage."
- Carries a hard consequence rule: "If a necessary Deployment Mitigation Level cannot be achieved, then the model’s deployment must be restricted; if a necessary Security Mitigation Level cannot be achieved, then further capabilities development of the model must be paused."
- Mitigations must come before the capability. The required DML and SML "must be achieved before the capability threshold is reached", and once a threshold has been reached "G42 will update this Framework to define a more advanced threshold" with stronger required mitigations.
- Allows a shortcut on preliminary screening. If a G42 model scores lower on open-source benchmarks than an outside model already evaluated as below the threshold, "then such G42 model will be presumed to be below the capability threshold". In-depth evaluation follows only where the preliminary evaluations cannot rule a capability out.
- In-depth evaluations use capability elicitation (prompt engineering, fine-tuning, agentic tool use) "to optimize performance, overcome model refusals, and avoid underestimating model capabilities". Language-specific models are covered: "Models created to generate output in a specific language, such as Arabic or Hindi, may be tested in those languages."
- For fine-tuned or adapted open-source models, G42 may rely on the upstream developer's evaluations. If the original model has had high-quality biological and cyber assessments and G42's changes do not enhance those capabilities, "we may place greater reliance on the original evaluation results."
- Capability evaluation results go to internal governance, not the public: "These reports will be created for our most advanced models at least once every six months". They are shared with the Frontier AI Governance Board and the G42 Executive Leadership Committee.
- Deployment Mitigation Level 2, the level both current thresholds require, sets the objective that "Even a determined actor should not be able to reliably elicit CBRN weapons advice" or automate powerful cyberattacks. The top level is left open: DML 4 is "To be defined when models reach capabilities necessitating Level 3 deployment mitigation measures".
- Security tiers run from open release to state-level defence. At SML 1 the specified measures are "None. G42 may choose to open source models." SML 3 aims to "resist even concerted attempts, with support from state programs, to steal model weights or key algorithmic secrets", using multi-party approval, end-to-end weight encryption and zero-trust architecture.
- Governance is internal and named by office: a Frontier AI Governance Board "composed of our Chief Responsible AI Officer, Head of Responsible AI, Head of Technology Risk, and General Counsel". Framework changes are proposed by that board and "approved by the G42 Executive Leadership Committee."
- Commits to verification from outside: "G42 will have independent internal audits to verify compliance with our policy", "G42 will engage in annual external audits to verify compliance with the Framework", and "An annual external review of the Framework will be conducted".
- Incident handling combines automated and human detection, and "non-sensitive incident information should be shared with applicable government bodies". Neither the government body nor a deadline is named.
- Disclosure has two tiers: "G42 will publish non-sensitive, up-to-date and active copies of the Framework" and an annual transparency report, while "We will share more detailed information with the UAE Government and relevant policy stakeholders."
- Its only policy-facing commitment is to engage: "G42 will proactively engage with government agencies, academic institutions, and other regulatory bodies to help shape emerging standards for frontier AI safety". It adds that "G42 will share threat intelligence with industry partners", and that "As deemed appropriate, we will solicit external expert advice for capability and safeguards assessments."
About this document
A 14-page PDF. The cover reads 'Frontier AI Safety Framework' with the G42 logo and 'February 2025'. It was issued in G42's corporate name and closes with an author list: Dr. Andrew Jackson, Prof. Boulbaba Ben Amor, Adele O Herlihy, Dr. Larry Murray, Rohit Manucha, Grzegorz Kosior and James Wilton. The file name calls it the 'Publication Version'. After a contents page it runs seven numbered sections: Introduction, Frontier Capability Thresholds (with a table setting each threshold against preliminary and in-depth evaluations and required DML/SML), Deployment Mitigation Levels (a four-row table), Security Mitigation Levels (a four-row table), Governance and Compliance (board, incident response, internal and external transparency, policy review), a three-phase Implementation Plan (first 6 months, 6–12 months, 12+ months) and a Conclusion. It is written almost entirely as a set of commitments about G42's own practice. The only outward asks are engagement with regulators and standards bodies and sharing incident information with government. G42's October 2025 Responsible AI Transparency Report places the framework as its follow-through on the Frontier AI Safety Commitments G42 signed at the AI Seoul Summit in May 2024.
How this sits against AI law
Each stance compared with what EU and US instruments actually require. Where no instrument addresses a theme, that gap is shown rather than hidden.
Capability thresholds with a restrict-or-pause rule
Each monitored capability threshold carries a required deployment and security mitigation level. If the deployment level cannot be met, deployment is restricted; if the security level cannot be met, "further capabilities development of the model must be paused."
Article 55(1)(b) obliges providers of general-purpose models with systemic risk to assess and mitigate systemic risks but sets out no capability thresholds, no graded mitigation levels and no duty to halt development. G42's tiered scheme and pause rule are its own additions.
SB 53 requires large frontier developers to publish a frontier AI framework describing how they assess catastrophic-risk capabilities against thresholds and apply mitigations. G42's framework contains those elements in the form the statute asks to be published.
Scope of hazards monitored
G42 currently monitors only biological threats and offensive cybersecurity, prioritised for impact and measurability. Autonomous operation and advanced manipulation are named as thresholds it "may also add" in future reviews.
The Act's systemic-risk concept (Article 3(65)) is open-ended, covering negative effects on public health, safety, public security, fundamental rights or society as a whole. Article 55(1)(b) requires those risks to be assessed and mitigated, so a fixed two-hazard list is narrower than the duty.
