
Preparedness Framework
The Preparedness Framework is a set of rules established by the company OpenAI that determines how dangerous new AI systems are allowed to become before they are released. It divides possible harms into risk levels and links each level to protective measures.
The Preparedness Framework is a self-imposed set of rules from the company OpenAI, which develops the chatbot ChatGPT. Translated, the name means roughly “framework for preparedness.” It answers a single question: How dangerous is a new computer program allowed to be—one that writes texts, generates code, or answers questions—before the company releases it to the public? To this end, OpenAI tests every major new program beforehand for certain capabilities that could cause great harm in the wrong context. For each capability there are thresholds. If a threshold is exceeded, the company must, according to its own rules, build in protective measures or stop the release. Competitors have set up similar frameworks as well, including Anthropic and Google DeepMind.
Self-commitment instead of law
Technology is developing faster than legislation. When the first large language models appeared, there were hardly any regulations for them. Companies filled this gap with their own rules, partly to show politicians and the public that they take risks seriously. The Preparedness Framework is the best-known example of this. It was first published at the end of 2023 and revised in 2025.
The difference from a law is important. A law can be enforced by a court, but a self-imposed promise cannot. OpenAI can change its own rules or define exceptions. The revised version even states that the company could adjust its requirements if a competitor releases a comparably risky system without protective measures. Critics see this as a loophole.
Nevertheless, the framework has an effect. It forces the company to document tests before every release, and it provides journalists and regulators with a benchmark. If a company breaks its own commitments, this can be demonstrated. New regulations such as the EU’s legal framework for AI also draw on ideas from such frameworks.
Risk categories and thresholds
At the core of the framework are a few risk areas. These include assistance in building biological or chemical weapons, attacks on computer systems—that is, cyberattacks—and a model’s ability to improve itself. In earlier versions, persuasiveness was also included, for instance regarding mass disinformation. These areas are deliberately narrow: the focus is on harms that affect very large numbers of people and cannot be undone.
For each area there are levels. Put simply: if a model reaches the “high” level, it may only be released with protective measures. If it reaches the “critical” level, according to the rules it may not be developed further at all as long as protective measures are missing. The classification is decided by tests in which experts deliberately try to provoke the model into giving dangerous answers. This procedure is called red teaming, borrowed from military exercises involving an attacking “red” team.
A comparison helps: think of it like a vehicle safety inspection, but with one crucial difference. In a vehicle inspection, an independent body checks against criteria set by the state. With the Preparedness Framework, the manufacturer largely tests itself and also sets the criteria itself. External reviewers are consulted, but they do not have the final say.
What makes it into the news
When OpenAI introduces a new model, an accompanying document usually appears alongside it, the so-called system card. It states how the model was classified in the risk areas. It is precisely these classifications that get quoted in news reports, for instance when a model is rated “high” in the biology domain for the first time. Such statements are the practical expression of the framework.
For investors and industry observers, the framework is also an economic issue. Stricter thresholds can delay product launches and cost money. Relaxations, on the other hand, regularly lead to disputes, including internally: several safety researchers have left OpenAI, citing that safety was being sacrificed for speed.
A common misconception: the Preparedness Framework does not deal with everyday issues like incorrect answers, biases in training data, or copyright. Other guidelines exist for that. Here, the focus is exclusively on rare but very large harms. Anyone who encounters the term in a news report should therefore understand it as a warning system for extreme cases, not as a general seal of quality.