THE ARTICLE · 6 MIN
“Frontier model” is used as if everyone agrees what it means: the most advanced AI systems of the day. In practice, the organisations that define it draw the line in very different places. Some ask how capable a model is, some how dangerous it could be, some how much computing power was used to train it, and one leaves the answer to a classified test.
This page sets out eight definitions in their own words, so you can see what someone means when they use the term. It is about the meaning of a phrase — not about what any law requires, and not legal advice.
First, what “training compute” means
Several definitions below count computing power. The AI research group Epoch AI explains the unit: “Compute usage is commonly measured as the number of floating point operations (FLOP) required to train the final version of the system”. The thresholds below are written as powers of ten — 10^25 is a 1 followed by 25 zeros.
1. The industry group: a capability definition that changed
The Frontier Model Forum was announced on 26 July 2023 as “a joint announcement and effort between OpenAI, Anthropic, Google, and Microsoft.” Its launch post described frontier models as “large-scale machine-learning models that exceed the capabilities currently present in the most advanced existing models, and can perform a wide variety of tasks”.
Its membership definition has since changed. Its About page says that “‘Frontier AI’ refers broadly to those general purpose AI models that constitute the state of the art, a collection which will shift over time as the field progresses.” Then, “For purposes related to its membership”, it defines a frontier AI model as “a general-purpose model that outperforms, based on a range of conventional performance benchmarks or high-risk capability assessments, all other models” “that have been widely deployed for at least 12 months”. It adds that this definition is “intentionally more expansive than only ‘current state of the art’ models”. As read in September 2026, its members are “Amazon, Anthropic, Google, Meta, Microsoft, and OpenAI.”
2. The UK government, 2023: “match or exceed” today’s best
For the international AI Safety Summit, the UK government published a discussion paper, Frontier AI: capabilities and risks, on 25 October 2023. For the purposes of the summit it described frontier AI as “highly capable general-purpose AI models that can perform a wide variety of tasks and match or exceed the capabilities present in” the most advanced models, adding: “Today, this primarily includes large language models”.
3. The research paper: defined by danger
A 2023 paper, Frontier AI Regulation: Managing Emerging Risks to Public Safety, by Markus Anderljung and 23 co-authors, drew the line around risk rather than capability alone. It described frontier AI models as “highly capable foundation models that could possess dangerous capabilities sufficient to pose severe risks to public safety”.
4. The European Union: a different name and a compute presumption
The EU AI Act uses a different label altogether. Its Article 51 is headed “Classification of general-purpose AI models as general-purpose AI models with systemic risk”.
Under Article 51(2), a general-purpose model “shall be presumed to have high impact capabilities” when “the cumulative amount of computation used for its training” “measured in floating point operations is greater than” 10^25. The Act also describes high-impact capabilities by comparison, as “capabilities that match or exceed the capabilities recorded in the most advanced general-purpose AI models”.
5. California: more than 10^26 operations
California’s SB 53, approved by the Governor on 29 September 2025, defines a frontier model as “a foundation model that was trained using a quantity of computing power greater than 10^26 integer or floating-point operations”. The count includes more than the first training run: it “shall include computing for the original training run and for any subsequent fine-tuning, reinforcement learning, or other material modifications”.
6. New York: a definition that changed within months
New York’s RAISE Act shows how quickly these definitions move.
- As first signed (chapter 699, December 2025), a frontier model meant “either of the following”: a model trained with more than 10^26 operations, “the compute cost of which exceeds one hundred million dollars”; or a model made by “applying knowledge distillation” to such a model, where that process’s compute cost “exceeds five million dollars”.
- As amended (chapter 96, signed March 2026), the definition follows California’s wording: a frontier model “means a foundation model that was trained” using computing power greater than 10^26 integer or floating-point operations.
7. The US federal government: a classified test
Executive Order 14409, “Promoting Advanced Artificial Intelligence Innovation and Security”, dated 2 June 2026, uses the term “covered frontier model” but sets no public number. It directs the Secretary of the Treasury, the Secretary of War (through the Director of the NSA) and the Secretary of Homeland Security (through the Director of CISA) to “develop and maintain a classified benchmarking process to assess the advanced cyber capabilities of AI models and determine the threshold at which an AI model should be designated a ‘covered frontier model’ for the purposes of this order”. It adds: “Such a determination shall be made by the Director of NSA”.
8. The research tracker: top ten at release
Epoch AI, which maintains a public database of more than 3,600 AI models, uses a moving definition for its own data: “Frontier models are models that were in the top 10 by training compute at the time of their release”.
It uses a separate, fixed line for scale: “Large-scale models are models that were trained with over 10^23 FLOP of compute, which is a static threshold”.
How many models cross these lines?
Counts depend on estimates of training compute, because not every company publishes it. Epoch AI reported: “As of June 2025, we have identified over 30 publicly announced AI models from 12 different AI developers” above 10^25 FLOP, and “The first model trained at this scale was GPT-4, released in March 2023.” For the higher line, a May 2025 Epoch report said “the first model in our dataset estimated to use over” 10^26 FLOP “was Grok-3 from xAI, released in February 2025”.
What to take from this
Our reading: when someone calls a model “frontier”, it is worth asking which definition they mean.
- Capability definitions (the industry group, the UK) are relative, so the frontier moves as models improve — a model that was frontier in 2023 may not be now.
- Danger definitions (the 2023 paper) depend on judgements about risk that people disagree about.
- Compute definitions (the EU, California, New York) are measurable in principle, but outsiders often have to estimate compute, and a fixed number can be overtaken quickly.
- A classified test (the US order) is not published, though the order provides for “sharing such assessments with AI developers and researchers as appropriate”.
None of these is the “right” one. They were written by different kinds of organisation, for different purposes.
Sources
- Frontier Model Forum, “Introducing the Frontier Model Forum” (26 July 2023); “About us”; “Membership”.
- UK Department for Science, Innovation and Technology, Frontier AI: capabilities and risks discussion paper (25 October 2023).
- Markus Anderljung and colleagues, “Frontier AI Regulation: Managing Emerging Risks to Public Safety”, arXiv:2307.03718 (2023).
- Regulation (EU) 2024/1689 (AI Act), Articles 3(64) and 51, EUR-Lex.
- California SB 53 (2025), Business and Professions Code §22757.11, California Legislative Information.
- New York Senate bills S6953-B (chapter 699 of 2025) and S8828 (chapter 96 of 2026), New York State Assembly bill pages.
- Executive Order 14409, “Promoting Advanced Artificial Intelligence Innovation and Security” (2 June 2026), whitehouse.gov and Federal Register document 2026-11415.
- Epoch AI, “Estimating training compute of deep learning models” (2022); “Data on AI Models”; “Over 30 AI models have been trained at the scale of GPT-4” (updated June 2025); “How many AI models will exceed compute thresholds?” (May 2025).
Checked September 2026.
Related: How to spot a fake quote or an invented source · How to check something online: the SIFT method · How to read a study without a science degree
- artificial intelligence
- ai models
- frontier ai
- definitions
- explainer
