Watchtower
Watchtower tracks when AI companies change their safety policies — and when they break them.
Meta updates and renames its safety framework from the "Advanced AI Scaling Framework" (v2) to the "Meta Superintelligence Scaling Framework" (v2.1).
Meta
Oct 2, 2026
On Oct. 2, 2026, Meta updated its safety framework, renaming the “Advanced AI Scaling Framework (Version 2)” (AAISF) to the “Meta Superintelligence Scaling Framework (Version 2.1)” (MSSF). The MSSF makes several additions to Meta’s safety framework as well as some other quiet changes not noted in either its preface or change log. The summary below highlights some key changes.
(1) Additions: new governance language, open-weight discussion, and Loss of Control category
The MSSF states that Meta is working on more board-level governance, in particular related to Meta’s policies.1 It also expands the discussion of open-weight models and their benefits as well as their misuse risks.2 Most significantly, the MSSF adds a new catastrophic outcome category, Loss of Control 3, which covers containment failures during training or evaluation, with a threat scenario outlined in which a model covertly operates outside its authorized environment.3 Meta outlines a new “prospective assessment” designed to assess this risk before training, based on predicting capabilities relevant to cyberattacks and interference with monitoring from existing evaluation data.4 New safeguards are referenced, including sandbox standards, red-teaming, vulnerability remediation, logging of all rollouts, and required monitoring for high-risk training and evaluation runs.5 Exceptions to the monitoring requirement require approval from the Chief AI Officer or the Director of Alignment and Risk.6
(2) Prior commitments to test maximum capabilities deleted
The MSSF drops Meta’s commitment to “conduct risk assessments and assign risk thresholds with maximum elicitation in mind, capturing the upper bound of risk by evaluating the model as part of a system with scaffolding and tooling available for the proposed deployment scenario.”7 Related language about various prior commitments was also deleted, including that testing “may include fine-tuning our models… to be helpful-only (i.e., refusal-free), and conducting evaluations on models without mitigations”; that “[i]f we are considering releasing a model’s weights, or if we might release it with a fine-tuning API, then we will engage in domain-specific capability training to attempt to upper bound the capabilities of the model”; and that “[w]e will review agent transcripts to check for indications of spurious or easily-fixable agent failures.”8
(3) Specific cyber thresholds and provisional deployment-hold removed
The MSSF replaces the specific numeric standard of a 75% pass@10 success rate on “simple” cyber challenges with the undefined standard of “sufficiently high performance.”9 It also deletes the requirement to provisionally classify a model crossing that threshold as “high risk” and hold its deployment until complex testing is complete.10 Additionally, for Cyber 1, the example criterion for high-risk classification changes from completing “at least one” realistic multi-host network challenge to the less specific threshold of “sufficiently many.”11
(4) Softened mitigation language
The MSSF deletes the statement that mitigations “should be sufficiently robust against adversarial attacks that are realistic given the deployment strategy and threat scenario.”12 In the chemical and biological risk section, the commitment to “ensure consistent refusal against state-of-the-art adversarial attacks that have been discovered” becomes a commitment to continue researching mitigations against adversarial attacks and to “evaluate our fully mitigated model under such attacks.”13 The requirement for evidence of reliable refusal is also narrowed to areas where refusal is part of Meta’s mitigation strategy.14
The above is not an exhaustive list, as the framework was extensively updated.
A diff of the changes can be found below:
- MSSF, PDF p. 2. Please note: the MSSF does not have page numbers so we will refer to the PDF page numbers in lieu of the document page numbers.
- MSSF, PDF p. 2; see also p. 5
- MSSF, PDF p. 2; see also p. 19, 28-30.
- MSSF, PDF p. 28-30.
- MSSF, PDF p. 29-30.
- MSSF, PDF p. 30.
- AAISF, p. 8.
- AAISF, p. 27.
- Compare AAISF p. 28-29 with MSSF PDF p. 22.
- Compare AAISF p. 29 with MSSF PDF p. 22.
- Compare AAISF p. 29 with MSSF PDF p. 22.
- AAISF p. 26.
- Compare AAISF p. 33 with MSSF PDF p. 25.
