Frontier Safety Framework Version 3.1
Published April 17, 2026 · Printed on the cover as "Published: April 17, 2026" and repeated as the top entry of the Section 5.3 change log, "Version 3.1 (April 17, 2026)". The companion blog post on deepmind.google carries the same date ("Updated April 17, 2026"), and the frontier-safety landing page lists it as "Version 3.1 (17 Apr 2026)".
Not law. This is a company's own public position on AI regulation. It is not law, and it carries no legal force.
What it argues for
This is the regime Google DeepMind applies to its own most capable models, which it describes as "a set of protocols that aims to address severe risks that may arise from the high-impact capabilities of frontier AI models." It is built around capability thresholds: Critical Capability Levels (CCLs) at which a model "may pose heightened risk of severe harm" in four domains — CBRN, cyber, harmful manipulation, and a combined machine learning R&D and misalignment domain — and, new in version 3.1, lower Tracked Capability Levels (TCLs) for CBRN and for ML R&D and misalignment that "capture significant risks that may manifest at a lower capability threshold than our CCLs." Early warning evaluations and alert thresholds track proximity to each level; a model that reaches one needs a residual risk assessment, supplemented by a safety case at CCL, and external deployments "take place only after the appropriate governance function determines the residual risk to be acceptable." The gate is deliberately narrow — for misuse levels it is "required only for external deployment, not internal deployment or further development," though for ML R&D and misalignment it extends to high-risk internal deployments. The acceptability test is openly relative and judgement-based: residual risk may be weighed against "what capabilities and mitigations are available on other publicly available models," the document concedes that "our assessments will often involve some level of subjective analysis," and mitigations are to be proportionate, "thus balancing safety with innovation." Security is pegged to the RAND weight-security levels, with a new "Security Level 2+" for the misuse CCLs and levels 3 and 4 for ML R&D. Its political argument is about collective action rather than regulation: "The safety and security of frontier AI models is a global public good," and certain mitigations would reduce risk for society "only if all relevant organizations provide similar levels of protection." Its commitment to government is conditional — if a model reaches a CCL posing "an unmitigated and material risk to overall public safety, we aim to share relevant information with appropriate government authorities."
Stated positions (13)
- Two tiers of threshold: Critical Capability Levels are "capability levels at which, absent mitigation measures, frontier AI models or systems may pose heightened risk of severe harm"; version 3.1 adds Tracked Capability Levels for "significant but not severe levels of harm", currently defined for CBRN and for ML R&D and misalignment only.
- Four risk domains with named CCLs: CBRN uplift level 1, Cyber uplift level 1, Harmful manipulation level 1 (exploratory), and two ML R&D levels — "ML R&D acceleration level 1" and "ML R&D automation level 1", the latter defined as a model that "Can fully automate the work of any team of researchers at Google focused on improving AI capabilities, with approximately comparable all-inclusive costs."
- A misalignment trigger set below the CCLs: the Stealth and Situational Awareness TCL is reached when situational awareness and stealth are such that, "absent additional mitigations, we cannot rule out the model significantly undermining human control"; periodic residual risk assessments then follow, with safeguards "such as chain-of-thought monitoring on high-risk deployments" applied if internal-deployment risk is otherwise unacceptable.
- Deployment gate, not development gate: for misuse levels the residual-risk test is "required only for external deployment, not internal deployment or further development"; for ML R&D and misalignment it covers "external deployment and high-risk internal deployment, not further development." The stated aim is to "prevent models posing unacceptable levels of risk from being deployed."
- Safety cases at CCL: "Where the model has reached a CCL, the residual risk assessment will be supplemented with a safety case", defined as "an assessable argument showing how severe risks associated with a model's CCLs have been reduced to an acceptable level."
- Acceptability is judged relative to the market: factors include "what capabilities and mitigations are available on other publicly available models (e.g. if other models are similarly capable and have few mitigations, then the marginal risk added by our external deployment is likely low)", and a model's security can be deemed adequate if "we assess that the benefits of the open release of model weights outweigh the risks."
- Security pegged to RAND weight-security levels: a newly defined "Security Level 2+" (RAND SL2 plus insider-risk teams, background checks, sandboxing of untrusted inputs, APT-style red-teaming and 24/7 incident response) for the CBRN, cyber and harmful manipulation CCLs; Security level 3 for ML R&D acceleration; Security level 4 for ML R&D automation, which "must be taken on by the frontier AI field as a whole."
- Collective action as the premise: "The safety and security of frontier AI models is a global public good", and recommended security levels "will only be effective if the entire frontier AI field applies them, and of limited social utility if not."
