The Hiroshima AI Process is a G7 initiative that asks AI developers to answer a standard set of questions about how they manage risk, and then publishes their answers. It is not new: the G7 launched its reporting framework in 2023, and HAIP 2.0, released in May 2026, is an incremental update. It is also voluntary: companies choose whether to report, and nothing happens to them if they do not. CeSIA has been involved in this process directly. We shared input and feedback on the V2 drafts with the OECD team between March and May 2026; we set out what V2 changes, and why it matters, in an earlier analysis.
This mapping grew out of that work. It asks how much of what HAIP requests is already required by law or already promised in companies’ own commitments, and where the genuine gaps are. One concern raised about it, including during its consultation, is that it adds another reporting burden for frontier developers, and the data does not support that. Of HAIP's 31 questions, 27 are already matched, strongly or partially, by at least one of the eight voluntary commitments these companies or their governments have signed or published (the three intergovernmental commitments plus the five lab frameworks), and 29 turn up somewhere among them. Across all ten instruments, only one, publishing a privacy policy, appears nowhere. So HAIP mainly recombines commitments that already exist, which puts the reporting-burden worry to rest: it asks for little that companies have not already committed to somewhere. That raises a sharper question - if HAIP restates what the law and the companies’ own pledges already contain, does it add anything of its own, or is it simply redundant? That depends on where the shared coverage is real, and where it thins out.
Safety testing is where the instruments agree
Coverage is broad, but the firm, detailed commitments cluster narrowly, around safety testing and a couple of reporting items. Red-teaming is nearly universal, a firm commitment in 9 of the 10 instruments, and all five AI companies also commit in detail to post-deployment monitoring and model- and system-card transparency (publishing a standard summary of what a model can do and where it should not be used), with cybersecurity and incident reporting close behind. Consensus mostly ends there. Beyond that cluster, most of the ten instruments say little.
Only six questions have no strong match anywhere. Those are lifecycle risk and training-data quality, privacy practices, publishing a privacy policy, training staff on AI safety, socio-economic research, and the UN Sustainable Development Goals. Most of these are workforce, rights and societal questions that instruments address loosely if at all. Lifecycle risk and training-data quality is the odd one out: nearly every instrument touches it, but none in real depth.
Where the AI companies go beyond the law, and where they stop
On 11 of the 31 questions, a lab's own framework is firmer than the binding EU regime (the AI Act and the Code of Practice, the only instruments in the map that carry legal force). On a few, like publishing safety research or the specifics of agentic AI, the regime says almost nothing. On the rest, like capability reporting, sharing evaluations and internal governance, it does set requirements, but in general or systemic-risk-limited terms that the AI companies' frameworks spell out in more detail.
We don't take that as a case for leaving governance to industry. A framework a company writes for itself, it can rewrite for itself. Soft law that is ahead today is unenforceable, and although walking back a public commitment is not cost-free, nothing stops a company from revising its own framework. That is a reason to pull binding law up to the frontier rather than cut it back.
Those voluntary commitments have clear limits, though. OpenAI, Meta and Google DeepMind each make firm commitments on 13 or 14 questions, more than anyone else, yet each leaves between 6 and 12 blank, and the blanks cluster in rights, user-facing disclosure and societal contribution. All five AI companies go silent on the same four questions, publishing a privacy policy, training staff on AI safety, telling users they are talking to an AI, and the SDGs. These frameworks exist to set a company's own capability thresholds and decide when to pause or add safeguards, not to hold it to public account, which is the gap HAIP fills.
What only the binding regime delivers
Some protections exist only because a legislature wrote them down, and one example shows it plainly. Telling a person they are dealing with an AI, under Article 50 of the AI Act (which requires providers to disclose when a user is interacting with an AI system, and to label AI-generated content), is a firm commitment in the EU regime and nowhere else; neither the voluntary commitments nor the AI companies' own frameworks touch it. Copyright runs the same way, held by the Act and the Code of Practice and largely missing from the voluntary side.
Across the map, the EU columns are the only binding ones, and these are already narrow. The systemic-risk obligations only apply to the largest general-purpose models, and even there, on 11 questions, the AI companies' frameworks are more detailed than the law. That is the binding layer as it stands, before anyone trims it further. If it is weakened, the field is left to commitments that are wide but unenforceable, and unevenly kept.
What HAIP adds
Most of this information already exists somewhere. What is missing is any way to read it together. EU documentation goes to the AI Office, the Code of Practice's model reports stay confidential, and what is public is kept in company-specific formats that do not line up against each other. HAIP is the one instrument published by default and filed in a common format across firms and jurisdictions. Its reports are published openly on the OECD's AI transparency portal, and it reaches organisations the EU framework was never designed to touch, like a US lab with no EU footprint, a compute provider, or a deployer outside the EU.
Even the newest instrument defers to HAIP. The New Delhi Frontier AI Impact Commitments are by far the narrowest set we mapped, blank on 23 of 31 questions, and what they do cover is economic impact and usage statistics rather than safety. They even send their reporting back to the Hiroshima framework. As the agenda tilts from safety toward adoption, a shared public reference like HAIP matters more, not less.
So what is HAIP for?
Taken together, the map describes a governance system that works in patches. There is a technical core almost every instrument covers, a frontier where the AI companies' own frameworks are often more detailed than the law but nothing binds them to it, a few rights protections that come only from hard law, and a mass of commitments whose answers rarely reach the public in comparable form.
So HAIP is not redundant, even though it asks for almost nothing the field has not already committed to somewhere. The substance is shared; what no other instrument provides is a single place where the answers are public, comparable across companies, and filed the same way across jurisdictions. Binding law is what makes commitments enforceable and hard to walk back, which is the case for strengthening the AI Act on frontier risk rather than paring it down. A common, public standard is what makes them legible. That is what HAIP is for, and it is why the overlap is the point, not the problem.
Caveats
Three caveats. A match in the map means a topic appears in an instrument's text; it does not mean the company does it well, or that anyone enforces it. The two EU columns were scored on legal overlap and the eight voluntary columns on whether the text makes a commitment, so the scales are close, but not identical. And the company frameworks are each firm's latest published version rather than a common date, so they are not perfectly aligned in time; OpenAI's is about a year older than the rest.
Method. Each of the 31 HAIP 2.0 questions was rated against every instrument on four levels, strong, partial, weak, and no overlap, using a rubric fixed in advance. It asks whether the substance matches, whether the commitment is binding, whom it binds, and how public the disclosure is. The two EU columns come from a legal-overlap analysis; each of the eight voluntary columns was rated independently by three different AI models and reconciled, with the few contested cells adjudicated separately. The figures are CeSIA's own analysis and are not an official assessment by the OECD or the EU.
