# Open-weight Frontier Ledger — Purpose

## Threat model (one paragraph)

Demonstrate a frontier open-weight (≥30B params, ≥1e22 FLOPs, weights publicly
available) capability claim or dual-use risk-mitigation claim that survives
six closure audits on the 2024–2026 corpus: **(1) fine-tuning safety-erosion
audit (Lermen-Rimsky lineage), (2) distillation cousin half-life, (3) bio /
chem dual-use uplift audit, (4) cyber / hacking dual-use uplift audit, (5)
weight-release-vs-API-access asymmetry, (6) sleeper-agent / backdoor
persistence (Hubinger lineage).** A clean trigger requires independent
third-party verification (METR / Apollo / AISI / Stanford CRFM) within 6
months. Frontier open-weight models in scope: Llama 3.1-405B / 4-Behemoth,
DeepSeek V3 / R1, Qwen 3, Mistral Large 2.

## Empty-space hypothesis (predeclared)

We predict no 2024–2026 paper triggers Bills 5, 8, 11 cleanly:

- **Bill 5 ★** — Distillation-resistant capability claim. Halevy-Heim-Pilz
  predicted to find 0/N capabilities distillation-resistant.
- **Bill 8 ★** — Cross-deployment-surface generalization (raw weights →
  fine-tune → quantize → distill → deploy). Asymmetric pattern: capabilities
  transfer cross-surface; safety mitigations don't.
- **Bill 11 ★** — Open-weight gating regulation achieves stated purpose.
  BIS Diffusion Framework rescinded May 2025 (4-month lifetime). EU AI Act
  10²⁵ misses Llama 3.1 405B.

## Status

Stage 1 (SCOPE) — purpose written.
