AI Safety Framework
Undated · The document carries no date anywhere on its face: no cover date, footer date, version number or change log (its only running text besides the body is a page counter, 1 / 5 to 5 / 5). The date 2026-06-25 comes from the PDF file's embedded metadata (CreationDate 2026-06-25 23:42:43 +09:00, ModDate 23:47:57 the same day), not from the document, and is used only to sort the record. The id therefore ends UNDATED. An earlier Korean-language file at a different samsung.com policy-file id has metadata dated 2026-06-12, which suggests the framework text existed by mid-June 2026, but that too is file metadata.
Not law. This is a company's own public position on AI regulation. It is not law, and it carries no legal force.
What it argues for
This is Samsung Electronics' published AI safety framework, and it is a framework for consumer devices running AI locally, not for frontier models or severe risks. It opens by fixing that scope — "As consumer electronics (CE) increasingly integrate on-device AI, AI safety has become an important issue" — and describes "a comprehensive on-device AI Safety Framework, which focuses on two key processes and four key components". The concerns it names are the ones a device maker faces: "With on-device AI, safety is essential for protecting user privacy, ensuring AI’s reliability, and mitigating potential risks from malicious attacks." The two processes are data and model governance (quality and privacy checks at data acquisition, data cards, model cards, a "safety principle checklist" and a fairness, transparency and accountability assessment) and safety evaluation with red teaming, in which "Each AI model undergoes a safety assessment to identify and mitigate potential risks" using "public safety benchmarks to quantitatively evaluate safety risks in various aspects such as toxicity, bias, truthfulness and overall reliability", followed by a four-phase red-teaming cycle run in "a separate and isolated Red Team test environment". The four components are model and system, data platform, tools and AI governance. Accountability sits with an internal unit: "The AI Strategy Team manages data, model life cycle, and safety-related processes in connection with various related departments and updates processes in response to applicable laws and regulations." The framework says nothing about regulation beyond that line and an aim to "comply with international standards", names no law, standard or regulator, and contains no capability thresholds, catastrophic-risk categories (CBRN, cyber, loss of control), stop condition, incident reporting, external review or publication cadence. Samsung Electronics signed the Frontier AI Safety Commitments at the AI Seoul Summit in May 2024, but this document does not address severe or frontier-model risk and should not be read as a frontier safety framework.
Stated positions (13)
- Scope is on-device consumer AI, stated at the outset: "As consumer electronics (CE) increasingly integrate on-device AI, AI safety has become an important issue." The framework is described as "a comprehensive on-device AI Safety Framework"; it covers no frontier, general-purpose or cloud models and no severe-risk capabilities.
- The risks it names are privacy, reliability and attack resistance: "With on-device AI, safety is essential for protecting user privacy, ensuring AI’s reliability, and mitigating potential risks from malicious attacks."
- Three principles are named, without definitions: the framework aims to address concerns "by keeping Fairness, Transparency and Accountability."
- Legal compliance is stated only as an aim, with no law named: a structured framework is "fundamental to preserve user trust and comply with international standards."
- Data is vetted at acquisition: "we take steps to evaluate its quality and appropriateness and to address any potential privacy and other issues", through a four-step process of specification planning and validation (including risk and quality assessment), monitoring of acquisition, verification and registration, after which "we utilize data cards to manage and keep track of the data."
- Models get model cards and an internal checklist: "we maintain a safety principle checklist and conduct fairness, transparency and accountability assessment." Nothing says the data cards or model cards are published.
- Every model is safety-tested before use: "Each AI model undergoes a safety assessment to identify and mitigate potential risks", using "public safety benchmarks to quantitatively evaluate safety risks in various aspects such as toxicity, bias, truthfulness and overall reliability", with results compared against reference models.
- Red teaming is adversarial security testing tied to Samsung's existing software security process: it uses "controlled adversarial techniques to simulate potential security threats" and "builds upon the existing security development life cycle and operates in four phases" (planning, analysis and design, evaluation and testing, operation and maintenance).
- Testing is isolated from production and mixes methods: Samsung sets up "a separate and isolated Red Team test environment to prevent potential interference with the production system", and "We execute both manual and automated tests."
