---
title: "What Is a Frontier Model? Definition and Safety Obligations"
date: 2026-09-06
author: "Barry Elad"
featured_image: "https://sqmagazine.co.uk/wp-content/uploads/2026/07/what-is-a-frontier-model.jpg"
---

# What Is a Frontier Model? Definition and Safety Obligations

A frontier model is a highly capable general-purpose AI model that can perform a wide variety of tasks and match or exceed the capabilities present in today’s most advanced models, per the definition the Department for Science, Innovation and Technology set for the purposes of the Summit.

California’s Transparency in Frontier Artificial Intelligence Act gives the same phrase a statutory meaning, defining a frontier model as a foundation model trained using computing power greater than 10^26 integer or floating-point operations. Frontier AI is the sense used below, not the unrelated economics usage in frontier markets or frontier firms.

## Key Takeaways

- For the purposes of the Summit, the Department for Science, Innovation and Technology defines frontier AI as highly capable general-purpose AI models that can perform a wide variety of tasks and match or exceed the capabilities present in today’s most advanced models. That wording sets a relative boundary, so the category shifts whenever a stronger model ships.
- California’s Transparency in Frontier Artificial Intelligence Act defines a frontier model as a foundation model trained using a quantity of computing power greater than 10^26 integer or floating-point operations.
- The EU AI Act presumes a general-purpose AI model to have high-impact capabilities when the cumulative amount of computation used for its training, measured in floating-point operations, is greater than 10^25, and a model meeting that condition is classified as a general-purpose AI model with systemic risk.
- Providers of general-purpose AI models with systemic risk must perform model evaluation in accordance with standardised protocols, including conducting and documenting adversarial testing, and must report serious incidents to the AI Office without undue delay. The provider notifies the Commission without delay and in any event within two weeks after that requirement is met, or after it becomes known that it will be met.
- **20** organisations, among them Amazon, Anthropic, Google, Microsoft, OpenAI and NVIDIA, have agreed to the Frontier AI Safety Commitments. In the extreme, those organisations commit not to develop or deploy a model or system at all if mitigations cannot be applied to keep risks below the thresholds.

## How Is a Model Classified as a Frontier Model?

Three regimes run three different tests. Only one of them writes a number into the definition itself. The order below starts with the statutory route, because California’s text is the only one here that defines the exact phrase in binding law.

### 1. Start From the Foundation Model Test

A foundation model, under California’s Transparency in Frontier Artificial Intelligence Act, is an artificial intelligence model that is trained on a broad data set, designed for generality of output, and adaptable to a wide range of distinctive tasks. A frontier model is a foundation model that was trained using a quantity of computing power greater than 10^26 integer or floating-point operations.

A frontier model is therefore a subset of foundation models rather than a separate species. Senate Bill 53 carries the operative text.

### 2. Measure the Training Compute

The quantity of computing power described in that definition includes computing for the original training run, and for any subsequent fine-tuning, reinforcement learning, or other material modifications the developer applies to a preceding foundation model.

That inclusion clause carries more practical weight than the headline figure. A developer who keeps tuning a model keeps accumulating compute toward the same ceiling. Runs of that size are a hardware question before they become a legal one, and [AI training chip data](https://sqmagazine.co.uk/ai-chip-statistics/) covers the accelerators behind them.

### 3. Check the Capability Test Your Regulator Uses

Under the EU AI Act, a general-purpose AI model is classified as carrying systemic risk if it has high impact capabilities evaluated on the basis of appropriate technical tools and methodologies, including indicators and benchmarks. Such a model shall be presumed to have high impact capabilities above the EU’s 10^25 floating point operation compute figure, and the Commission shall adopt delegated acts in accordance with Article 97 to amend the thresholds in light of evolving technological developments.

The UK approach names no compute figure at all. It turns instead on whether a model can match or exceed the capabilities present in today’s most advanced models.

Two metaphors make the split concrete. One country writes a speed limit as a number. The next posts a sign telling drivers to keep up with the fastest cars on the road. Both govern speed, and only one of them tells a driver what to do without looking around.

