AIG-054 Safety and Security Model Report
Description
A safety and security model report exists for each general-purpose AI model designated as carrying systemic risk before it is placed on the market. The report describes the model and its behaviour, documents the systemic risk identification, analysis and mitigation carried out under the framework, the external evaluations and reports obtained, the reasons the systemic risk was found acceptable with the conditions under which that finding would stop holding, and how the model changes the systemic risk landscape. The report is updated when the framework's triggers fire and at the interval the applicable code of practice sets for the most capable models on the market, each update carries a changelog, the AI Office is given access by the time the model is placed on the market and within the period the code sets after each update, and a summarised version with the removals needed to protect mitigations and commercial information is published where the code requires it.
Rationale
The report is the artefact the AI Office reads; the framework (AIG-050) and the evaluations (AIG-051) are what it describes, so a report that restates them at length is worse than one that cites them and states the reasoning. The six-month refresh for the most capable models and the five-business-day access period are the Code's figures and belong in the evidence. Publication of a summary is required only where it is needed to assess or mitigate systemic risk, with the Code's exemption for models no more capable than one already on the market. The profile marks this control recommended rather than required because its only sources are Code measures and the Code is a voluntary route to demonstrating compliance (ADR-038, ADR-046 decision 4); a provider that does not adhere to the Code demonstrates Art.55 compliance another way and records how. Boundary with AIG-050 and AIG-051 as above. Boundary with AIG-047: the model documentation may be cited by the report and is not repeated in it. gpai-provider seat (ADR-031).
Applicability (9 profiles)
The safety and security model report is the gpai-provider seat (ADR-046) and is recommended rather than required even there.
A general-purpose model providers duty (gpai-model-provider, ADR-046). The deployer takes the model documentation and the published training summary the provider issues into its AIG-032 assessment.
The Safety and Security Model Report is a Code of Practice measure and the Code is a voluntary route to demonstrating Art.55 compliance (ADR-038, ADR-046 decision 4). Recommended for a provider of a model designated as carrying systemic risk; a provider that does not adhere to the Code records how it demonstrates Art.55 compliance instead.
The safety and security model report is the gpai-provider seat (ADR-046) and is recommended rather than required even there.
A general-purpose model providers duty (gpai-model-provider, ADR-046). The deployer takes the model documentation and the published training summary the provider issues into its AIG-032 assessment.
The safety and security model report is the gpai-provider seat (ADR-046) and is recommended rather than required even there.
The safety and security model report is the gpai-provider seat (ADR-046) and is recommended rather than required even there.
The safety and security model report is the gpai-provider seat (ADR-046) and is recommended rather than required even there.
The safety and security model report is the gpai-provider seat (ADR-046) and is recommended rather than required even there.
Framework Mappings (10)
| COP-S-10 | Additional documentation and transparency | partial |
| COP-S-10.2 | Public transparency | full |
| COP-S-7 | Safety and Security Model Reports | full |
| COP-S-7.1 | Model description and behaviour | full |
| COP-S-7.2 | Reasons for proceeding | full |
| COP-S-7.3 | Documentation of systemic risk identification, analysis, and mitigation | full |
| COP-S-7.4 | External reports | full |
| COP-S-7.5 | Material changes to the systemic risk landscape | full |
| COP-S-7.6 | Model Report updates | full |
| COP-S-7.7 | Model Report notifications | full |
Evidence (1)
The safety and security model report for a designated model at its current version, with its changelog and the record of access given to the AI Office.
Example: Aurora-2 Safety and Security Model Report v2.3, 11 August 2026, changelog at annex A, AI Office access confirmed 13 August 2026.
Test: Verify: (1) the report exists with a version dated before the model's placement date, (2) it describes the model and its behaviour, the identification, analysis and mitigation carried out, the external evaluations obtained, the reasons for proceeding with the reversal conditions and the change to the systemic risk landscape, each either stated or cited to the framework, the determination or the evaluation report, (3) each update in the period follows a framework trigger or falls within the interval the code sets, and carries a changelog entry, (4) the access record shows the AI Office given access by placement and within the period the code sets after each update, (5) where a public summary was required, it is published with the removals recorded and justified.
Questions (2)
Does a safety and security model report exist for each designated model before it is placed on the market?
The report is the document delivered to the AI Office. The framework and the evaluation reports it describes are AIG-050 and AIG-051 and do not stand in for it.
Which of the following does the report cover?
Options follow the report's sections then its lifecycle. Cited content counts where the citation points to the framework, the determination or the evaluation report.