Preparedness Framework (OpenAI)
OpenAI’s internal risk-classification framework for frontier models: it grades a model’s dangerous capabilities in tracked categories — Cybersecurity, Biological & Chemical, and AI Self-Improvement — onto tiers, with “High” and “Critical” as the decision thresholds that gate how (or whether) a model ships. First seen in this wiki via the GPT-5.6 system card, which rates GPT-5.6 High in cyber and bio/chem, Below High in self-improvement, and none Critical.
What kind of governance instrument it is
A frontier-lab self-governance scheme — distinct from the public standards this wiki also tracks:
- Unlike NIST AI RMF (voluntary government guidance) or ISO/IEC 42001 (a certifiable management-systems standard), the Preparedness Framework is authored, applied, and graded by the developer itself, on thresholds it defines.
- Its output is operational: a tier (High/Critical) drives a deployment decision — staged preview, trusted-defender access, or hold — rather than a compliance attestation. In the GPT-5.6 case the High ratings are the stated basis for a limited preview and the request for government coordination before broad release.
Why it matters
It is the provider-side companion to the state-side release controls this wiki tracks: where EO 14409 imposes a 30-day pre-release government review from outside, the Preparedness Framework is the lab’s internal capability gate that decides what to escalate. The two meet at the same event — a staged GPT-5.6 release — from opposite directions. Its governance tension: a self-defined, self-graded threshold with no independent auditor is exactly the assurance gap that public standards (iso-iec-42001) and certification (nemko-digital) exist to close.
Related
gpt56-system-card · openai-gpt56-access-restriction · eo-14409 · nist-ai-rmf · iso-iec-42001 · risk-based-regulation · ai-governance · synthesis