- Openly subjective assessment: "Because the science of AI risk assessment is still developing, our assessments will often involve some level of subjective analysis"; mitigation is to be "proportionate with expected impact of a model's risk, thus balancing safety with innovation."
- External input is discretionary: proximity to a level is analysed "involving internal and external experts as needed", and "Where appropriate, we may engage relevant external actors, including governments". For ML R&D, Google DeepMind may rely on its own progress data because "we do not expect other groups to put significantly more effort into ML R&D than we do ourselves."
- Disclosure to authorities is conditional and aspirational: only where a model has reached a CCL posing "an unmitigated and material risk to overall public safety" does it "aim to share relevant information with appropriate government authorities", covering model information, evaluation results and mitigation plans, subject to confidentiality and proprietary considerations.
- Review at least annually: the Framework "will be reviewed at least once a year—more frequently if we have reasonable grounds to believe the adequacy of the Framework or our adherence to it has been materially undermined", with the updated version "reviewed by the appropriate corporate governance bodies." Governance is described in a single paragraph that names no body or office.
- Harmful manipulation remains provisional: "The research into harmful manipulation from a severe risk perspective is nascent. The CCL and our assessment of the risk in this domain is exploratory and subject to further research, and may be substantially changed over time."
About this document
A 20-page PDF titled "Frontier Safety Framework", cover-marked "Version 3.1" and "Published: April 17, 2026", hosted on Google DeepMind's storage bucket and linked from deepmind.google. No individual author or signatory appears in the document; the accompanying blog post is bylined Four Flynn, Helen King and Anca Dragan. After a one-page overview and a table of contents it runs five sections: the framework itself (scope, CCLs and TCLs, and a five-step risk management process of identification, inherent risk assessment, mitigation, residual risk assessment and risk acceptance determination); misuse (security and deployment mitigations, then CBRN, cyber and harmful manipulation capability levels, each in a table pairing the CCL with a recommended security level and rationale); machine learning R&D and misalignment (the Stealth and Situational Awareness TCL and two ML R&D CCLs); a one-paragraph governance section; and updates and disclosures, including a change log listing versions 1.0 (May 17, 2024), 2.0 (February 4, 2025), 3.0 (September 22, 2025) and 3.1. A glossary closes it. The text is almost wholly self-directed — it describes Google DeepMind's own thresholds, evaluations and sign-off — and names no statute. Its external references are footnoted links to the UK government's emerging processes paper, METR, Anthropic's RSP and SB 53 compliance pages, OpenAI's Preparedness Framework, Frontier Model Forum reports, the RAND weight-security report and three arXiv papers.
How this sits against AI law
Each stance compared with what EU and US instruments actually require. Where no instrument addresses a theme, that gap is shown rather than hidden.
Capability thresholds and tiered risk acceptance
Every frontier model is assessed against Critical Capability Levels in CBRN, cyber, harmful manipulation and ML R&D, and against lower Tracked Capability Levels for CBRN and for ML R&D and misalignment. A model reaching a level needs a residual risk assessment, and a safety case at CCL, before the appropriate governance function accepts the risk.
Article 55(1)(b) obliges providers of general-purpose AI models with systemic risk to assess and mitigate possible systemic risks, but the Act sets no capability tiers, alert thresholds or safety-case requirement; the two-tier CCL/TCL scheme is Google DeepMind's own construction.
SB 53 obliges a large frontier developer to publish a frontier AI framework describing how it defines and assesses thresholds for catastrophic risk and applies mitigations, which is the shape of this document; the statute leaves the thresholds themselves to the developer.
A deployment gate rather than a development gate
The residual-risk test for misuse levels applies "only for external deployment, not internal deployment or further development"; for ML R&D and misalignment it extends to high-risk internal deployments. The stated aim is to prevent models posing unacceptable levels of risk from being deployed, and the document contains no commitment to pause development.
The Act's systemic-risk duties in Articles 53 and 55 attach to providers placing general-purpose models on the Union market and contain no duty to halt training, so a gate keyed to deployment sits where the Act itself draws the line.
SB 53 is a transparency statute: a large frontier developer must publish and follow its own framework and publish a transparency report when deploying a new frontier model, but the law contains no prohibition on training or deploying a model.
Risk from internal deployment and loss of human control
The Stealth and Situational Awareness TCL is reached when the company cannot rule out a model significantly undermining human control; periodic residual risk assessments then cover high-risk internal deployments, with safeguards such as chain-of-thought monitoring applied where the internal risk is otherwise unacceptable.
The Act's general-purpose model duties are framed around models placed on the Union market and contain no separate gate for a developer's high-risk internal use of its own model, so treating internal deployment as a risk event is beyond what the Act asks.
