No idea, sorry.
[UPDATE] There is a clue in section 3.3.1 Minimal Declaration Processing Requirements:
"A safety declaration that increases the current safety level must always be recognized. An implementation that always processes code as if safety were high may safely ignore this declaration."
To me this seems to imply that the default value of SAFETY is implementation-dependent.
I also found that passage. It's either implementation-defined or else they went incredibly out of their way to hide the requirements.