The frontier enterprises — the coverage set

This file records the twelve companies the project uses as its illustrative coverage set: the richest and most powerful American companies occupying every decisive layer of frontier AI. It is the evidence base for the proposed enterprise scope (see the definition and CURE 7 in the v3.5 queue). It is a reference and an argument support, not a finding of any offense — no offense yet exists in law, which is the project’s point.

Naming discipline. Companies are named. Control facts about natural persons — founder, chief executive, voting control — are stated only from public filings and the companies’ own materials, because who controls a company is a governance fact, not an accusation. The conduct record stays at company level: no individual is connected here to any incident.

Two twelves, disambiguated. This coverage set (twelve companies across four layers) is a different list from the framework twelve — the twelve companies METR records as having published a frontier safety framework (see the models file). Eight companies appear on both — the five developers plus Microsoft, Amazon and NVIDIA. The lists serve different purposes: the framework twelve evidences self-designation; the coverage set demonstrates the legal category.

Sourcing. Every quotation carries its source, and the verification record owns the apparatus — every URL, retrieval date, grade, and the list of claims that were checked and failed. Quotations enter two ways: opened by the project at the cited page, or recorded from the maintainer’s sourced research with its citation; the record marks which, so any line here can be re-pinned on demand. ⚠ marks a figure that still lacks a citation. Valuations are approximate as of August 2026 and move daily; private valuations are softer than market capitalizations.


The two definitions

AI laboratories hold a technical definition of frontier: systems near the state of the art in capability, generality, autonomy, or training compute. The proposed legislation holds a legal definition: the companies and officers with enough capability, control, wealth and institutional reach to create or materially amplify frontier-AI risk. The law does not need to decide which company has the best model. Coverage attaches where three things meet:

frontier system + frontier activity + control or scale.

Wealth alone covers nobody. Wealth combined with a material frontier function — training the model, supplying the compute, deploying into consequential institutions — covers everyone who matters.

The selection test

Each company in the set satisfies all or most of six conditions: (1) substantial financial or organizational power; (2) a material AI function; (3) a plausible connection to frontier capability or deployment; (4) practical authority over a decision that can create or reduce public risk; (5) enough public evidence to make legislative coverage defensible; (6) a United States corporate, infrastructure, or deployment nexus.

The coverage set, by layer

The canonical order is by layer, because the layer order is the argument: the developers first — that is where the 2026 incident record lives — then the compute the frontier runs on, then the machines it acts through, then the institutions it enters. The wealth-ranked view follows below.