A building code offers the closer parallel. One city classifies a structure by storey count and the next classifies it by occupancy risk, so the same building gets two different files under two inspection regimes.

The table below shows how each regime decides.

| Regime | Term used in the text | What triggers it | Who assesses |
|---|---|---|---|
| UK DSIT discussion paper | Frontier AI | Capabilities that match or exceed today’s most advanced models | Not assigned in the paper |
| California TFAIA | Frontier model | Foundation model trained above 10^26 integer or floating-point operations | The developer, enforced afterwards by the Attorney General |
| EU AI Act | General-purpose AI model with systemic risk | High impact capabilities, presumed above 10^25 floating-point operations | The Commission, with the scientific panel |

*Sources: Department for Science, Innovation and Technology; California Legislative Information; Official Journal of the European Union*

## Why Does the Frontier Model Label Matter?

The label does something rather than describe something. Flip it, and a developer inherits evaluation duties, a notification deadline, a published framework, and an enforcement ceiling.

Anderljung and co-authors define frontier AI models as highly capable foundation models that could possess dangerous capabilities sufficient to pose severe risks to public safety. That academic framing explains why anyone bothers with the category at all, and it is the real-world impact the label is reaching for.

Frontier AI models pose a distinct regulatory challenge, according to Anderljung and co-authors: dangerous capabilities can arise unexpectedly, it is difficult to robustly prevent a deployed model from being misused, and it is difficult to stop a model’s capabilities from proliferating broadly. Those three properties explain why governments wanted a bounded category at all, and why the boundary keeps being drawn in different places.

The three tests do not line up. The UK’s moves whenever the field moves, California’s is pinned to a number, and the EU AI Act never uses the phrase frontier model as a legal category. One system can therefore be a frontier model in Sacramento, a general-purpose AI model with systemic risk in Brussels, and merely one of several advanced models in London on the same day, with a different obligation set attached to each status.

Our AI benchmark coverage shows capability rankings reordering roughly twice a year while public perception lags well behind, and a relative definition inherits every bit of that churn. The same movement shows up in [AI model capability comparisons](https://sqmagazine.co.uk/ai-model-tracker/), where the ranking reshuffles faster than any statutory threshold could be amended.

## Frontier Model Safety Obligations by Jurisdiction

Providers of general-purpose AI models with systemic risk must perform model evaluation in accordance with standardised protocols and tools reflecting the state of the art, including conducting and documenting adversarial testing of the model with a view to identifying and mitigating systemic risks.

They must also assess and mitigate possible systemic risks at Union level. They must report serious incidents to the AI Office without undue delay, and ensure an adequate level of cybersecurity protection for the model and its physical infrastructure, if appropriate. Those duties carry a measurable price, tracked in [EU AI Act compliance cost data](https://sqmagazine.co.uk/eu-ai-act-compliance-cost-statistics/).

California attaches its duties to company size rather than to every developer that clears the compute line. A large frontier developer is a frontier developer that, together with its affiliates, collectively had annual gross revenues in excess of **$500,000,000** in the preceding calendar year. The statute also defines a frontier AI framework as documented technical and organizational protocols to manage, assess, and mitigate catastrophic risks.

A large frontier developer that fails to publish or transmit a compliant document, fails to report an incident, or fails to comply with its own frontier AI framework is subject to a civil penalty, dependent upon the severity of the violation, that does not exceed **$1,000,000** per violation. That penalty is recovered in a civil action brought only by the Attorney General.

Signatory organisations undertook to assess the risks posed by their frontier models or systems across the AI lifecycle, including before deploying that model or system, and to set out thresholds at which severe risks would be deemed intolerable. Those are undertakings, not statutes. Folding them into the same sentence as the EU and California duties would misstate both registers.

| Obligation | EU AI Act | California TFAIA | Seoul commitments |
|---|---|---|---|
| Pre-deployment evaluation | Model evaluation under standardised protocols | Not covered | Risk assessment across the lifecycle, including before deployment |
| Adversarial testing | Required and documented | Not covered | Not covered |
| Incident reporting | To the AI Office, without undue delay | Required, and enforceable by penalty | Not covered |
| Published framework | Not covered | Frontier AI framework required | Not covered |
| Penalty for failure | Not covered in Article 55 | Civil penalty that does not exceed $1,000,000 per violation | Not covered; the regime is voluntary |

*Sources: Official Journal of the European Union; California Legislative Information; Department for Science, Innovation and Technology*

## Pros, Cons, and Risks

### Advantages

- At least three building blocks for the regulation of frontier models are needed, per Anderljung and co-authors: standard-setting processes, registration and reporting requirements, and mechanisms to ensure compliance with safety standards.
- The AI Security Institute holds pre-deployment access to leading AI models and close collaborations with AI companies that give it privileged access to their development approaches.
- A bounded category gives a regulator something smaller than all AI to supervise, and it produces documentation an outsider can read.

### Trade-offs and Risks

- The Commission shall adopt delegated acts to amend the thresholds as well as to supplement benchmarks and indicators in light of evolving technological developments. A threshold written with an amendment power attached is a threshold its own drafters expect to move.
- The UK recast the AI Safety Institute as the AI Security Institute on **14 February 2025**, a name chosen to reflect a focus on serious AI risks with security implications. Vocabulary that changes at the institution defining it changes for everyone downstream.
- A compute figure measures the size of a training run, not what the resulting system can do, so two models on either side of the line can behave very similarly.

**Classification is not clearance:** Article 55 obliges providers to conduct adversarial testing with a view to identifying and mitigating systemic risks, and to ensure an adequate level of cybersecurity protection for the model and its physical infrastructure, if appropriate. Identifying and mitigating is the ceiling. The classification never makes a model safe, secure, certified, cleared or approved, and none of these instruments claims to prevent harm. The register that fits is narrower: evaluation helps identify risk, the rules require documentation of it, and they oblige reporting.



## Frontier Model vs Foundation Model vs Large Language Model

Frontier AI today primarily includes large language models such as those underlying [ChatGPT](https://sqmagazine.co.uk/chatgpt-statistics/), Claude, and Bard, though the Department for Science, Innovation and Technology records that frontier AI systems may not be underpinned by LLMs and could be underpinned by another technology.

That clause separates an architecture from a category. Large language model names how a system is built. Frontier model names where a system sits against a rule, or against the rest of the field. The architecture itself is a separate subject, covered in [how large language models work](https://sqmagazine.co.uk/what-are-large-language-models/).

Two of the four terms carry a numeric boundary in their own defining text. California puts a frontier model above computing power greater than 10^26 integer or floating-point operations. The EU presumes high-impact capabilities, the first of the conditions for classifying a general-purpose AI model as carrying systemic risk, when cumulative training computation sits above 10^25 floating-point operations.

The EU term belongs in the same table, because readers meet it in the same sentences and it is a synonym for none of the other three.

| Term | What it names | What defines the boundary | Is it a legal trigger |
|---|---|---|---|
| Foundation model | A model trained on a broad data set, designed for generality of output, adaptable to a wide range of distinctive tasks | Generality and adaptability, with no compute figure | Yes, in California statute, as the parent category |
| Frontier model | A foundation model above a compute line | Training compute greater than 10^26 integer or floating-point operations | Yes, in California statute |
| Large language model | An architecture, not a capability tier | How the system is built | No |
| General-purpose AI model with systemic risk | The EU category covering the same territory | High impact capabilities, presumed above 10^25 floating point operations | Yes, in the EU AI Act |

*Sources: California Legislative Information; Department for Science, Innovation and Technology; Official Journal of the European Union*

## Real-World Applications

Three concrete use cases show the label doing work, and each one names a specific institution or company rather than an imagined user.

### Pre-Deployment Testing by a Government Institute

The AI Security Institute is a research organisation within the UK government’s Department for Science, Innovation and Technology. Its work includes testing leading AI systems before they are released publicly, and collaborating with top AI companies to improve their safety and security. The institute is backed with **£66 million** in funding per financial year and advances research with over **£15 million** in grant funding.

A government body seeing a model before the public does is the clearest published example of the label doing work.

### A Government Renamed Its Own Institute

Peter Kyle recast the AI Safety Institute as the AI Security Institute on **14 February 2025**. He spoke at the Munich Security Conference, days after the conclusion of the AI Action Summit in Paris. The institute was bolstered by a new criminal misuse team partnering with the Home Office. It also partners with the Defence Science and Technology Laboratory to assess the risks posed by frontier AI.

The institution most associated with this vocabulary revised its own framing within two years. That is a useful signal about how settled the terminology is.

### Companies Setting Their Own Intolerable-Risk Thresholds

The Frontier AI Safety Commitments were announced with one signatory list and extended with another.

- **Announced signatories:** Amazon, Anthropic, Cohere, Google, G42, IBM, Inflection AI, Meta, Microsoft, Mistral AI, Naver, OpenAI, Samsung Electronics, Technology Innovation Institute, xAI and Zhipu.ai.
- **Added to the existing list:** Magic, Minimax, 01.ai and NVIDIA.

Those organisations committed to set out thresholds at which severe risks posed by a model or system, unless adequately mitigated, would be deemed intolerable, and to monitor how close a model or system is to such a breach.

Two of those signatories draw most of the public attention in this category, and their relative scale sits in [OpenAI and Anthropic compared](https://sqmagazine.co.uk/openai-vs-anthropic-statistics/).

## Which Models Count as Frontier Models?

Neither government publishes a roster, so the honest answer names the criterion rather than the models. California’s test is arithmetic: a foundation model trained using a quantity of computing power greater than 10^26 integer or floating-point operations qualifies, and the count includes subsequent fine-tuning and reinforcement learning. The UK test is comparative, measuring a model against today’s most advanced models.

Both tests get applied to a specific model at a specific moment, and the comparative test changes its answer without anybody amending anything.

## Who Decides Whether a Model Is a Frontier Model?

In the EU, the provider notifies the Commission without delay and in any event within two weeks after the requirement is met. Under a separate condition, a model is classified on a decision of the Commission taken ex officio or following a qualified alert from the scientific panel. In California, the developer’s own compute figure does the work, because a frontier developer is a person who has trained, or initiated the training of, a frontier model using at least as much computing power as the technical specification requires.

Enforcement arrives afterwards, through a civil action brought only by the Attorney General. Self-classification followed by state enforcement is a familiar disclosure-regime pattern. It puts the burden of an accurate compute figure on the developer.

## Conclusion

California fixes the boundary at a quantity of computing power greater than 10^26 integer or floating-point operations. The EU presumes high-impact capabilities above 10^25 floating-point operations for a category it calls a general-purpose AI model with systemic risk. Two numbers an order of magnitude apart, sitting under different names in different legal systems, describe roughly the same neighbourhood of technology.

The Commission may amend those thresholds by delegated act in light of evolving technological developments. Looking forward, that reserved power suggests the direction of travel runs toward capability-based tests, because a fixed compute number ages badly against efficiency gains. Whether the other regimes converge on the same approach is at present an open question, and anyone tracking the term should expect its boundary to keep moving.

Definition of AI Red Teaming. Link to full glossary entry follows the description.**AI Red Teaming**AI red teaming is a structured testing effort that uses adversarial methods to find flaws, vulnerabilities, and misuse risks in a deployed AI system.

[Read more](https://sqmagazine.co.uk/glossary/ai-red-teaming/)

Definition of Frontier Model. Link to full glossary entry follows the description.**Frontier Model**A frontier model is a highly capable general-purpose AI model that matches or exceeds today's most advanced systems, and triggers safety obligations.

[Read more](https://sqmagazine.co.uk/glossary/frontier-model/)