Dendrons Compass
Frontier Safety Audit - one worked case below, checked against primary source text
Does the EU's GPAI Code of Practice actually require a minimum content standard for public safety reports?
We check named regulations, such as California's SB 53 and the EU AI Act's General-Purpose AI Code of Practice, against what a specific company has actually published. This is one worked case: one obligation, one document, cited precisely.
This case was checked by hand against the primary source text on both sides. It is not an automated output. If we have read a clause wrong, tell us and we will correct this page: np@dendrons.ai
Who this is for
- Banks, insurers, and other companies that rely on a frontier model provider, checking whether that provider's disclosures are enough for their own vendor and model risk obligations, under rules like MAS FEAT or RBI's guidelines.
- AI safety and policy people who want a quick, checkable example, not a general opinion.
The obligation
EU General-Purpose AI Code of Practice, Safety and Security Chapter, Commitment 10, Measure 10.2 (“Public transparency”)
“If and insofar as necessary to assess and/or mitigate systemic risks, Signatories will publish...a summarised version of their Framework and Model Report(s)...For Model Reports, such publication will include high-level descriptions of the systemic risk assessment results and the safety and security mitigations implemented.”
The document
Anthropic's Frontier Compliance Framework, Version 2, effective 24 July 2026, Section 4 (“Model Reporting”)
“We will publish public summaries of these assessments via standalone reports or as part of our model system cards upon model launch.”
The question we tested
Does the EU Code leave public safety-report summaries without any defined minimum content, a gap sometimes assumed but rarely checked against the actual Code text?
The finding
No. Measure 10.2 does set a real, if thin, minimum: a Model Report summary must include high-level descriptions of both the systemic risk assessment results and the mitigations implemented. That is a defined content floor, not an empty box.
The sharper finding is elsewhere. Publication itself is conditional on the signatory's own judgment, “if and insofar as necessary”, with no independent check on that judgment call. And the required content is vague: “high-level descriptions” sets no floor on depth or format, so two signatories could both comply while disclosing very different amounts.
Separately, Anthropic's own FCF commitment reads as more specific than what the Code strictly requires of it: it commits to publishing “upon model launch,” unconditionally, rather than only if and insofar as Anthropic itself judges it necessary.
Sourcing
Both quotes above were read directly from primary documents: the Code of Practice's official Safety and Security chapter PDF, and Anthropic's own published Frontier Compliance Framework. Neither quote was taken from a summary or a secondary source.
Beta, early version under testing
Request a custom analysis
We are not yet offering an automated tool that generates a gap analysis for any obligation and document a visitor submits. An unverified automated analysis has a real failure rate, and a wrong answer shown to someone testing it is worse than an honest beta with hand-checked examples only. Tell us what pairing you would want checked, and we will look into it and reply directly.
Request a check →Looking for design partners
We are building this out further. If you would use it, tell us what you would want it to check.
np@dendrons.ai →