Layer 1 — model creation

Company Approx. value Control (public record) Main AI 10²⁶ status Their own word
OpenAI implied ≈$500B at the Oct 2025 recapitalization; ⚠ later figures reported near $852B, unpinned OpenAI Foundation controls OpenAI Group PBC — it “appoints all members of the board of directors of OpenAI Group and can replace directors at any time” (openai.com/our-structure); Microsoft ≈27% equity ChatGPT; GPT-5 line; o-series; Codex; Sora; the Frontier enterprise agent product Undisclosed (current); GPT-4.5 estimated 3.8 × 10²⁶ (Epoch, Likely) “If another frontier AI developer releases a high-risk system without comparable safeguards, we may adjust our requirements.” (Our updated Preparedness Framework, openai.com, 15 Apr 2025); and it has named an enterprise product Frontier — a platform for agents that “do real work” (openai.com/index/introducing-openai-frontier)
Anthropic $380B post-money, Series G, 12 Feb 2026 (anthropic.com); ⚠ later figures reported near $965B, unpinned Delaware public benefit corporation; the Long-Term Benefit Trust holds Class T stock electing board members; Amazon (largest, up to ~$8B) and Google are minority investors Claude family; Claude Code Undisclosed (current); Opus 4 estimated 5 × 10²⁵–2 × 10²⁶ (Epoch, tentative) “As frontier AI models advance, we believe they will bring about transformative benefits for our society and economy. Frontier AI models also, however, present new challenges and risks that warrant careful study and effective safeguards.” (Responsible Scaling Policy, anthropic.com, updated 14 Aug 2026); “We believe it would be good for the world to have the option to slow or temporarily pause frontier AI development.” (anthropic.com/institute/recursive-self-improvement); operates the Frontier Red Team
xAI within SpaceX since Feb 2026 (combined ≈$1.25T); pre-merger ≈$230–250B Elon Musk founded and controls; SpaceX absorbed xAI in Feb 2026 (Bloomberg, 2 Feb 2026); “xAI LLC” remains the named developer in its own framework of 30 Jun 2026 Grok family; Colossus supercluster (~200,000 GPUs by May 2025, HPCwire) Grok 4 estimated 5.0 × 10²⁶ (Epoch, Speculative); Grok 3 at 3.5 × 10²⁶ (Likely) — the strongest documented case over the line “This Frontier AI Framework (‘FAIF’) outlines xAI’s approach to policies for mitigation of significant risks associated with the development, deployment, and release of xAI’s frontier AI models, such as Grok.” (xAI Frontier Artificial Intelligence Framework, 30 Jun 2026); “Grok 4.6 achieves frontier intelligence across several agentic coding and knowledge work benchmarks. It matches GPT-5.6 Sol on the composite score of nine benchmarks.” (x.ai/news/grok-4-6, 12 Aug 2026); and the homepage itself: “Frontier AI models for everything you imagine. Reasoning, code, voice, images, and video. Trained on the world’s largest supercluster.” (x.ai, retrieved 22 Aug 2026) — a frontier self-designation and a compute self-claim in one breath, on the front door
Alphabet / Google DeepMind ≈$4.2T Public; Larry Page (27.1%) and Sergey Brin (25.2%) hold ≈52.3% of voting power through ten-vote Class B shares (2025 proxy) Gemini (Gemini 3, Nov 2025); Gemma; Imagen; Veo; AlphaFold; own TPU line (Ironwood) Historic models below (Gemini 1.0 Ultra 5.0 × 10²⁵); current undisclosed, likely over “We call our most powerful foundation models ‘frontier models’.” and “The Frontier Safety Framework is a set of protocols that ensure our most advanced AI models remain reliable, thoroughly tested, and aligned with human values.” (deepmind.google/frontier-safety)
Meta ≈$1.4T Public, dual-class; Meta’s 2026 proxy: Zuckerberg “controls a majority of our outstanding voting power” (≈61% per a shareholder-proponent SEC filing) Llama 4 family; Meta AI; Muse Spark; Meta Superintelligence Labs; open-weight distribution Llama 4 Behemoth 5.2 × 10²⁵ (Epoch) — below; current undisclosed; Meta’s own framework adopts ≥10²⁶ as its criterion (next column) “Frontier AI in our Framework refers to a new or substantially modified highly capable general-purpose generative AI model that we are developing for deployment.” and “We trained the model using at least 10^26 integer or floating point operations … or another threshold as may be defined by evolving standards or industry best practices.” (Advanced AI Scaling Framework v2 — the renamed Frontier AI Framework — ai.meta.com, Apr 2026)

