IRBAI · Regulatory Framework

How We Regulate AI Models

Regulatory risk does not follow from a model’s headline capability. It arises at the intersection of a model’s form — what it is — and its behaviour — what it does — and is further modified by scale, access, and domain of use. IRBAI assesses each such intersection and certifies those that carry risk, rather than regulating by model name or aggregate capability.

01 · RISK AT INTERSECTIONS

A given model form may present low risk in one behaviour and significant risk in another. Assessment is conducted at the level of the individual intersection, not the broad category.

02 · CAPABILITY ≠ RISK

A narrow system of high capability may present limited risk; a less capable but general and autonomous system may present greater risk. Risk is assessed as a function of generality, autonomy, and access.

03 · LAYERED CERTIFICATION

A deployed model may require multiple certificates, one for each risk intersection it occupies. Certification is applied in layers corresponding to the structure of the system.

Risk: Minimal Low Elevated High Severe
SELECT A CELL

Foundation-model risk by form × behaviour

Click any highlighted cell to see why it carries risk and which IRBAI certificate applies.

Capability alone is an insufficient basis for regulation. A system that performs a single task at superhuman level is narrow; its societal risk is limited, and it is treated as a bounded-domain system. A general system capable of autonomous action across open-ended tasks warrants greater scrutiny, including at lower measured capability. Frameworks that regulate on capability or compute thresholds alone do not capture this distinction; IRBAI regulates on a system’s position within the matrix.
Overlay attributes — these modify the risk of every cell
Scale
narrow → frontier / systemic (capability & compute thresholds)
Access
closed API → open-weight → on-device (reversibility of release)
Domain
general → regulated vertical (bio, health, finance, elections, defence)
Layer
base model → deployed system → application (who holds the certificate)
From model to application — we regulate the whole stack

The matrix addresses the model: its form and its capabilities. Regulatory risk is realised at deployment — when a model is made available through an API, integrated into a product, or applied to a regulated decision. IRBAI certifies each layer of the stack and assigns accountability to the layer that exercises the relevant control.

Layer 01 · The Model
Foundation & general-purpose models
The underlying capability, certified on form, behaviour, and systemic risk, as set out in the matrix above.
AIFM-LANG · -VIS · -AUDIO · -VIDEO · -MULTI · -CODE · -FRONTIER · -AGENT · -BIO · -EMBODIED  —  licensed under AIFM-L
Layer 02 · The Platform
Platforms, APIs & open-weight release
The means by which a model is made available to third parties. The provider controls access, sets enforceable conditions of use, screens and monitors clients, and remains responsible for reasonably foreseeable misuse that this access enables.
AIFM-API · AIFM-OPEN · AIFM-COMPUTE · AIFM-EDGE
Layer 03 · The Application
Deployed systems in a real-world domain
The deployed system, at which effects are realised — for example an employment-screening tool, a clinical triage assistant, an automated trading system, or a public-facing government service. Certified on its impact in context, by sector.
Industry certificates — Health · Finance · Government · Biometric · Legal · Education · and every sector in the register
Open-weight & open-source models

Open-weight release is assessed prior to publication

The public release of model weights is irreversible. A released model cannot be recalled, updated, or withdrawn, and the corrective measures available for hosted models do not apply once weights are distributed. IRBAI does not restrict open release on that basis; open availability supports transparency, independent evaluation, and market competition. Certification requirements are instead applied before publication. Under AIFM-OPEN, an open-weight release is assessed on the marginal risk it introduces — the extent to which distributing the specific weights materially increases access to serious-harm capabilities, including chemical, biological, radiological and nuclear (CBRN) or offensive-cyber capabilities, relative to models and information already publicly available.

1
Marginal-risk assessment
Evaluation of capability uplift relative to the existing public frontier.
2
Staged and conditioned release
Lower-risk models are released without restriction; elevated-risk capabilities are subject to staged release, access conditions, or licence terms.
3
Release withheld
Capabilities assessed to exceed the serious-harm threshold are not authorised for open-weight release.

Certification is determined by a model’s position in the risk matrix. It does not depend on whether the model is open or closed, or on its jurisdiction of origin. Provenance and security requirements apply separately and do not substitute for capability assessment.

Responsibility is allocated across the value chain

Responsibility for compliance is not transferred in full to the deploying party. Obligations attach to the entity that holds the relevant control. A developer can implement corrections at the source of a general-purpose model, effective across all downstream uses; obligations concerning dangerous capabilities and reasonably foreseeable misuse therefore rest primarily with the developer. A deployer, able to constrain a model only at the point of use, is responsible for the specific context of deployment. Providers accordingly retain a share of responsibility for the conduct of their downstream and API clients, and a deployed system will commonly require certification at more than one layer.

Model developer
Dangerous capabilities, reasonably foreseeable misuse, and correction at source.
Platform / API operator
Conditions of access, and the monitoring and enforcement of use.
Deployer
The decisions, data, and individuals affected by the deployed system.
Note. Example systems are shown to illustrate each category only, and span the US, China (CN) and Europe (EU) — region tags mark where a system originates. They are not assessments, ratings, endorsements, or regulatory determinations about any specific product or company, and the field moves quickly. IRBAI certification attaches to a system's position in this matrix, assessed on application. Cert codes shown are part of the IRBAI Foundation-Model licensing scheme.