Skip to main content

Envisioning is an emerging technology research institute and advisory.

LinkedInInstagramGitHub

2011 — 2026

research
  • Observatory
  • Newsletter
  • Methodology
  • Origins
  • Vocab
services
  • Signals Session
  • Bespoke Projects
  • Use Cases
  • Readinessfree
  • Signals
  • Free scan↗free
impact
  • ANBIMAFuture of Brazilian Capital Markets
  • IEEECharting the Energy Transition
  • Horizon 2045Future of Human and Planetary Security
  • WKOTechnology Scanning for Austria
solutions
  • Innovation
  • Strategy
  • Consultants
  • Foresight
  • Associations
  • Governments
resources
  • Partners
  • How We Work
  • Data Visualization
  • Multi-Model Method
  • FAQ
  • Security & Privacy
about
  • Manifesto
  • Community
  • Events
  • Support
  • Contact
ResearchServicesSignalsAbout
ResearchServicesSignalsAbout
  1. Home
  2. Vocab
  3. Model Uplift

Model Uplift

Risk that a model helps an actor cause harm they could not cause unaided.

Year: 2023Generality: 700Added: Jun 10, 2026
Back to Vocab

Model uplift, in frontier-safety frameworks, is the increase in an actor's ability to cause harm that results from access to a powerful AI model, measured against the harm the same actor could achieve using only freely available resources such as search engines, textbooks, and existing tools. The concept is central to how organizations like NIST, OpenAI, and Anthropic reason about deployment risk: a model is considered high-risk under uplift analysis if it materially expands what a motivated actor can do, even if the model itself never produces a catastrophic output on its own.

Mechanically, uplift is measured by comparing the success rate, speed, or quality of a harmful task performed by a human with model assistance against the same task performed with only baseline resources. The comparison is usually run on red-team tasks that span biology, chemistry, cybersecurity, and persuasion. The result is a per-domain uplift estimate, often expressed as a percentage improvement, which is then aggregated into a deployment decision. Some frameworks distinguish between knowledge uplift (the model explains something the actor could not have learned unaided) and capability uplift (the model executes part of the harmful task itself, such as writing functional exploit code).

The advantage of uplift framing is that it makes risk commensurable across very different harm domains and aligns deployment decisions with real-world attacker economics. The cost is that uplift is hard to measure rigorously: baseline performance varies by actor, and small differences in task design can swing the estimate by large margins. The framework also tends to underweight the risk of new attack types that the model enables but that have no clean baseline, because there is nothing to compare against. Despite these limitations, uplift has become the dominant frame in frontier-safety policy because it is the only concept that connects model capability to harm in a way that does not require the model to fail catastrophically before risk is recognized.

Open questions include how to standardize uplift measurement across organizations, how to handle the long tail of low-probability high-severity harms, and whether uplift is the right frame for risks that are not actor-mediated, such as autonomous model behavior in agentic systems. The relationship between uplift evaluations and the actual deployment decisions that follow from them is also under active debate, with critics arguing that uplift estimates are too uncertain to anchor a regulatory regime.

Research this in Signals

Scan Model Uplift for yourself.

Signals turns a topic into a sourced research record you can inspect and rerun. Your first scan is free, and this one starts with Model Uplift already loaded, so edit it or scan as is.