← All company positions
Metaframework

Advanced AI Scaling Framework — Version 2

Published April 7, 2026 · Printed in "Appendix II - Change log" as "April 7, 2026 (Advanced AI Scaling Framework v2.0)". The cover page carries no date. Meta's announcement post prints April 8, 2026.

Not law. This is a company's own public position on AI regulation. It is not law, and it carries no legal force.

What it argues for

This is the governance regime Meta holds itself to for frontier models, and version 2 is a substantial rewrite of the February 2025 Frontier AI Framework — including a rename from "Frontier AI Framework" to "Advanced AI Scaling Framework". It takes an explicitly "outcomes-led" approach: Meta first names catastrophic outcomes it must strive to prevent, then threat-models the causal pathways to them, then builds evaluations to measure whether a model would "substantially contribute" to those pathways. It covers three catastrophic risk domains — Chemical & Biological, Cybersecurity, and Loss of Control, the last newly added in v2 — plus two "emerging" areas (nuclear & radiological, physical autonomy) that it says warrant investigation but are too nascent to be rigorously measured yet. Crucially, v2 loosened the release gates while tightening the disclosure: the critical threshold moved from "Stop" to "Develop with Mitigations" and the high threshold from "Do not release" to "Deploy with mitigations", with the triggering standard relaxed from "uniquely enable" to "substantially contribute to" — so all thresholds now permit proceeding provided mitigations are validated to bring residual risk back to moderate or lower. In exchange it adds named accountability (the Chief AI Officer or the Director of Alignment and Risk decides deployment), whistleblower and non-compliance reporting protocols with retaliation protections, incident response provisions, and defined criteria for publishing preparedness reports and a model spec. It defines "Frontier AI" by two tests — high capability in the named catastrophic risk domains, or a compute threshold of at least 10^26 integer or floating point operations "or another threshold as may be defined by evolving standards or industry best practices" — explicitly hooking its own scope to the kind of compute threshold regulators use. Open-weights release is treated as a first-class deployment mode rather than an exception: the document commits that if Meta is considering releasing a model's weights or a fine-tuning API, it will run domain-specific capability training to "attempt to upper bound the capabilities of the model" before release, and it notes that chem-bio and cyber catastrophes are "more likely to occur through adversarial use of closed or open-weight deployments" while Loss of Control risks arise with similar probability in any deployment type, including internal. On regulation as such the document is deliberately modest but not silent: it commits to reviewing the Framework at least annually with a published change log and justification for each modification, to tracking developments through engagement with "academics, policymakers, civil society organizations, and governments", and it observes that "there is a lack of consensus among industry and within regulatory frameworks as to how to define some of these terms and concepts" — positioning Meta's own definitions as provisional pending convergence.

Stated positions (10)

  • Outcomes-led risk thresholds rather than capability-led ones: Meta defines catastrophic outcomes first (arguing they are "more stable and enduring than the particular capabilities of any given Frontier AI"), then threat-models pathways, then evaluates whether a model would "substantially contribute" to a threat scenario.
  • Three in-scope catastrophic risk domains — Chemical & Biological, Cybersecurity, and Loss of Control (new in v2) — plus nuclear & radiological and physical autonomy flagged as emerging outcomes needing further research before they can be rigorously measured.
  • v2 relaxed the release gates: critical threshold changed from "Stop" to "Develop with Mitigations", high from "Do not release" to "Deploy with mitigations", moderate from "Release" to "Deploy"; and the trigger standard was relaxed from "uniquely enable" to "substantially contribute to". Every threshold now permits proceeding if mitigations are validated to reduce risk to moderate or lower.
  • Explicit, checkable scope definition: "Frontier AI" = high capability in a Framework risk domain OR training compute of at least 10^26 integer or floating point operations, "or another threshold as may be defined by evolving standards or industry best practices".
  • Named human accountability: the Chief AI Officer or the Director of Alignment and Risk determines whether to require more testing, require additional mitigations, or approve deployment — with whistleblower and non-compliance reporting protocols, retaliation protections, and incident response provisions added in v2.
  • Transparency undertakings: publish preparedness reports with defined content requirements and update triggers (including a substantial compute increase over the last reported model), publish a model spec plus evaluations of adherence to it, disclose model-weight security practices, and disclose known issues limiting generalisation of safety testing — including training changes that reduce interpretability or may cause obfuscation of a model's reasoning.
  • Open-weights treated as a governed deployment mode, not an exemption: for weight releases or fine-tuning APIs, Meta commits to domain-specific capability training to "attempt to upper bound the capabilities of the model", refusal-only and no-mitigation testing, and task-optimized agent scaffolds with generous token budgets in agentic evaluations.
  • Publishes illustrative numeric risk-acceptance criteria — e.g. on the BioTIER refusal evaluation at least 80% refusal or safe responses and 40% under adversarial attack; at least 40% on MASK and at most 50% on Agent Misalignment; and <75% pass@10 on simple capture-the-flag challenges rules a model out of above-moderate cyber risk.
  • Commits to at least annual review with a published change log and a stated justification for each modification, and acknowledges "a lack of consensus among industry and within regulatory frameworks" on defining these terms — framing its own definitions as provisional pending standards convergence.
  • A benefits assessment sits alongside the risk assessment: Meta argues mitigations must be chosen so as to avoid "eliminating the benefits we hoped to deliver in the first place", i.e. that risk management should be calibrated against the societal upside rather than applied absolutely.

