top of page

Google, Anthropic, and OpenAI Safety Standards Plan Tests Self-Regulation

Sep 28
11 min read

Google, Anthropic, and OpenAI have reportedly moved closer to creating private OpenAI safety standards, despite years of calls for stronger public oversight. The proposed organization would set common rules for frontier AI developers without operating as a government regulator. Its working name is the Standards Authority for Frontier AI, or SAFA.

The initiative remains a proposal, not an established authority. The companies have not jointly announced SAFA, published its governance documents, or explained how its decisions would be enforced. Most details come from people familiar with the discussions.

That verification gap creates the central tension. The companies building some of the most capable AI systems want to help define how those systems should be tested. Their technical knowledge gives them a strong reason to participate. Their commercial interests give everyone else a strong reason to demand independence.

The Reported OpenAI Safety Standards Body Is Taking Shape

The immediate change is organizational: private discussions about AI safety are reportedly becoming a plan for a standing standards authority.

The Information reports that Google, OpenAI, and Anthropic are developing an industry-led organization focused on frontier AI safety. Frontier AI refers to highly capable, general-purpose models that approach or exceed the abilities of existing leading systems.

The organization’s tentative name is the Standards Authority for Frontier AI. The acronym, SAFA, could still change because the group has not been formally launched. The companies reportedly hope to establish it by late 2026 or early 2027.

That timetable matters because a launch date turns a broad policy conversation into an operational project. An actual authority would need leaders, funding, membership rules, technical procedures, and a credible decision-making structure.

The companies have reportedly approached Sriram Krishnan about becoming chief executive. Krishnan previously worked as a venture capitalist and served as a senior AI policy adviser in the Trump administration. His reported candidacy suggests that the organization wants political credibility alongside technical expertise.

Other possible leaders and scientific advisers have also reportedly been discussed. However, no appointment appears to have been publicly confirmed. The companies have not disclosed whether candidates accepted, declined, or remain under consideration.

A separate report showed that the coordination was not merely speculative. OpenAI global policy chief Chris Lehane said the company had discussed AI safety with Anthropic and Google DeepMind for several weeks. His comments confirmed the talks, although they did not confirm every reported detail about SAFA.

The safety discussions reportedly include questions about catastrophic risks, third-party evaluations, and cooperation among competing developers. They also raise concerns about antitrust law when direct competitors coordinate their conduct.

That distinction is essential. Cooperation on safety testing can create shared protections, but coordination can also influence competition. A standards body needs boundaries that allow risk reduction without letting its members control markets or exclude smaller rivals.

No public document yet explains how SAFA would resolve that problem. The reported year-end target also leaves limited time to design safeguards around funding, voting rights, conflicts of interest, and appeals.

For now, readers should treat SAFA as a developing proposal supported by credible reporting. It should not be described as an operating regulator, certified auditor, or finalized agreement.

Why the Three Labs Want Common Rules Now

Google, OpenAI, and Anthropic face a coordination problem that individual safety policies cannot solve.

Each company can publish its own risk framework, commission evaluations, and restrict a model’s release. Those actions do not create a common threshold across the industry. A company that delays deployment may lose users, revenue, or developer attention while a competitor continues moving.

Common OpenAI safety standards could reduce that pressure if every participating developer accepts comparable tests. They could also help customers compare safety claims that currently rely on different definitions and reporting formats.

The timing reflects a broader shift from abstract principles toward operational controls. Developers now need procedures for capability evaluations, security testing, incident reporting, external access, and post-deployment monitoring.

OpenAI’s governance framework covers risks involving cyber offense, biological threats, harmful manipulation, and loss of control. It also describes model reporting, incident response, security management, and external expert input.

Anthropic maintains its own responsible scaling approach, while Google DeepMind uses internal safety frameworks and evaluation programs. These systems share broad themes, but they do not automatically produce identical release decisions.

A shared body could define minimum evaluation requirements before a frontier model reaches users. It could specify who conducts testing, what evidence developers must provide, and how serious findings affect deployment.