SB 53's catastrophic-risk definition covers expert-level help with chemical, biological, radiological or nuclear weapons, cyberattacks and other serious crimes carried out without meaningful human oversight, and a model evading its developer's control. G42 monitors only the biological and cyber limbs.
Pre-deployment capability evaluation
Evaluations run throughout the model lifecycle. Preliminary benchmark screens can presume a model is below threshold if it scores under an outside model already judged below it, and in-depth evaluations with capability elicitation follow where a capability cannot be ruled out. Detailed results go to internal governance at least every six months.
Article 55(1)(a) requires model evaluation according to standardised, state-of-the-art protocols, including adversarial testing. G42's two-stage evaluation with elicitation is of that kind, though its comparative-benchmark presumption is a shortcut the Act neither endorses nor rules out.
SB 53 requires a transparency report, published before or with deployment, that summarises the catastrophic-risk assessments carried out and their results. G42 sends its detailed evaluation reports only to its own board and executive committee.
Security of model weights
Security Mitigation Levels scale from none (with open-source release permitted) through access controls, segmentation and red-teaming at level 2, to multi-party approval, end-to-end weight encryption and zero-trust architecture at level 3, meant to resist state-supported theft. Level 4 is left to be defined.
Article 55(1)(d) requires only an adequate level of cybersecurity protection for a systemic-risk model and its physical infrastructure, naming no tiers or specific controls.
SB 53 requires a large frontier developer's published framework to describe the cybersecurity practices it uses to secure unreleased model weights against unauthorised access, modification or transfer.
Internal governance and independent audit
A Frontier AI Governance Board of four officeholders oversees compliance, investigates non-compliance and approves escalations. G42 commits to independent internal audits, "annual external audits to verify compliance with the Framework" and an annual external review of the framework.
The Act imposes no periodic external audit on providers of general-purpose models. Under Article 92 the AI Office may itself evaluate a model, including through independent experts, but only as an enforcement step.
Illinois SB 315, recorded in our corpus as adopted and taking effect on 1 January 2027, requires independent third-party audits of large frontier developers' safety frameworks. It is the only US instrument that makes compulsory the external audit G42 volunteers.
Incident reporting to authorities
G42 will build an incident response plan with automated and human detection and says "non-sensitive incident information should be shared with applicable government bodies". No recipient and no deadline are named.
Article 55(1)(c) requires providers of systemic-risk models to track, document and report serious incidents and possible corrective measures to the AI Office, and as appropriate to national authorities, without undue delay. That is a named recipient and a clock the framework does not have.
SB 53 requires critical safety incidents to be reported to California's Office of Emergency Services within 15 days, or within 24 hours where there is an imminent risk of death or serious physical injury.
Public disclosure of the framework and transparency reporting
G42 will publish non-sensitive, current copies of the framework, publish model cards with each deployment and issue an annual transparency report. More detailed information goes to the UAE Government and relevant policy stakeholders.
Article 53 requires technical documentation for the AI Office and downstream providers and one public artefact, a summary of training content. Nothing in the Act obliges a provider to publish a safety framework or model cards. The training-content summary the Act does require is not among G42's commitments.
SB 53 requires large frontier developers to publish their frontier AI framework on their website and to publish a transparency report before or when deploying a new frontier model, which matches G42's public-framework and reporting commitments.
Open release of low-risk models
At the lowest security level no novel measures are required and "G42 may choose to open source models". For fine-tuned open-source models, G42 may rely on the original developer's high-quality evaluations where its changes do not enhance hazardous capabilities.
Article 53(2) exempts free and open-source general-purpose models from the technical-documentation duties but not models with systemic risk. Like G42, it lets openness depend on the risk level rather than prohibiting or privileging release.
America's AI Action Plan has a section headed 'Encourage Open-Source and Open-Weight AI' and treats the choice to release an open or closed model as fundamentally up to the developer.
G42 wrote, in February 2025, a framework with most of the elements that California's SB 53 (RAI-US-CA-CS5TFXX-2025) made mandatory for large frontier developers seven months later: published capability thresholds, tiered mitigations, weight security and internal governance. It goes further than the EU AI Act (RAI-EU-NA-E2AIXXX-2024) in the same places: graded levels, a pause rule and annual external audits, none of which the Act's general-purpose model chapter requires. Its weak points are the ones the law makes enforceable. Incident reporting names no recipient and no clock, where the Act requires reports to the AI Office without undue delay and SB 53 sets 15 days. Its hazard list of biological and cyber only is narrower than either SB 53's catastrophic-risk definition or the Act's open-ended systemic-risk concept. In its home jurisdiction nothing comparable binds it. The UAE instruments in our corpus are non-binding principles: the UAE Charter for the Development and Use of Artificial Intelligence (RAI-AE-NA-DEVELOP-2024), with twelve principles covering safety, human oversight and transparency, and the AI Ethics Principles and Guidelines (RAI-AE-NA-AEPGUXX-2022). Abu Dhabi Law No. 3 of 2024 (RAI-AE-AB-ADN32XX-2024) creates the Artificial Intelligence and Advanced Technology Council to set policy and strategy, not developer duties. The framework's only link to UAE government is G42's own undertaking to share more detailed information with it.
Source
https://www.g42.ai/application/files/9517/3882/2182/G42_Frontier_Safety_Framework_Publication_Version.pdf- Date on the page:
- February 2025
- Source checked:
- opened and confirmed on 2026-09-30