Global AI Assurance · Model assurance
Frontier Model Assurance
Frontier developers run serious assurance of their own: capability evaluations, threshold declarations, safeguard reporting, external expert input and, increasingly, third-party evaluation. Those mechanisms are necessary. They are also provider-side.
An institution needs a second record, held independently, that describes the artefact it is about to depend on and states plainly how much of that description is verifiable by someone other than the provider.
Published as reference architecture. Control weights, grading rubrics and the full control set are set per engagement.
The question this record answers
Safety is a property of a deployment, not of an artefact. What can be assessed about the artefact alone is the strength of the evidence behind it.
Not the question
Is this model safe?
The question
How much independently verifiable assurance exists about this model's capabilities, safeguards, security, governance and residual risk?
Safety is a property of a deployment, not of an artefact. What can be assessed about the artefact alone is how much of its behaviour is evidenced by something an outsider can inspect.
Substantiated
Independent evidence exists across capability, safeguards, security and governance, and it is current.
Partially substantiated
Provider evidence is documented; independent coverage is uneven or dated.
Provider-attested
The record rests on the provider's own statements, versioned but unverified.
Insufficient
Material domains have no inspectable evidence at all; deployment conditions must carry the risk.
Five profiles make the record
Every field exists because a supervisor, an auditor, a board or an incident review asks for it.
Identity and provenance
Establishes exactly which artefact is being assured, because the answer changes on every version.
Capability profile
What the system can do, assessed against the fifteen domains rather than a benchmark table.
Safety profile
What safeguards exist, what has been tested, and what remains unresolved.
Security profile
How the model itself can be attacked, taken or turned, before any institutional deployment.
Governance profile
Whether the provider's own assurance process is documented, versioned and inspectable.
Fifteen capability domains
Assessed independently of what a vendor calls a release, because the institutional consequence follows the capability, not the branding.
Reasoning
Determines whether the system can construct multi-step plans that were never specified by the operator.
Coding
Code generation reaches production systems through tools and pipelines, not just through a person reading output.
Cybersecurity
Capability to find, chain and exploit weaknesses changes the institution's threat model whether or not it is used offensively.
Biology
High-consequence uplift domain with published provider thresholds; relevant to research, health and government estates.
Chemistry
Same uplift logic as biology, with different control owners and different national reporting duties.
Persuasion
Affects conduct, consumer fairness and information integrity where the system speaks to customers or the public.
Deception
A system that can misreport its own reasoning breaks the evidence chain the institution relies on.
Tool use
The point at which a model stops producing text and starts producing actions in other systems.
Long-horizon planning
Actions taken across many steps outrun single-prompt review and require runtime intervention instead.
Agentic execution
Determines whether the system can complete work without a human in each step.
Self-improvement
Capability to improve its own performance or successors; a threshold domain for provider safeguards.
Replication and adaptation
Persistence and self-copying change containment requirements and incident response.
Data exfiltration
Combined with credentials and tools this becomes a data-protection and supervisory reporting event.
Financial action
Payment, trading and settlement authority carries prudential consequence and a named accountable person.
Decision autonomy
How far the system may decide rather than recommend, which is what the board is actually approving.
What this is not
Cabier does not rank providers, does not publish a per-model score, and does not certify any model. A record describes a defined artefact assessed against a defined assurance profile, in a defined deployment context, on a stated date.
A capability read only becomes useful when it resolves onto assets, obligations and controls.
Compile capability into institutional risk