⚡ Quick Summary
The General-Purpose AI Risk-Management Standards Profile (Version 1.2), developed by UC Berkeley's Center for Long-Term Cybersecurity (CLTC), provides an actionable, cross-sector risk-management profile tailored to upstream developers of general-purpose AI (GPAI) and frontier foundation models, as well as downstream deployers. Built to complement the NIST AI Risk Management Framework (AI RMF 1.0) and ISO/IEC 23894, the Profile maps technical and procedural controls across the four core functions: Govern, Map, Measure, and Manage.
This updated version introduces dedicated guidance for third-party evaluations, post-deployment continuous monitoring, capability-based risk thresholds, and mitigations against emerging threat vectors such as strategic deception, sandbagging, autonomous replication, situational awareness, and CBRN weapons proliferation.
🧩 What's Covered
The Profile delivers granular implementation guidance and resources structured across the four NIST AI RMF core functions:
- Govern: Establishing organizational accountability through Three Lines of Defense (3LoD) structures; defining clear executive oversight (e.g., Chief Risk Officer and Board committees); instituting whistleblower protections; enforcing Software Bills of Materials (SBOMs), AI Bills of Materials (AIBOMs), and SLSA frameworks; and executing six-stage AI incident response plans (Preparation, Identification, Containment, Eradication, Recovery, Lessons Learned).
- Map: Identifying foreseeable uses, misuses, and systemic harm factors across societal, organizational, and fundamental rights domains. It details risk characterization for catastrophic threats, including cyberattacks, CBRN proliferation, labor market disruption, and sandbagging. It emphasizes setting dynamic, capability-based unacceptable-risk thresholds and margins of safety to guide go/no-go training and deployment gates.
- Measure: Advanced Test, Evaluation, Verification, and Validation (TEVV) approaches beyond static benchmarks. It details independent third-party red-teaming, propensity evaluations, dangerous capability elicitation, detectability of alignment faking, data contamination detection (e.g., zlib-perplexity ratios), privacy leak audits, and environmental footprint tracking via emissions calculators.
- Manage: Implementing defense-in-depth risk treatments, including incremental scale-up protocols (e.g., testing after every 2x–4x increase in effective compute), structured access, tiered API access, staged releases for open-weights models, tamper-resistant safeguards (TAR), emergency power-off ("kill switches") / safe interruptibility mechanisms, and active post-deployment monitoring.
💡 Why it matters?
GPAI models possess multi-purpose reach and unpredictable emergent capabilities, making traditional point-in-time and static machine learning risk assessments inadequate. By translating high-level frameworks like NIST AI RMF and ISO/IEC 23894 into concrete technical practices, this Profile bridges the gap between voluntary standards and regulatory compliance regimes such as the EU AI Act (Articles 53 and 55) and state-level laws like California's SB 53. It establishes verifiable operational controls that prevent catastrophic failures while supporting responsible innovation.
❓ What's Missing
The authors note several acknowledged scope boundaries and areas reserved for future versions: it excludes general IT infrastructure security (directing users to NIST CSF or ISO/IEC 27001) and does not provide sector-specific application controls for specialized industry verticals. Furthermore, the Profile highlights current scientific limits in inner interpretability, reliable extraction of persistent backdoors, and detecting strategic deception or evaluation tampering.
👥 Best For
Upstream foundation model developers, AI safety engineers, red-team practitioners, Chief Risk Officers, compliance teams implementing EU AI Act or NIST AI RMF controls, downstream system integrators, and independent AI auditors.
📄 Source Details
- Title: General-Purpose AI Risk-Management Standards Profile (Version 1.2)
- Authors: Nada Madkour, Jessica Newman, Deepika Raman, Krystal Jackson, Evan R. Murphy, Charlotte Yuan, and Dan Hendrycks
- Publisher / Organization: UC Berkeley Center for Long-Term Cybersecurity (CLTC) & AI Security Initiative
- Date Published: April 2026
- Associated Documents: Agentic AI Risk-Management Standards Profile; Mapping Key Standards and Regulations to the GPAI Profile V1.2; Evaluation of Frontier AI Company Practices; Transparency, Documentation, and Reporting Recommendations
📝 Thanks to
Appreciation to lead authors Nada Madkour, Jessica Newman, Deepika Raman, Krystal Jackson, Evan R. Murphy, Charlotte Yuan, and Dan Hendrycks, along with CLTC leadership (Ann Cleaveland), workshop organizers, and the broad multi-stakeholder community across academia, government, civil society, and industry who contributed expert feedback to Version 1.2.