About this document

A 44-page, roughly 13,800-word PDF published by Meta as a static resource on ai.meta.com. No author byline, no cover date, no external reviewer. The cover reads only "Advanced AI Scaling Framework — Version 2"; the sole date printed anywhere sits in Appendix II's change log, which dates v2.0 to April 7, 2026 and the initial "Frontier AI Framework" to February 3, 2025. A "How to read this document" page announces five numbered sections — Introduction; Governance & Transparency; Outcomes & Thresholds; Implementation; Future work — plus Appendix I, about twenty defined terms, and Appendix II, a change log that itemises six named amendments against v1 rather than summarising them in prose. The structural spine is Table 1: three risk thresholds (Critical, High, Moderate or lower) against three columns (threshold definition, security mitigations, measures). Four further tables pair outcomes with threat scenarios and example enabling capabilities — Cyber 1-3, CB 1-3, Loss of Control 1-2, and one sample Physical Autonomy row. Footnotes cite arXiv evaluation literature (Cybench, CTF benchmarks, pass@k). Every commitment points inward: Meta's own models, evaluations, thresholds and executives. The document asks nothing of legislators, makes no recommendation, and names no statute, regulator or jurisdiction across all 44 pages; law surfaces only obliquely — redactions "as appropriate under law", preparedness triggers "informed by evolving regulatory requirements", internal-use summaries for unnamed "relevant authorities". Modal verbs carry the weight: "we will" alternates with "we may", "typically", "where appropriate", and protection "insofar as is technically feasible and commercially practicable".

How this sits against AI law

Each stance compared with what EU and US instruments actually require. Where no instrument addresses a theme, that gap is shown rather than hidden.

What counts as a frontier model — the scope trigger

Appendix I defines Frontier AI by two alternative limbs: high capability in one of the Framework's catastrophic risk domains relative to Meta's own or the most advanced external models, OR training compute of at least 10^26 integer or floating-point operations, counting material fine-tuning and RL steps. Anything outside both limbs is outside the Framework entirely.

European UnionAsks for less

The AI Act presumes a general-purpose model has systemic risk at cumulative training compute above 10^25 FLOP — an order of magnitude below Meta's compute limb. A model trained at, say, 3x10^25 FLOP that is not judged more capable than Meta's existing models is presumed systemic-risk under the Act while falling outside Meta's Framework altogether. Meta's capability limb partly closes the gap, but it is self-assessed against a self-chosen reference class, where the Act's trigger is arithmetic and rebuttable only to the Commission.

United StatesAligned

SB 53 defines a frontier model at greater than 10^26 operations. Meta's compute limb is that number exactly, and its capability limb is an additional catch that the statute does not require. The one asymmetry runs the other way: SB 53's heavier duties attach to a large frontier developer defined by revenue, a test Meta plainly meets and the Framework never mentions.

Publishing a versioned self-governance framework with a change log

Commits to review the Framework at least every twelve months, or sooner where there are reasonable grounds to believe its adequacy or Meta's adherence has been materially undermined; to have each update confirmed by the Director of Alignment and Risk and the Chief AI Officer; and to publish a justification for each modification in the appended change log. Appendix II is that change log, already carrying two entries.

European UnionAligned

Article 55 requires providers of systemic-risk general-purpose models to assess and mitigate systemic risk on a continuing basis, with a published safety and security framework as the expected demonstration route under the Act's code-of-practice machinery. Meta's annual-review-plus-published-change-log discipline matches that in substance. The difference is legal character rather than content: the Act's duty is binding and cannot be narrowed by the provider, whereas this Framework states that defined outcomes or threat scenarios might be removed if Meta determines they no longer meet its criteria.

United StatesAligned

The New York Frontier Model Transparency and Safety Act will require a large developer to write, implement and publish a safety and security protocol and keep it current, from 1 January 2027. Meta's Framework is already precisely that artefact, published in full rather than in redacted summary, and its change log makes the year-on-year movement legible — which is the only reason the v2 loosening of release gates can be seen at all.

RAI-US-NY-A9449S8-2026Awaiting Entry — not binding law today.