- Findings lead to re-assessment and remediation, not a stop rule: after final validation reports the evaluation team plans a re-assessment, and the development team adopts mitigations "such as retraining models or selecting a more safe model to deploy". No condition is stated under which a model would not ship.
- Evaluation is periodic across the lifecycle: the model and system component includes "conducting periodical model evaluation and validation processes throughout AI model’s development and lifecycle."
- Governance is internal and operational: "We have established an operational team to monitor and manage AI Safety Framework execution", and "The AI Strategy Team manages data, model life cycle, and safety-related processes in connection with various related departments and updates processes in response to applicable laws and regulations." No board, executive owner, external reviewer or review cadence is named.
- Omits what frontier safety frameworks carry: no capability thresholds, no catastrophic-risk domains, no pause or non-deployment commitment, no model-weight security tiers, no incident reporting and no public reporting of evaluation results.
About this document
A 5-page PDF in English hosted in the policy-file area of samsung.com's global sustainability section, titled AI Safety Framework (numbered as section 1, which suggests it was lifted from a longer policy document). It has no byline, no author and no signature, and is issued in Samsung Electronics' corporate voice; the file name is Samsung_Electronics_AI_Safety_Framework_en.pdf. It is undated. After a one-paragraph introduction and a figure captioned Structure of AI Safety Framework (image only, no text), it runs four short headed parts: Importance of AI Safety Framework for CE Devices; Key Processes to Ensure AI Safety (Data & Model Governance; AI Safety Evaluation & Red Teaming, with four phases — Planning, Analysis & Design, Evaluation & Testing, Operation & Maintenance); Key Components to Support AI Safety Process (Model & System, Data Platform, Tools, AI Governance); and Governance Operation, a two-sentence paragraph naming the AI Strategy Team. It is roughly 800 words, cites no law, standard, benchmark by name or external body, and makes no request of any government. A Korean-language version exists at another samsung.com policy-file address.
How this sits against AI law
Each stance compared with what EU and US instruments actually require. Where no instrument addresses a theme, that gap is shown rather than hidden.
Severe-risk thresholds and frontier-model scope
The framework is scoped to "on-device AI" in consumer electronics. It names no catastrophic-risk domains, sets no capability thresholds and contains no commitment to pause or withhold a model; findings lead to retraining or choosing a different model.
Article 55 requires providers of general-purpose AI models with systemic risk to evaluate models including by adversarial testing, assess and mitigate systemic risks, report serious incidents to the AI Office and ensure adequate cybersecurity; the framework addresses systemic risk not at all. Whether any Samsung model is a systemic-risk general-purpose model is not stated in the document.
SB 53 requires large frontier developers (models trained above 10^26 operations, annual revenue above $500 million) to publish a frontier AI framework covering catastrophic-risk thresholds, mitigations, third-party assessment, cybersecurity and governance. Samsung meets the revenue test; nothing public shows it trains models at that compute scale, so the comparison is with what the law expects of such a framework, not a finding that Samsung is in breach.
Training-data governance and documentation
Data is checked at acquisition for quality, appropriateness and privacy through a four-step process of specification planning, monitored acquisition, verification and registration, then tracked with data cards; models are documented with model cards. Neither is said to be published.
Article 10 requires training, validation and testing data for high-risk AI systems to be subject to data governance and management practices, including assessment of the availability, quantity and suitability of the data and examination for possible biases — the same kind of acquisition-stage vetting Samsung describes.
AB 2013 requires developers of generative AI systems made available to Californians to post documentation of their training data on their website, including dataset sources, whether the data contains copyrighted material or personal information, and how it was cleaned. Samsung keeps data cards for internal tracking and commits to no publication.
Pre-deployment safety evaluation against benchmarks
"Each AI model undergoes a safety assessment to identify and mitigate potential risks", using public safety benchmarks for toxicity, bias, truthfulness and reliability and comparing the model against reference models; evaluation repeats periodically across the model lifecycle.
Article 9 requires a risk management system for high-risk AI systems run as a continuous process across the lifecycle, including testing before the system is placed on the market against previously defined metrics — the practice Samsung describes, though the Act also requires the results to be documented for authorities.
NIST's Generative AI Profile (AI 600-1) is voluntary guidance that recommends measuring generative-AI risks such as confabulation, harmful bias and dangerous or hateful content before and after deployment; Samsung's benchmark categories track it closely, and neither instrument sets a pass mark.
