← All company positions
xAIframework

xAI Frontier Artificial Intelligence Framework

Published 30 June 2026 · Printed on the document as "Effective Date: 30 June 2026".

Not law. This is a company's own public position on AI regulation. It is not law, and it carries no legal force.

What it argues for

This is a self-binding governance framework, not advocacy: xAI states the risk-management regime it holds itself to for frontier models such as Grok, and says nothing about what AI law should be. It names four risk domains it treats as primary — CBRN Risks, Offensive Cybersecurity Risks, Loss of Control Risks and Harmful Manipulation Risks — and borrows that terminology explicitly from "The Safety and Security Chapter of the General-Purpose AI Code of Practice developed under the EU AI Act", while also referencing "NIST's AI Risk Management Framework and ISO/IEC 42001 for AI management systems". The core commitment is a full systemic risk assessment "at least once a year" plus smaller evaluations at trigger points (new model release, a serious incident, a material increase in risk from use or integration, or a material change in the basis for judging risks acceptable), with a "systemic risk acceptance determination" that is "a precondition for release of our models for public use". Where risk is not acceptable outright, the stated levers are tiered availability — "the full functionality of our models may be available to only a limited set of trusted parties, partners, and government agencies" — differentiated controls by end-user type, or another round of assessment. Security commitments are pinned to named external baselines ("NIST 800-171 Rev.3 framework and supported by SOC 2 Type II evaluations"), including encryption of model weights and measures against "large-scale extraction and distillation of reasoning traces". Its only posture toward regulators is passive compliance: "When reportable under applicable laws and regulations, xAI will provide the relevant authorities with a copy of the incident report within the required deadlines."

Stated positions (10)

  • Frames governance around four named risk domains — CBRN, Offensive Cybersecurity, Loss of Control, and Harmful Manipulation — and adopts that vocabulary from the EU AI Act's General-Purpose AI Code of Practice (Safety and Security Chapter), cited in two footnotes.
  • Commits to a full systemic risk assessment and mitigation process "at least once a year", plus off-cycle evaluations at four stated trigger points (updated model release, serious incident, materially increased risk from use/integration, or materially changed basis for accepting risk).
  • Makes the systemic risk acceptance determination a release gate: evaluations "are performed precedent to the wider deployment of our models, and are a precondition for release of our models for public use"; xAI "will only proceed ... if the systemic risks stemming from the model are determined to be acceptable".
  • Endorses tiered release over binary withhold-or-ship: "the full functionality of our models may be available to only a limited set of trusted parties, partners, and government agencies", with different feature sets for consumer mobile apps versus sophisticated business users.
  • Anchors itself to external standards rather than proposing new ones — NIST AI RMF and ISO/IEC 42001 for AI management, NIST 800-171 Rev.3 plus SOC 2 Type II for information security — reviewed during annual reviews.
  • Treats mitigation as layered model-level safeguards (safety training, system prompts, CBRN classifiers/filters) aimed at "bottlenecks" in malicious-use pathways, with continuous work on robustness to jailbreaks and prompt injection.
  • Commits to a documented Security Goal naming the threat actors defended against — "sophisticated non-state actors, insider threats, state-sponsored actors" — reviewed at least every year, and to measures against distillation of reasoning traces to prevent unauthorized proliferation.
  • Assigns internal accountability by "designating risk owners" responsible for mitigating identified risks and monitoring for critical incidents, with escalation channels including red-teaming, telemetry alerting, employee escalation, monitoring of public comments on the X platform, and third-party reporting.
  • Reserves the right to shut down: xAI "may temporarily fully shut down the relevant system" if continuing to run it "would materially and unjustifiably increase the likelihood of a risk", and may revoke access to implicated user accounts.
  • Toward regulators the stance is compliance, not advocacy — incident reports go to "the relevant authorities" only "when reportable under applicable laws and regulations"; the framework proposes no legislation, no licensing regime, and no third-party audit or external red-team requirement.

About this document

A nine-page, roughly 3,300-word PDF headed "xAI Frontier Artificial Intelligence Framework", carrying an effective date of 30 June 2026 and a running footer on every page. It is issued in the name of xAI LLC with no named author, signatory, version number or revision history; its PDF metadata still carries the internal working title "Privileged/Confidential DRAFT working FRAMEWORK DOC" and shows it was exported from Google Docs. Four numbered sections: an Introduction naming four risk domains (CBRN, Offensive Cybersecurity, Loss of Control, Harmful Manipulation); a Risk Management Framework covering risk identification — with sub-parts on CBRN, loss of control and offensive cyber, but none on manipulation — systemic risk analysis, a risk acceptance determination, safety mitigations and security mitigations (the number 2.3 is used twice); a section on Incident reporting; and a one-paragraph section on Governance. Footnotes tie its vocabulary and its four risk domains to the Safety and Security Chapter of the EU's General-Purpose AI Code of Practice, which xAI signed, and cite the DeepSeek-R1 paper as the reason for its anti-distillation controls. It also names NIST's AI Risk Management Framework, ISO/IEC 42001, NIST SP 800-171 Rev. 3 and SOC 2 Type II. It commits to an annual systemic risk assessment, an annually reviewed Security Goal, and evaluation before public release. It contains no numeric threshold, no evaluation result, no external reviewer, and no ask of governments or other labs.