Per-release safety transparency — preparedness reports and a model spec

Commits to publish a preparedness report for every closed or open frontier release and for significant capability-increasing updates, covering risk assessment, evaluation results, elicitation detail and resources spent, human-expert baselines, reference-class comparisons, model-weight security practices, mitigation adequacy reasoning, adversarial robustness and controllability results, undesirable post-training behaviours such as reward hacking or scheming, and known issues that could hinder generalising safety testing to real-world risk. Also commits to publish a model spec and to evaluate adherence to it. Redactions are permitted for trade secrets, with reasons given.

European UnionAsks for more

The Act routes technical documentation to the AI Office and to downstream providers rather than to the public; what reaches the public is a summary of training content and, for systemic-risk models, whatever the code of practice surfaces. Meta commits to publish the evaluation and mitigation record itself, including the disclosure of known limits on its own safety testing, which no provision of the Act obliges. Note also what is absent: the Framework says nothing about the Act's training-data summary or copyright-policy duties.

United StatesAsks for more

SB 53 requires a transparency report at or before deployment of a new or substantially modified frontier model, plus periodic summaries of catastrophic-risk assessments to the state. Meta's preparedness-report content list is materially richer than that floor — elicitation methodology, evaluator access, human baselines, reference-class results, interpretability regressions in training, and scheming or reward-hacking findings are all volunteered, and none are statutory minimums.

Serious-incident reporting to authorities

Section 2.3.2 commits to a comprehensive global incident response programme that identifies incidents from internal and external sources and reports critical incidents "as appropriate". Section 2.2.2 adds that Meta will regularly assess catastrophic risk from internal use and, "as appropriate", give relevant authorities a summary through an internal-use risk report, with expedited updates for any unprecedentedly rapid capability increase. No recipient is named, no clock is set, and "critical incident" is never defined.

European UnionAsks for less

Article 55(1)(c) requires providers of systemic-risk general-purpose models to track, document and report serious incidents and possible corrective measures to the AI Office and, as appropriate, to national competent authorities, without undue delay. Meta commits to reporting "as appropriate" with no timeframe, no named recipient and no definition of the reportable event — three things the Act supplies and the Framework leaves to Meta's own judgement.

United StatesAsks for less

The New York act runs a 72-hour disclosure clock to the Attorney General and state authorities for safety incidents, backed after the 2026-03-27 chapter amendment by penalties of $1M for a first violation and $3M thereafter. The Framework carries no clock at all, so on its own terms it would not tell a reader whether Meta considers itself to owe anyone a report within any period.

RAI-US-NY-A9449S8-2026Awaiting Entry — not binding law today.

Named executive accountability and whistleblower protection

New in v2: the Chief AI Officer oversees the whole evaluation and mitigation process and approves deployment; the Director of Alignment and Risk executes the risk-assessment lifecycle, preparedness reports and Framework updates, and must be given sufficient human, financial and computational resources. Section 2.3.1 commits to a confidential and, at the reporter's option, anonymous internal channel, regular status updates to the discloser, and explicit protection from adverse employment action and retaliation for good-faith reports.

European UnionNo equivalent law

The AI Act imposes no duty on a general-purpose model provider to name an accountable executive, and contains no AI-specific whistleblower regime; a non-EU provider must appoint an authorised representative in the Union, which is a service-of-process role, not a safety-accountability one. Meta's named-officer structure and retaliation protection have no counterpart obligation in the Act — they answer a US statutory pattern, not a European one.

United StatesAsks for less

SB 53 gives covered employees a statutory right: an anonymous internal reporting channel for large frontier developers, status updates to the reporter on a fixed cadence, anti-retaliation protection enforceable in court with injunctive relief and fees, and an external route. Meta's version is a policy, all reports route ultimately to the internal governance function, the Chief AI Officer and the Director of Alignment and Risk — the same people a Framework-compliance report would concern — with no external channel and no remedy. The Framework-specific protocol is also described as still being developed.

What is deliberately left out of scope

Section 3.2 admits an outcome only if it satisfies all four criteria — plausible, catastrophic, net new (not achievable at that scale, cost or by that actor without general-purpose AI), and instantaneous or irremediable. Harms that unfold gradually or are partially remediable are expressly excluded and left to "other safety and integrity processes outside of the scope of this Framework", which the document does not describe. Nuclear, radiological and physical autonomy are parked as emerging, with a sample table but no threshold.

European UnionNo equivalent law

The draft High-Risk Classification Guidelines work by intended purpose and deployment context against the Annex III use-case list — biometrics, critical infrastructure, education, employment, essential services and credit, law enforcement, migration, justice. Meta's four criteria screen out exactly this class of harm, because discrimination in a hiring or credit decision is gradual and remediable rather than instantaneous and irreversible. The Framework is not weaker on this layer; it is silent on it, and a reader should not treat it as Meta's answer to high-risk classification.