The authority might also support confidential information sharing. Frontier labs sometimes discover dangerous capabilities, security weaknesses, or misuse patterns that competitors need to understand. Public disclosure can expose sensitive details, so a trusted exchange mechanism has practical value.

Yet common procedures only help when the participating companies follow them under pressure. The difficult cases involve delayed launches, restricted features, costly security changes, or evidence that undermines a company’s public claims.

Voluntary standards are easiest to follow when they validate a planned release. Their credibility is tested when compliance threatens revenue or strategic advantage.

Government action remains fragmented across jurisdictions. California and the European Union have developed obligations affecting advanced AI, while federal policy in the United States continues to evolve. Companies operating globally must translate overlapping requirements into technical controls.

An industry authority could make that translation easier. It could produce evaluation methods that regulators, auditors, customers, and developers understand. It could also become another layer of private policy without legal accountability.

This is why the reported proposal concerns more than one committee. The organization’s real influence would depend on whether its standards affect actual deployment decisions.

If SAFA merely publishes recommendations, it will resemble many existing policy forums. If it can demand evidence, disclose failures, and impose meaningful consequences, it would occupy a much more consequential role.

The Frontier Model Forum Already Covers Similar Ground

SAFA must explain why another industry organization is necessary when the same companies already created a frontier AI forum.

Anthropic, Google, Microsoft, and OpenAI launched the Frontier Model Forum in 2023. Its stated goals include advancing safety research, developing best practices, supporting evaluations, and sharing information with governments and civil society.

The Forum’s original joint announcement described a public library of technical evaluations and benchmarks. It also promised standardized assessments and secure information sharing about AI risks.

Those objectives overlap substantially with the reported SAFA agenda. Both involve common standards, frontier model evaluations, shared expertise, and coordination among leading developers.

The overlap creates a basic governance question: what authority would SAFA possess that the Forum lacks?

One possible answer is enforcement. The Frontier Model Forum operates primarily as a collaborative industry group. SAFA could be designed more like a self-regulatory authority, with defined rules and compliance procedures.

That distinction would need to appear in binding documents. A new name and executive team would not create meaningful authority by themselves. The organization would need a clear mandate that separates standard setting from ordinary policy coordination.

Membership is another open question. The Frontier Model Forum was established by four companies and later broadened its reach. The reported SAFA discussions center on Google, OpenAI, and Anthropic, leaving Microsoft’s role unclear.

Smaller model developers, open-source projects, academic researchers, enterprise customers, and civil society groups also have interests at stake. Standards designed by three dominant labs might impose requirements that only large companies can afford.

Testing sophisticated models requires specialist researchers, secure computing environments, and controlled access to sensitive systems. Compliance costs could become a barrier for smaller developers even when the rules improve safety.

Large laboratories possess the staff and infrastructure to meet complex certification demands. They also possess the policy teams needed to influence how those demands are written.

That combination creates a regulatory-capture risk. Regulatory capture occurs when a rule-making system increasingly serves the interests of the entities it is meant to constrain.

The risk does not prove that SAFA would be captured. It means the organization needs institutional safeguards before outsiders can rely on its judgments.

Those safeguards should include independent voting power, transparent conflict policies, published methodologies, and procedures for challenging decisions. Membership standards should be proportionate to risk rather than company size.

The body would also need to coordinate with existing public institutions instead of presenting private certification as a substitute. Government agencies carry democratic authority that a company-funded group cannot reproduce.

OpenAI itself previously acknowledged that limitation. A paper on frontier AI regulation called industry self-regulation an important first step, while arguing that government intervention would still be necessary.

That earlier position provides a useful test. SAFA can complement public regulation by producing technical standards and evidence. It should not quietly turn an acknowledged first step into the final system.

The Real Tradeoff Is Expertise Versus Independence

The strongest case for SAFA is technical competence, while the strongest case against it is institutional dependence.

Frontier model evaluations are difficult to design. A test must examine dangerous capabilities without teaching a model how to evade scrutiny. It must also distinguish repeatable behavior from isolated outputs.