Layer 2 — compute creation and control

Company Approx. value Control (public record) Main AI 10²⁶ status Their own word
NVIDIA ≈$5.2T — the most valuable company in the world Public; Jensen Huang, founder and chief executive CUDA; Blackwell and Vera Rubin accelerators; NeMo; Isaac/GR00T Not applicable as a trainer; supplies the accelerators on which essentially every model over 10²⁶ was trained Sam Altman, in NVIDIA’s own materials: NVIDIA infrastructure is “the foundation that lets us keep pushing the frontier of AI” (investor.nvidia.com, NVIDIA Vera Rubin Opens Agentic AI Frontier, 2026 — the release title is NVIDIA’s own use of AI Frontier); and “the frontier of AI, maximum intellectual capability, is going up and up” (blogs.nvidia.com, 22 Sep 2025)
Microsoft ≈$3.6T Public; single share class, one vote per share, no controlling shareholder Azure AI; Copilot; Phi; MAI models (seven launched Jun 2026); Microsoft Frontier Tuning; ≈27% of OpenAI; hosts and distributes OpenAI’s frontier models Own MAI models undisclosed; the >10²⁶ runs it hosts are OpenAI’s Mustafa Suleyman, CEO of Microsoft AI: “The compute used to train frontier models has increased by a factor of one trillion.” and “At Microsoft AI, we recognize that there are no shortcuts to the frontier.” (microsoft.ai, 2 Jun 2026); “To build a frontier firm, you have to optimize frontier performance against cost.” (microsoft.ai, Optimizing the frontier performance curve)
Amazon / AWS ≈$2.8–3T (crossed $3T on 3 Aug 2026) Public; Jeff Bezos, founder and executive chair Nova family and Nova Forge; Titan; Bedrock; Trainium/Inferentia chips; Project Rainier (~500,000 Trainium2 chips) built with Anthropic No disclosed own run over 10²⁶; supplies the compute for Anthropic’s Andy Jassy, letter to shareholders: “high-performance inference with leading selection of frontier models (Bedrock)” (aboutamazon.com, Apr 2026); “Today, we’re introducing Amazon Nova Forge, a new service to build your own frontier models using Nova.” (aws.amazon.com, 2 Dec 2025); Amazon publishes Amazon’s Frontier Model Safety Framework, describing “scal[ing] the capabilities of Amazon’s frontier models” (amazon.science), and describes “frontier agents” that work autonomously (aboutamazon.com)
Oracle ≈$422B Public; Larry Ellison, founder, ≈40.6% holder; co-CEOs Clay Magouyrk and Mike Sicilia since Sep 2025 OCI Supercluster; OCI Generative AI; Database 23ai; Stargate infrastructure partner; classified-cloud deployment for the Department of War (announced 1 May 2026) Not applicable as a trainer; trains and serves others’ frontier models Oracle describes its work as “frontier AI infrastructure” (oracle.com/ai-world/cloud); “Organizations training and serving frontier AI models require infrastructure engineered for extreme throughput” (Oracle Blogs, 17 Mar 2026); and its Department of War release describes “integrating secure frontier AI into classified environments” (oracle.com newsroom, 1 May 2026 — release text, not a named person’s quote)

Layer 3 — physical-world autonomy

Company Approx. value Control (public record) Main AI 10²⁶ status Their own word
Tesla ≈$1.4T Public; Elon Musk, largest individual holder at ≈20%; no super-voting class Full Self-Driving; Autopilot; Dojo; AI5/AI6 silicon; Optimus Undisclosed; plausibly frontier-scale across its autonomy workloads, not publicly proven Tesla says it develops and deploys “autonomy at scale in vehicles, robots and more” (tesla.com/AI); the frontier label is applied to it by coverage — “Tesla’s New Frontier: Embodied AI” (FMP, 8 Apr 2026). Its chosen register is autonomy; coverage follows the function, not the vocabulary

Layer 4 — institutional deployment and enterprise integration

Company Approx. value Control (public record) Main AI 10²⁶ status Their own word
Palantir ≈$412B Public; Class F shares in a founder voting trust (Karp, Thiel, Cohen) engineered to hold just under half of all voting power regardless of economic stake (2025 proxy) AIP; Foundry; Gotham; Apollo; Ontology — defense, intelligence, health, industrial integration of others’ models Below / not applicable as a trainer; covered, if at all, as a deployer-integrator Alex Karp, CEO: “It’s not just the man and woman on the street who are unhappy with the frontier labs” (The Register, 11 Jun 2026) — Palantir positioning itself against the frontier labs is itself evidence the category exists and that Palantir sits one layer below it
Databricks ≈$190B ($5B round closed 13 Aug 2026, led by Coatue) Private; Ali Ghodsi and six co-founders; venture and employee ownership Mosaic AI; DBRX; Agent Bricks; Genie; the governed-data layer where enterprises run frontier models DBRX on the order of 10²⁴ — well below; covered, if at all, as the deployment and data-governance layer “Enterprise demand for frontier AI is accelerating, and with Databricks, we’re making its deployment even simpler” — Brad Lightcap, COO of OpenAI, in Databricks’ own partnership release, which is headed “Frontier Models on Enterprise Data” (databricks.com, Sep–Oct 2025)

