Subscribe to the Non-Human & AI Identity Journal

Preparedness Framework

OpenAI’s risk classification structure for model capability and safety thresholds. In this context, it helps distinguish between models that assist cybersecurity work and models that could meaningfully scale offensive or defensive operations without enough human oversight.

Expanded Definition

OpenAI’s Preparedness Framework is a risk classification and evaluation structure used to decide when a model’s capabilities cross into higher concern territory. It focuses on whether a model remains safely assistive or begins to meaningfully increase the scale, speed, or reliability of harmful activity, especially where human oversight may not be enough to contain misuse. That makes it different from general model safety advice, because it is tied to capability thresholds and deployment decisions rather than abstract principles.

Definitions vary across vendors and research groups, but the core idea is consistent: organisations need a repeatable way to assess when model behaviour creates materially different security exposure. In practice, this is closely related to broader governance work described in the NIST Cybersecurity Framework 2.0, especially where risk identification and response planning must keep pace with changing system capability. The most common misapplication is treating Preparedness Framework scores as a one-time approval gate, which occurs when teams ignore model updates, new tools, or changed access patterns after initial review.

Examples and Use Cases

Implementing Preparedness Framework rigorously often introduces review overhead and slower release cycles, requiring organisations to weigh faster deployment against stronger safeguards and clearer escalation paths.

  • A security team evaluates whether a new model can materially improve phishing or social engineering output and then limits access until additional controls are in place.
  • An AI platform owner uses threshold-based reviews to decide whether a model should be allowed to generate code, automate actions, or only assist with drafting.
  • A governance group ties model evaluations to internal risk acceptance so that higher-capability systems require executive sign-off before broader use.
  • A red team assesses whether model outputs could help an attacker scale reconnaissance, exploit development, or credential abuse, then feeds findings into control decisions.
  • An enterprise aligns preparedness checks with broader risk management workflows from the NIST Cybersecurity Framework 2.0 so that capability changes trigger reassessment, not just documentation updates.

For agentic or tool-using systems, the term becomes more operationally important because a model with execution authority can move from content generation into action. In that environment, preparedness is not only about prompt quality or model accuracy, but also about what the system can reach, change, or exfiltrate through connected tools and secrets.

Why It Matters for Security Teams

Security teams need this framework because model capability growth can outpace traditional governance, especially when the same system is reused across development, support, analytics, and agentic workflows. If the preparedness level is misunderstood, teams may grant access too early, assume a model is safe because it passed one assessment, or fail to detect that a new connector changes the threat profile entirely. That is where AI governance meets identity and access control: once a model or agent can act on behalf of users, service accounts, or other NHIs, its permissions become part of the risk decision.

The concept also helps security leaders communicate when stronger oversight, usage limits, or human review are mandatory rather than optional. It complements risk frameworks like the NIST Cybersecurity Framework 2.0 by giving teams a way to classify AI systems before they become operational liabilities. Organisations typically encounter the real impact only after a model is connected to sensitive tools or misused at scale, at which point the Preparedness Framework becomes operationally unavoidable to address.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 address the attack surface, NIST AI RMF, NIST AI 600-1 and NIST CSF 2.0 set the technical controls, and EU AI Act define the regulatory obligations.

Framework Control / Reference Relevance
NIST AI RMF AI RMF frames governance, mapping, measurement, and management for model risk decisions.
NIST AI 600-1 The GenAI Profile helps translate AI governance into concrete risk controls for models.
NIST CSF 2.0 GV.RM-01 CSF 2.0 defines risk management governance that aligns with preparedness-style reviews.
OWASP Agentic AI Top 10 Agentic AI guidance addresses tool use, autonomy, and escalation risk in model deployments.
EU AI Act The EU AI Act requires risk-based controls for high-risk AI systems and oversight duties.

Embed model readiness checks into enterprise risk governance and reassess after capability changes.