OpenAI · OpenAI Frontier Governance Framework · View original document ↗

Tiered Model Risk Classification System

Medium severity Medium confidence Explicitdocumentlanguage Unique · 0 of 343 platforms
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity OpenAI recorded 16 documented changes in the last 30 days.
Start monitoring updates
Monitor governance changes for OpenAI Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.
Document Record

What it is

The framework establishes a four-tier risk scoring system applied to each frontier model before deployment, assessing cybersecurity, CBRN, persuasion, and autonomous replication risk; models classified as critical in any category are stated to be ineligible for deployment.

This analysis describes what OpenAI's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes a pre-deployment gate that determines which model capabilities are made available to API operators and end users; a critical classification in any of the four assessed domains would result in that model being withheld from deployment under the stated policy.

Interpretive note: The document does not specify the methodology or verification process for risk classification, creating ambiguity about how consistently the tiered system is applied across model versions.

Consumer impact (what this means for users)

Under this provision, the capabilities of any OpenAI frontier model made available to users are subject to a pre-deployment risk assessment that may result in model features or entire models being withheld if classified as critical risk in cybersecurity, CBRN, persuasion, or autonomous replication domains.

Cross-platform context

See how other platforms handle Tiered Model Risk Classification System and similar clauses.

Compare across platforms →

Monitoring

OpenAI has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
We assess each new model we develop using our Preparedness Framework, which evaluates risk across four categories: cybersecurity, chemical/biological/nuclear/radiological (CBRN) threats, persuasion, and autonomous replication and adaptation (ARA). Models are scored as low, medium, high, or critical risk in each category. We will not deploy a model that scores 'critical' in any category.

— Excerpt from OpenAI's OpenAI Frontier Governance Framework

ConductAtlas Analysis

Institutional analysis (Compliance & governance intelligence)

REGULATORY LANDSCAPE: This provision engages the EU AI Act's requirements for general-purpose AI models with systemic risk, which mandate risk assessments and adversarial testing before deployment for covered models. The European AI Office is the primary enforcement authority for GPAI systemic risk obligations. The provision also references alignment with California SB 1047 frameworks, though that legislation's applicability depends on whether successor measures are enacted. GOVERNANCE EXPOSURE: Medium. The risk classification system is an internal governance mechanism; its legal enforceability as a commitment to regulators or users is not established by this document. Compliance exposure arises if the framework's stated thresholds are not operationally implemented consistently or if the classification methodology is not subject to independent verification. JURISDICTION FLAGS: EU/EEA operators using OpenAI API services face the highest regulatory exposure as the EU AI Act's GPAI systemic risk provisions enter into force. California exposure depends on legislative developments. US federal exposure is currently limited to voluntary commitments. CONTRACT AND VENDOR IMPLICATIONS: Enterprise API operators should assess whether OpenAI's stated pre-deployment risk classification creates implicit representations about the safety properties of deployed models. Vendor due diligence should include review of how classification decisions are communicated to operators and what remedies exist if a previously available model is reclassified. COMPLIANCE CONSIDERATIONS: Compliance teams should map this classification system against their own AI risk assessment obligations under applicable law, particularly for EU-regulated entities. Contract review should assess whether API terms of service incorporate or reference these classification commitments and what obligations arise if a model's risk classification changes post-deployment.

Full compliance analysis

Regulatory citations, enforcement risk, and due diligence action items.

Track 3 platforms — free Get Monitor

Free: track 3 platforms + weekly digest. Monitor: 25 platforms + same-day alerts. No credit card required.

Applicable agencies

  • FTC
    The FTC has oversight authority over unfair or deceptive practices in AI product representations, which could apply if stated risk classification commitments are not operationally implemented.
    File a complaint →

Provision details

Document information
Document
OpenAI Frontier Governance Framework
Entity
OpenAI
Document last updated
July 4, 2026
Tracking information
First tracked
July 4, 2026
Last verified
July 4, 2026
Record ID
CA-P-013248
Document ID
CA-D-00902
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
9a9787547aba77d52e34382b19a35003d8270b7548a085fe542ceb7258ee509d
Analysis generated
July 4, 2026 23:20 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: OpenAI
Document: OpenAI Frontier Governance Framework
Record ID: CA-P-013248
Captured: 2026-07-04 23:20:52 UTC
SHA-256: 9a9787547aba77d5…
URL: https://conductatlas.com/platform/openai/openai-frontier-governance-framework/tiered-model-risk-classification-system/
Accessed: July 5, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Get Compliance

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does OpenAI's Tiered Model Risk Classification System clause do?

This provision establishes a pre-deployment gate that determines which model capabilities are made available to API operators and end users; a critical classification in any of the four assessed domains would result in that model being withheld from deployment under the stated policy.

How does this clause affect you?

Under this provision, the capabilities of any OpenAI frontier model made available to users are subject to a pre-deployment risk assessment that may result in model features or entire models being withheld if classified as critical risk in cybersecurity, CBRN, persuasion, or autonomous replication domains.

Is ConductAtlas affiliated with OpenAI?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by OpenAI.