Google DeepMind Frontier Safety Framework (v1 2024 -> v2 Feb 2025 -> v3 Sept 2025 -> v3.1 Apr 2026)

Google DeepMind · 2024-05-17 (v1); 2025-09-22 (v3); 2026-04-17 (v3.1)

Company policyImplemented

Google DeepMind's protocol for spotting when a model crosses dangerous capability thresholds. It has been updated repeatedly and model reports are published, but it sits alongside Google's 2025 decision to drop its no-weapons pledge.

What it calls for

  • Safety evaluations
  • Alignment research
  • Transparency

Scope

Single company; Critical Capability Levels for CBRN, cyber, ML R&D, harmful manipulation, misalignment

What actually happened

v3 added a 'harmful manipulation' CCL and shutdown-resistance protocols; v3.1 added Tracked Capability Levels (https://deepmind.google/blog/strengthening-our-frontier-safety-framework/). DeepMind published FSF reports per model, e.g. Gemini 3 Pro (Nov 2025, https://deepmind.google/models/fsf-reports/gemini-3-pro/). Context: Google deleted its 2018 pledge not to build weapons or surveillance AI in Feb 2025 (https://www.vice.com/en/article/google-abandoned-core-parts-ai-pledge-weapons/) and 580+ employees protested a classified Pentagon Gemini deal in April 2026 (https://thenextweb.com/news/google-employees-classified-military-ai-pentagon).