The thirteenth example — CoreWeave

CoreWeave (public since 28 Mar 2025; ≈$48.5B; founders Intrator, Venturo, McBee; NVIDIA a shareholder, $2B added Jan 2026) trains nothing of its own and supplies GPU capacity to Microsoft (over 60% of its 2024 revenue), OpenAI, Meta, NVIDIA, IBM, and Cohere. Its chief executive: “This expansion reinforces our position as the essential partner for any organization navigating the complexities of frontier-scale AI.” (coreweave.com, 16 Mar 2026.) It sits outside the core twelve deliberately: the category is criteria-based, and any company meeting the criteria enters. A closed list would be a political enemies list; criteria are law.

What each layer answers

The developers (OpenAI, Anthropic, xAI, Google DeepMind, Meta) are the ordinary technical frontier: they train the models, they publish the frontier frameworks, and three of them account for the five documented 2026 agent intrusions in the incident record. The best objection — “our exact compute is secret” — is answered by the developer’s own SEC. 8 certification and, since CURE 6, by the developer’s own published word frontier.

The compute controllers (NVIDIA, Microsoft, Amazon, Oracle) do not need to train the largest model. NVIDIA designs the accelerators, software stack, and rack-scale systems on which essentially every frontier run executes; Microsoft and Amazon supply and host the training and deployment capacity of the leading developers, and train their own models besides; Oracle leases superclusters to the frontier and carries frontier systems into classified environments. The best objection — “we are neutral suppliers” — fails on their own records: a supplier that designs, markets, finances, and reserves capacity specifically for frontier AI, and retains contractual power over access and scale, is not an interchangeable vendor. Ordinary commodity supply is expressly out.

The embodied developer (Tesla) puts autonomy into machines that act on roads and in buildings, where the failure mode is physical injury rather than text — “autonomy at scale in vehicles, robots and more,” in its own words. A statute that defined frontier only as language models would write a loophole for the systems most capable of hurting someone by accident. Tesla also shows why the legal category cannot rest on any single limb: its chosen register is autonomy rather than frontier, its training compute is undisclosed, and its coverage follows its function — embodied frontier capability at fleet scale — not its vocabulary.

The institutional integrators (Palantir, Databricks) select the model, connect it to sensitive data, define its permissions, and place it inside defense, intelligence, health, financial, and industrial decision systems. The best objection — “we do not train frontier foundation models” — is correct, and is the point: a company placing frontier systems inside consequential institutions can create more immediate public exposure than the laboratory that trained the weights. They are covered as what they are, never deemed developers of models they did not train.

Why not only the model developers

Because that would regulate the visible model-makers while leaving the surrounding power structure outside the law. The frontier is produced by chips, data centers, cloud access, models, deployment platforms, sensitive data, institutional permissions, and the capital that sustains the whole system. A company controlling one of those decisive layers may hold more practical power over public risk than a smaller company that technically pressed train.

A model developer cannot say the cloud provider was responsible; the cloud provider cannot say it only hosted the model; the deployment company cannot say it merely integrated someone else’s system. A law that covers only the model trainer leaves the other decisive points of control legally invisible.

Why not every company that uses AI

Ordinary AI use is not enough, and the statute says so on its face. Coverage requires a material frontier function combined with frontier scale — frontier training compute, hyperscale compute supply, critical-sector deployment, autonomous physical systems at fleet scale, or the bracketed capacity conditions — and the protective clause holds that no person is covered solely because of wealth, market value, use of artificial intelligence, or ordinary commercial supply. A company using a commercial model through an API is not covered by that fact.

Criteria, not names

The statute never names these companies. A statute imposing special criminal duties on twelve named companies would invite a bill-of-attainder challenge and would read as an enemies list; criteria are law. The set is illustrative: it demonstrates that the criteria, applied to the facts of August 2026, capture the principal forms of frontier-AI power — and that a company does not need to agree it is a “frontier company” for coverage to follow the facts.