External evaluators often need access to model weights, internal safeguards, system logs, and unreleased capabilities. Companies have legitimate reasons to protect that information from competitors and malicious actors.

A specialized authority could create secure channels for reviewing confidential evidence. It could maintain consistent methods across releases and preserve institutional knowledge between incidents.

That model resembles auditing in other high-risk sectors. Independent specialists receive access to confidential records, test claims against defined standards, and report conclusions without publishing every sensitive detail.

However, access alone does not create independence. An evaluator can understand a system deeply while remaining financially or professionally dependent on its developer.

A 2026 research paper on frontier AI auditing argues that outsiders still lack reliable ways to verify leading developers’ safety claims. Its authors propose assurance levels ranging from limited reviews to continuous verification.

That framework highlights an important distinction. A benchmark measures performance under selected conditions. An audit tests whether a developer’s wider claims, controls, and practices deserve confidence.

SAFA would need to decide which function it performs. A standards publisher, a testing laboratory, an auditor, and an enforcement authority are different institutions. Combining them without clear boundaries would concentrate too much discretion.

Funding is an immediate concern. If member companies pay for the organization, the public needs to know whether contributions affect appointments, priorities, or access to findings.

Leadership selection presents the same challenge. A politically connected executive could help the group work with governments. That person would still need independence from the companies that offered the role.

Technical advisers also need conflict disclosures. The frontier AI safety community is small, and experts frequently move among laboratories, nonprofits, universities, and government bodies.

These relationships do not automatically disqualify anyone. They do make transparent recusal rules essential.

Recent reporting illustrates the tension around outside evaluators. Some officials and industry leaders want experts with direct laboratory experience, while critics question close personal and professional links.

One independent assessment noted that many AI evaluations still emphasize performance more than security behavior. The same report quoted SaferAI’s Henry Papadatos arguing that voluntary company action remains insufficient without public transparency.

A credible authority should therefore publish more than reassuring conclusions. It should identify the standard used, the evaluator’s independence, the evidence category reviewed, and any limitations affecting the result.

It should also disclose disagreements. If an evaluator recommends delaying a model and a member releases it anyway, users and regulators should know that the process failed to control deployment.

Enforcement options could range from private remediation requirements to public notices and membership suspension. Each option involves tradeoffs around confidentiality, legal exposure, and public safety.

A body with no consequences risks becoming a reputation service. A body with substantial power but weak accountability risks becoming a private regulator controlled by market leaders.

That is the central SAFA tradeoff. The laboratories possess information that outsiders need, but they should not receive unchecked authority because they possess it.

Developers and Enterprise Buyers Will Feel the Effects

The first practical impact will appear in procurement, model access, and release procedures rather than consumer-facing product labels.

Enterprise buyers already ask vendors about security controls, privacy, incident response, and regulatory compliance. Frontier AI standards could add model-specific evidence to those reviews.

A company deploying an AI coding agent might want proof that the model was tested for vulnerability creation, credential theft, and unauthorized actions. A healthcare customer might prioritize privacy, manipulation risks, and reliability under unusual prompts.

Common standards could make those questions easier to compare. Buyers would receive evidence organized around shared categories instead of incompatible vendor reports.

That benefit depends on access. A certification badge without supporting documentation would give procurement teams little basis for judging the quality of an assessment.

Developers could also face new restrictions. Model providers might require stronger identity checks, monitoring, or staged access when evaluations identify dangerous capabilities.

Those controls can reduce misuse, but they can also limit experimentation. Researchers and small companies may struggle to obtain the same access as large customers.

Open-source developers face a different problem. Standards built around closed laboratory practices may assume that one organization controls model weights, deployment infrastructure, and user access.

Open models distribute those responsibilities. A useful framework must distinguish risks created during training from risks created through deployment, modification, and downstream distribution.

If SAFA ignores this distinction, its standards could favor centralized services by design. That would turn a safety framework into a market-structure decision.

Cloud providers would also feel pressure. