RAND threat-model boundary: SL2 excludes insiders; SL3 includes cybercrime syndicates and insider threats
SL2 excludes insiders; SL3 includes insidersobserved
| Value kind | observed — Reported measurements, counts, and specifications keep the precision and scope stated by their source; an exact specification is not treated as a range. |
|---|---|
| Scope | SL2 excludes insiders; SL3 includes cybercrime syndicates and insider threats. Framework target definitions do not establish conformance. |
| As of | Publication 30 May 2024 |
| Source | RAND, Securing AI Model Weights, 30 May 2024; security-level threat definitions, not an assessment of achieved laboratory controls. |
| Review | checking…review by 2026-08-27 · standard cadence |
| Recorded changes | last 2026-09-16 · 3 revisions tracked |
| Claim id | where-consensus-assesses-frontier-labs-sit |
Where the guide uses it
← Full numbers register — every date-stamped figure in the guide, with revision history.