SB 53 goes a step further than the Framework on internal use: a large frontier developer must transmit summaries of its assessments of catastrophic risk from internal use of its frontier models to the Office of Emergency Services every three months, a reporting line the Framework does not mention.
Security of model weights
Security is pegged to the RAND model weight security levels: a new Security Level 2+ (SL2 plus insider-risk teams, background checks, sandboxing, APT-style red-teaming and 24/7 incident response) for the CBRN, cyber and harmful manipulation CCLs, level 3 for ML R&D acceleration and level 4 for ML R&D automation.
Article 55(1)(d) asks only for "an adequate level of cybersecurity protection" for a systemic-risk model and its physical infrastructure, with no graded levels, named controls or benchmark framework.
SB 53 requires a large frontier developer's published framework to describe its cybersecurity practices for securing unreleased model weights against unauthorised modification or transfer, which the RAND-indexed security levels do.
Reporting to government authorities
Only if a model reaches a CCL posing an unmitigated and material risk to overall public safety does Google DeepMind "aim to share relevant information with appropriate government authorities", subject to confidentiality and proprietary considerations. Incident reporting appears only as part of post-market monitoring, with no recipient or deadline.
Article 55(1)(c) obliges systemic-risk providers to report serious incidents and possible corrective measures to the AI Office "without undue delay", and Article 52 requires notifying the Commission once a model meets the systemic-risk threshold — unconditional duties where the Framework offers an aim conditioned on an unmitigated CCL.
SB 53 sets a 15-day deadline for reporting a critical safety incident to the Office of Emergency Services, or 24 hours where there is an imminent risk of death or serious physical injury; the Framework names neither a recipient nor a clock.
External evaluation and independent review
Proximity to a capability level is analysed "involving internal and external experts as needed", and external parties are involved "Where required or appropriate". Every acceptance decision is taken by an internal "appropriate governance function"; no independent audit is committed to.
Article 55(1)(a) requires state-of-the-art model evaluation including documented adversarial testing, but leaves the choice between internal and independent external testing to the provider.
Illinois SB 315 has been adopted and, from its 1 January 2027 effective date, will make an independent third-party audit of frontier AI safety protocols compulsory for large frontier developers; the Framework keeps external review discretionary.
Marginal risk and field-wide adoption
Residual risk may be judged acceptable in light of what capabilities and mitigations other publicly available models have, and recommended security levels will "only be effective if the entire frontier AI field applies them". The company frames frontier AI safety as "a global public good".
The Act's systemic-risk duties in Article 55 are owed by every provider individually and do not relax because a competitor's model is similarly capable and less mitigated; conversely, the uniform EU floor is the kind of field-wide application the Framework says its mitigations depend on.
SB 53 leaves the content of a developer's risk-acceptance criteria to the developer and enforces publication and adherence, so a marginal-risk test is permissible under it provided it is disclosed in the published framework, as here.
Harmful manipulation
An exploratory CCL covers models able to "systematically and substantially change beliefs and behavior in identified high stakes contexts" with harm at severe scale; the company calls the research "nascent" and says the CCL may be substantially changed.
Article 5(1)(a) has prohibited, since 2 February 2025, placing on the market AI systems that deploy purposefully manipulative or deceptive techniques materially distorting behaviour and causing significant harm — a far lower bar than the Framework's severe-scale threshold, although the Framework says risks outside its scope are handled by Google's wider responsibility practices, which this document does not describe.
No US federal or state frontier-AI instrument in force treats a model's manipulative capability as a catastrophic risk; SB 53's catastrophic-risk definition centres on weapons, cyberattacks, criminal conduct without meaningful human oversight and evasion of control.
Google DeepMind's framework is a self-governance document that names no statute, yet it lands close to what California's SB 53 asks a large frontier developer to publish: capability thresholds, mitigations, weight security and an annual review. Where it goes beyond the law it goes beyond the EU AI Act, whose systemic-risk duties are drafted as bare outcomes — assess, mitigate, secure adequately — with no tiers, safety cases or named security levels, and its attention to high-risk internal deployment has no counterpart in either regime. The soft edges are the parts regulators have made enforceable: reporting to government is an aim conditioned on an unmitigated CCL, against the EU's "without undue delay" duty to the AI Office and SB 53's 15-day and 24-hour clocks; external review is discretionary where Illinois SB 315 will make a third-party audit compulsory from 2027; and the marginal-risk test lets acceptability depend on what competitors ship, a relativism the EU's individually owed duties do not recognise. US federal law adds nothing binding to either side.
Source
https://storage.googleapis.com/deepmind-media/DeepMind.com/Blog/strengthening-our-frontier-safety-framework/frontier-safety-framework_3-1.pdf- Date on the page:
- Published: April 17, 2026
- Source checked:
- opened and confirmed on 2026-09-29