RAI-EU-NA-CLASSIF-2026Draft — not binding law today.
United StatesNo equivalent law

Colorado SB24-205 obliged developers and deployers of high-risk systems to use reasonable care against algorithmic discrimination in consequential decisions, with impact assessments and disclosure, until it was repealed on 14 May 2026. Nothing in this Framework engaged that duty while it stood: the word discrimination does not appear, and the four inclusion criteria structurally exclude it. The two instruments govern disjoint risk surfaces.

RAI-US-CO-CSCPAXX-2024Repealed — not binding law today. Superseded by RAI-US-CO-SB26189-2026.

Open-weight release treated as a governed deployment mode

Appendix I lists open release as one of five deployment types, and the Framework treats it as an assessment variable rather than an exemption. For open-weight releases and fine-tuning APIs, Meta models adversaries capable of modifying model behaviour through continued training, and commits that where weights may be released it will conduct domain-specific capability training to attempt to upper bound the model's capabilities before release. Transparency is argued as a benefit of openness: published weights let the broader community independently inspect and assess capability.

European UnionAsks for more

Article 53(2)'s relief for free and open-source general-purpose models expressly does not extend to models with systemic risk, so the Act gives an open-weight frontier model no discount — but it also prescribes no specific pre-release treatment for weight publication. Meta volunteers two things the Act does not specify: adversary modelling that assumes continued training on the released weights, and capability upper-bounding before the weights leave. On the point where EU law is silent, the Framework is concrete.

United StatesAligned

America's AI Action Plan makes encouraging open-source and open-weight American models an express policy objective, on the argument that open models serve startups, academia and national competitiveness. Meta's treatment of open release as a normal, governed deployment mode rather than an exceptional risk is the corporate position that most directly matches that federal preference — and the Framework's transparency-through-openness argument is the same argument the Plan makes.

A voluntary instrument with no legislative ask

The Framework is entirely self-directed. It makes no recommendation to any government, names no statute, regulator or jurisdiction in 44 pages, and reserves to Meta the power to add, remove or update catastrophic outcomes and threat scenarios and to change how models are prepared for evaluation. v2 exercised that power: the critical measure moved from Stop to Develop with Mitigations and the high measure from Do not release to Deploy with mitigations, while the trigger widened from uniquely enable to substantially contribute.

European UnionAsks for less

Under the AI Act's enforcement architecture the systemic-risk duties are supervised centrally by the AI Office, with information requests, evaluation powers, requests for mitigation and fines for non-compliance; a provider cannot narrow its own obligations by publishing a revised document. This Framework is amendable by the two executives it names, and v2 loosened its own release gates without any external confirmation. The commitments may be substantively strong, but the instrument supplies no external check on their revision.

United StatesAligned

EO 14179 revoked its predecessor and set federal policy toward removing barriers to American AI leadership, favouring industry-led practice over prescriptive federal rulemaking on model development. A published, unilateral, self-amendable framework that asks nothing of Washington is the form of governance that policy invites, and Meta's document supplies it — while, silently, tracking the specific obligations that California and New York have since made mandatory.

Meta's v2 reads as though drafted against the US state statutes without ever naming them: it adopts California SB 53's 10^26 threshold verbatim, the published-framework-plus-annual-change-log form both California and New York now require, and the named-officer and whistleblower architecture SB 53 made law — then goes beyond all of them on what a per-release preparedness report must contain. Against the EU AI Act it is simultaneously narrower and more forthcoming: narrower in trigger (10^26 against the Act's 10^25 systemic-risk presumption), narrower in risk surface (catastrophic, net-new and irremediable outcomes only, with the entire Annex III high-risk use-case layer untouched), yet more public in disclosure, since the Act routes documentation to the AI Office while Meta publishes. The decisive gap is enforceability and incident reporting: EU duties are binding, centrally supervised and not narrowable by the provider, whereas this Framework is amendable by the two executives it names — and v2 has already used that power to loosen its own release gates while committing only to report critical incidents "as appropriate", with no clock and no named recipient.

Source

https://ai.meta.com/static-resource/Meta_Advanced-AI-Scaling-Framework-v2
Date on the page:
April 7, 2026 — printed on p.44 under the heading "Appendix II - Change log", as the entry "April 7, 2026 (Advanced AI Scaling Framework v2.0)". Verified as the claim described: the cover prints only "Advanced AI Scaling Framework / Version 2" with no cover date, and the change log's only other entry is "February 3, 2025 (Frontier AI Framework) - Initial version." A regex sweep over all 44 pages found NO other date printed anywhere in the document, so there is no conflicting date.
Source checked:
opened and confirmed on 2026-09-18