Meta publishes its Frontier AI Framework
Meta defined thresholds for 'high-risk' and 'critical-risk' systems in cyber and biological-weapons scenarios, and said it would halt development of any model it could not mitigate to below critical risk.
- Ideas & essays
- Government & policy
- Open weights & ecosystem
- Notable
Meta published its Frontier AI Framework, a document describing how it decides whether to release a model openly, restrict access to it, or halt its development entirely. Meta framed the framework as fulfilling a commitment made at the 2024 Seoul AI Safety Summit, and focused it on two categories of catastrophic outcome: large-scale cyberattacks and the proliferation of chemical or biological weapons.
The framework defines two thresholds. A model is “high risk” if it could provide meaningful uplift toward carrying out one of the specified threat scenarios without being able to complete it outright; it is “critical risk” if it could uniquely enable that scenario. For a model assessed as critical risk that Meta cannot mitigate, the framework commits the company to halting development, restricting access to a small group of experts, and applying security protections against theft or leak “insofar as is technically feasible and commercially practicable.” The assessment relies on internal and external threat-modelling exercises rather than a fixed, quantitative test.
The document was notable chiefly for what it implied about Meta’s prior position. Meta had built its AI strategy around releasing Llama model weights openly by default, arguing that open access served both innovation and safety scrutiny; publishing conditions under which it would not release a model — and might stop building one — was the company’s first formal acknowledgement that unconditional open release was not a permanent commitment. Critics of open-weight release, who had argued Meta’s approach ignored the risk that a released model’s safety features could simply be removed after the fact, took the framework as a partial concession; supporters of open release argued the thresholds were vague enough to leave Meta’s practical behaviour largely unconstrained.