The wealth view

Ranked by approximate value, the set reads: NVIDIA ≈$5.2T; Alphabet ≈$4.2T; Microsoft ≈$3.6T; Amazon ≈$2.8–3T; Tesla ≈$1.4T; Meta ≈$1.4T; combined SpaceX–xAI ≈$1.25T; OpenAI and Anthropic in the high hundreds of billions (private, softer figures); Oracle ≈$422B; Palantir ≈$412B; Databricks ≈$190B. This is the concentration the findings describe: the technology, the compute, the capital, and the institutional reach of the frontier sit inside roughly a dozen American companies, several individually worth more than the annual output of most countries — and, at present, no natural person in any of them holds a personal, non-delegable legal duty to prevent the public harms their systems can cause. Wealth is where the findings point; function is what the elements require.

Sources and verification

The entity-based case, made independently — added 23 August

Source: Dean W. Ball & Ketan Ramakrishnan, “Entity-Based Regulation in Frontier AI Governance,” Carnegie Endowment, 7 July 2025 (⚠ P — full text supplied 23 Aug, validated; carnegieendowment.org/research/2025/07/artificial-intelligence-regulation-united-states). Ball co-authored before joining the U.S. Office of Science and Technology Policy; his bio at the time of the August posts read “head of strategic futures @openai.” Ramakrishnan is an associate professor at Yale Law School.

The scholarly case for this file’s category has now been made independently, from the other side of the regulatory argument. Ball and Ramakrishnan argue that frontier statutes should be triggered by characteristics of the developing entity — for example aggregate AI R&D spend — rather than of models or uses: models are “fast-evolving and novel artifacts, which are often a leaky abstraction for the risks of frontier AI development,” while “[r]egulating corporate entities — something that U.S. law has done for centuries, often with considerable success — might do much better.” Their count of the covered universe matches this file’s: “in the United States, five to ten firms.”

Three of their points meet this project’s text directly. On evasion, they answer the subsidiary-splitting objection with the same instruments CURE 7’s aggregation rules draw on: veil-piercing, substantive consolidation, the integrated-enterprise test, and banking law’s common-control tests. On scope, their observation that entity-based regulation reaches “governance procedures, the handling of algorithmic secrets, and the detection of insider threats” — risks no model-property trigger can see — is the argument for duties that attach to functions rather than artifacts. And at the middle of their own spectrum of options sits this sentence: covered developers “might be required to appoint a chief risk officer, who reports directly to the board of directors.” That is the entity-based literature reaching, on its own reasoning, toward the designation architecture at SEC. 4 — stopping short of the office this Act names, but walking the same corridor.

Stated honestly, both ways. Their paper is regulatory design, not liability design; it proposes disclosure-to-oversight regimes, not offenses, and it should not be cited as support for criminal exposure. What it is, is independent scholarly convergence on the trigger: the covered frontier enterprise. The Act is entity-based at the trigger and person-based at the duty — and each half now has its own literature.

Quotations carry their sources above; the apparatus behind them — full URLs, retrieval dates, per-item grades, and the nine claims that were checked and did not survive — is the verification record, which governs where the two disagree. Compute estimates are Epoch AI’s, used under CC BY 4.0 with the citation given in the models file; they are estimates, not disclosures — the absence of disclosure is itself a finding the Act’s SEC. 8 and SEC. 9 address. Ownership and control facts are from proxy statements, SEC filings, and the companies’ own governance pages. Corrections enter the errata register.

The argument this file supports: the case — personal, legal accountability for the natural persons with practical authority over frontier-AI activity, regardless of delegation or corporate structure.


Back to top

This page was built . The repository is the authoritative record; if this page and the repository differ, the repository is right.

Visits are counted with GoatCounter: no cookies, no personal data, nothing shared. The count is private to the maintainer.

This site uses Just the Docs, a documentation theme for Jekyll.