How this sits against AI law

Each stance compared with what EU and US instruments actually require. Where no instrument addresses a theme, that gap is shown rather than hidden.

Publishing a frontier safety framework

xAI publishes a standing framework setting out how it governs frontier model risk, and says it will review it periodically and expects significant changes as model capabilities expand.

European UnionAligned

xAI signed the Safety and Security Chapter of the GPAI Code of Practice, whose Commitment 1 requires exactly such a Framework and whose Measure 1.4 gives the AI Office unredacted access to it within five business days of confirmation.

United StatesAligned

Section 22757.12 requires a large frontier developer to write, implement and conspicuously publish a frontier AI framework and to review it at least annually.

Stated thresholds for frontier capability

xAI names four risk domains and says it applies risk tiers and safety margins, but publishes no capability threshold, compute figure or trigger level at which a mitigation or a halt would apply.

European UnionAsks for less

Article 51(2) fixes an explicit quantitative trigger for systemic risk at 10^25 training FLOP, and the Code of Practice requires a Framework to state its systemic risk acceptance criteria rather than merely assert that criteria exist.

United StatesAsks for less

SB 53 requires the published framework to describe how the developer defines and assesses the thresholds it uses to identify catastrophic risk.

Evaluation before deployment as a release gate

xAI states that its risk evaluations are performed before wider deployment and are a precondition for release of its models for public use, and that it will proceed only where the systemic risks are determined acceptable.

European UnionAligned

Article 55(1)(a) and (b) require providers of GPAI models with systemic risk to evaluate the model under state-of-the-art standardised protocols, including documented adversarial testing, and to assess and mitigate systemic risks at Union level.

United StatesAsks for more

The RAISE Act as enacted barred a large developer from deploying a frontier model where that would create an unreasonable risk of critical harm. The chapter amendment signed 27 March 2026 removed that prohibition: the operative New York text now turns on publishing a safety and security protocol and disclosing incidents, and it does not take effect until 1 January 2027. xAI's pre-deployment release gate therefore goes beyond what New York will require, rather than matching it.

RAI-US-NY-A9449S8-2026Awaiting Entry — not binding law today.

Security controls on model weights

xAI commits to a documented Security Goal naming the threat actors it defends against, reviewed annually, with encryption of model weights, role-based and least-privilege access, and real-time monitoring against unauthorised transfer, built on NIST SP 800-171 Rev. 3 and SOC 2 Type II.

European UnionAligned

Article 55(1)(d) requires an adequate level of cybersecurity protection for the model and its physical infrastructure, which the Code of Practice elaborates into specific objectives for protecting unreleased model parameters.

United StatesAligned

SB 53 requires the framework to describe the cybersecurity practices used to secure unreleased model weights from unauthorised modification or transfer.

Protecting reasoning traces from distillation

Beyond securing weights, xAI commits to security measures against the large-scale extraction and distillation of its models' reasoning traces, citing the DeepSeek-R1 result that traces can cheaply reproduce advanced capability.

European UnionAsks for more

Article 55(1)(d) and the Code of Practice reach the model and its unreleased parameters; neither treats a model's own outputs or reasoning traces as a capability-proliferation channel that must be secured.

United StatesNo equivalent law

The US frontier statutes reach only unreleased model weights; no US instrument addresses distillation of a deployed model's outputs by a competitor or adversary.

Harmful manipulation as a frontier risk

xAI names Harmful Manipulation Risks as one of its four primary risk domains, taking the term from the EU Code of Practice, but gives it no sub-section, no benchmark and no mitigation — unlike CBRN, cyber and loss of control.

European UnionAsks for less

Article 5(1)(a) prohibits outright the placing on the market or use of an AI system deploying subliminal or purposefully manipulative techniques that materially distort behaviour and cause significant harm, so manipulation is not an optional risk domain in the EU.

United StatesNo equivalent law

No US frontier statute treats large-scale manipulation as a catastrophic risk; the state definitions turn on CBRN, cyberattacks on critical infrastructure, loss of control, and death, injury or property-damage counts.

xAI's framework is built to the shape of EU law: it signed the Safety and Security Chapter of the GPAI Code of Practice, and the document follows that Chapter's commitments almost section by section, so on evaluation, weight security and incident reporting it tracks what Articles 53 to 55 of the AI Act already demand. Where it diverges from the EU it does so by omission — no published thresholds, no independent external evaluator, no model-level report, and nothing at all on the manipulation risk it names as one of its own four domains. In the United States nothing at federal level obliges xAI to do any of this; every binding counterpart is state law — California's SB 53, New York's frontier statutes and Illinois' audit mandate — and it is Illinois, not Brussels, that will force the one thing this framework most conspicuously lacks.

Source

https://media.x.ai/v1/website/xai-frontier-artificial-intelligence-framework-30-june-2026-99c40684.pdf
Date on the page:
Effective Date: 30 June 2026
Source checked:
opened and confirmed on 2026-09-18