On 19 July 2026, at the World Artificial Intelligence Conference (WAIC) 2026, Concordia AI and Shanghai Artificial Intelligence Laboratory jointly released the Frontier AI Risk Management Framework 2.0 (the “Framework”). Written for general-purpose AI model developers, the Framework sets out a systematic approach to proactively identifying, assessing, mitigating, and governing severe risks that could threaten public safety and national security.
The Frontier AI Risk Management Framework was first published as Version 1.0 in July 2025 and updated to Version 1.5 in February 2026; Version 2.0 is the third public release. It draws on risk management standards and practices from safety-critical industries, and aligns with domestic and international standards including ISO 31000:2018, ISO/IEC 23894:2023, and GB/T 24353:2022. The Framework is organized into six stages (risk identification, risk thresholds, risk analysis, risk evaluation, risk mitigation, and risk governance) that span the full model lifecycle and form a closed risk management loop. Building on this process, it introduces a three-dimensional analytical lens: Deployment Environment, Threat Source, and Enabling Capability (E-T-C). Developers are asked to assess not only what a model can do, but where it operates and what could go wrong, and then to target mitigations accordingly through deployment controls, access restrictions, or the removal of hazardous capabilities.
On thresholds, the Framework uses “Red Lines” to mark intolerable harms and “Yellow Lines” to mark early warning signals that call for intervention before that point. Residual risk after mitigation is sorted by these two lines into three risk zones: below the Yellow Line is the Green Zone, where routine deployment is acceptable; between the Yellow and Red Lines is the Yellow Zone, where deployment is permitted only under controlled conditions; at or above the Red Line is the Red Zone, where deployment or development should be suspended. Each zone carries a different level of authorization, mitigation, and governance requirements.
Key updates since Version 1.0, covering both the 1.5 and 2.0 iterations, include:
– Expanded coverage of loss of control risks: The scenarios and thresholds for loss of control have been refined, and agent oversight measures and emergency response mechanisms strengthened. Version 2.0 further incorporates loss of oversight as a cross-cutting precondition shared by both passive and active loss of control, and identifies internal deployment with elevated privileges as a critical risk environment.
– Iterated Red Line risk scenarios: Version 2.0 adds a Red Line scenario for chemical safety and updates the scenarios for biological risks, cyber offense, large-scale persuasion and harmful manipulation, and loss of control. The Framework now covers five risk domains with 13 specific Red Lines, each defined along the three dimensions of deployment environment, threat source, and enabling capability, and each accompanied by a hypothetical scenario.
– Operationalized risk analysis: The risk analysis guidance for developers has been updated to clarify its essential components, including model evaluations, elicitation, and risk modeling and estimation.
– Enhanced interoperability: The Framework’s risk management measures are mapped, item by item, against the AI Safety Governance Framework 2.0 of the National Technical Committee 260 on Cybersecurity (TC260) and the Safety and Security Chapter of the EU Code of Practice for General-Purpose AI Models. This helps developers meet the safety expectations shared by major domestic and international regulatory guidance with a single set of measures.
Loss of oversight can originate on both the human and the system side. On the human side, reviewers may gradually stop scrutinizing models substantively, influenced by automation bias, the complexity of the systems, and competitive pressures. On the system side, a model may alter its behavior when it detects that it is being evaluated, its externalized reasoning traces may diverge from its actual objectives, and it may circumvent or corrupt logging and monitoring channels. The Framework recommends treating continuous monitoring for loss of oversight as a distinct objective of loss of control risk governance.
The Framework is also explicit about the status of these Red Lines. They rest principally on expert judgment in frontier safety and on an emerging international discussion, and do not yet reflect a settled consensus among domain experts or across the international community. They are therefore better understood as a precautionary commitment that developers can make ahead of consensus: voluntary constraints that cover the most severe risks before agreement and regulation are in place.
The Framework is intended to be a living document. The authors will review its content and usefulness regularly, and comments sent to them will be reviewed and integrated semi-annually. The publishers hope it offers frontier model developers, policymakers, and third-party research and evaluation bodies a risk management approach they can reference, compare against, and put into practice, and they welcome collaboration on how it is applied.
Read the full report: [Chinese full text] | [English full text]