Red teaming and resistance to adversarial attack
Samsung red-teams models with "controlled adversarial techniques to simulate potential security threats" in a four-phase process built on its security development life cycle, run in an isolated environment with manual and automated tests, followed by re-assessment once fixes are applied.
Article 15 requires high-risk AI systems to be resilient against attempts by unauthorised third parties to alter their use or performance by exploiting vulnerabilities, and names data poisoning, model poisoning, adversarial examples and confidentiality attacks as threats to address.
The NIST Generative AI Profile treats AI red-teaming as a pre-deployment testing practice and covers information-security risks; it is voluntary, as Samsung's commitment is.
Fairness and bias
Fairness is one of three named principles. Samsung keeps a "safety principle checklist", runs a fairness, transparency and accountability assessment on models and benchmarks every model for bias.
Article 10 requires the data used for high-risk AI systems to be examined for possible biases likely to affect health, safety or fundamental rights or lead to prohibited discrimination, and for measures to detect, prevent and mitigate them.
Texas's TRAIGA prohibits developing or deploying an AI system with the intent to unlawfully discriminate against a protected class, an intent-based ban. Samsung's routine bias testing of every model goes beyond what that prohibition requires.
Transparency to users and marking of AI-generated content
Transparency is named as a principle, but the framework makes no commitment to tell users when they are dealing with AI, to label or watermark generated content or to publish model information; its transparency work is an internal assessment.
Article 50 requires providers to design AI systems that interact with people so that they are informed they are dealing with AI, and requires providers of systems generating synthetic audio, image, video or text to mark outputs in a machine-readable format detectable as artificially generated.
The California AI Transparency Act (SB 942 as amended by AB 853, operative 2 August 2026) requires covered generative AI providers with over one million monthly users to offer a free AI detection tool, embed latent disclosures in generated image, video and audio, and offer users a visible disclosure option. The framework mentions none of this.
Internal governance and lifecycle management
An operational team monitors execution of the framework, and "The AI Strategy Team manages data, model life cycle, and safety-related processes in connection with various related departments and updates processes in response to applicable laws and regulations." No board, named executive, external reviewer or review cadence is given.
Article 17 requires providers of high-risk AI systems to keep a documented quality management system covering, among other things, data management, testing and validation procedures and an accountability framework for management and staff; Samsung describes an internal system of that kind without publishing its documentation.
The NIST AI Risk Management Framework is voluntary guidance whose Govern function asks organisations to assign roles and responsibilities and maintain policies for managing AI risk across the lifecycle — which is the level of commitment Samsung makes.
Incident reporting and outside accountability
The framework contains no incident-reporting process, no external evaluation, no public reporting of safety results and no statement of how or when it will be revised.
Article 73 requires providers of high-risk AI systems to report serious incidents to market surveillance authorities, and Article 55 requires providers of systemic-risk general-purpose models to report serious incidents to the AI Office without undue delay.
SB 53 requires frontier developers to report critical safety incidents to California's Office of Emergency Services within 15 days (24 hours where there is imminent risk of death or serious injury) and large frontier developers to republish framework changes within 30 days; Samsung's framework has no equivalent process.
Measured against the EU AI Act, Samsung's framework reads like the internal half of a high-risk provider's compliance file — data vetting, bias checks, pre-release testing and adversarial robustness work — without the outward-facing half: nothing on telling users they are dealing with AI, marking generated content, reporting incidents or publishing documentation. Against US law the fit depends on which instrument is in view. The voluntary NIST materials describe much the same practice, and Samsung's routine fairness testing goes further than Texas's TRAIGA, which only bars AI built with intent to unlawfully discriminate. But California's disclosure laws — AB 2013 on training data, the AI Transparency Act on detection tools and embedded disclosures, and SB 53 on published frontier frameworks and incident reports — ask for exactly the public artefacts this document does not commit to. The framework never names any of these laws; its only reference to regulation is that the AI Strategy Team "updates processes in response to applicable laws and regulations."
Source
https://www.samsung.com/global/sustainability/policy-file/AZTUlveqAMoALYMV/Samsung_Electronics_AI_Safety_Framework_en.pdf- Date on the page:
- Source checked:
- opened and confirmed on 2026-09-30