- Compare AAISF p. 33 with MSSF PDF p. 25.
Anthropic
Sep 22, 2026
Anthropic’s release of Opus 5.5 with an “inconclusive” determination for harmful-manipulation.
xAI
Sep 21, 2026
xAI says Grok 4.7 scores below its safety framework’s capability thresholds on dual-use knowledge, but xAI’s safety framework doesn’t provide thresholds.
OpenAI
Sep 9, 2026
Updated the GPT-6 Astra system card, specifically to hedge claims about misalignment.
OpenAI
Aug 18, 2026
OpenAI updated its Model Spec, the document outlining intended model behavior
xAI
Aug 17, 2026
xAI updated Grok 4.6's model card after release. A changelog was included.
Aug 14, 2026
Google updated its Gemini 3.7 Flash model card after publication, making changes to language in the “Key Results for Gemini 3.7 Flash” column in the Frontier Safety Assessment section
Frequently asked questions
Have more questions? Our team is happy to help, contact us.
We engage in a combination of research, outreach, and public advocacy to ensure that AI companies are meeting public expectations and living up to their past promises, in order to ensure responsible AI development and deployment.
We review technical literature, regulatory guidance, and case studies to distill concrete measures that will meaningfully improve public safety — such as frontier-model risk assessments, red-teaming requirements, and whistle-blower protections — and advocate for the most important voluntary steps that companies can take today to ensure they are acting responsibly.
We also monitor whether companies follow their stated policies and industry norms. When we find evidence of back-tracking or inadequate risk controls, we document it and call for corrective action — mobilizing employees, customers, and civil-society allies until the company adopts the necessary safeguards.
Finally, we publicize our research to inform the public of how AI companies stack up on safety and responsibility. We release our work in the form of scorecards, independent reports, open letters, and long-form writing so that regulators, investors, and the wider public can see how individual developers perform on safety and responsibility.
Various AI experts including Nick Bostrom and Stuart Russell have compared the development of advanced AI to the myth of King Midas.
According to legend, King Midas was once granted one wish by the god Dionysus: that everything he touched would turn to gold. At first, he was thrilled with his new powers. But the King soon discovered that he couldn’t touch food, water, or even his family without instantly turning them to metal. In other words, he got exactly what he wanted in pursuit of immense wealth — and it turned out it wasn’t what he wanted at all.
Much like King Midas, AI companies are now eagerly pursuing incredible wealth and power by developing increasingly powerful AI systems. But ensuring that these systems act in alignment with our values is still an unsolved technical problem. If we misspecify even a single goal for these systems, how will we prevent them from causing an incredible catastrophe – if they follow our instructions at all?
In the words of Stuart Russell, “If you continue on the current path, the better AI gets, the worse things get for us. For any given incorrectly stated objective, the better a system achieves that objective, the worse it is.” The Midas Project exists to ensure that AI companies do not take this extraordinary gamble without public accountability and oversight.
The Midas Project is a nonprofit organization founded in early 2024 by Tyler Johnston. Our work is supported by a small core team and a wider base of volunteers and supporters. We are a nonprofit, tax-exempt, 501(c)(3) organization that relies on donations from the public.
No. One of our central values is being pro-technology.
Progress in technology has improved lives for millions of people around the globe (after all, without it, we wouldn’t have penicillin, air conditioning, or the internet). Artificial intelligence is already being used to help improve medicine, education, and overall living standards. We believe this progress should continue, and we hope AI will be a positive force in the world.
But we may not be on track to realize this future. Without technical breakthroughs, we risk developing powerful AI systems that act against user intent, or can be misused by bad actors to cause tremendous harm. Powerful AI could also concentrate unprecedented power among a handful of AI companies and exacerbate social inequality. To avoid these downsides, AI must be developed with caution, transparency, and public oversight. That’s why The Midas Project is committed to raising awareness about the risks of AI and ensuring that everyone is given a chance to make their voice heard.
If you’d like to get involved, consider signing up for our newsletter, joining as an official volunteer, or making a charitable donation today.
You can email us at info@themidasproject.com, or reach out via the form on our contact page.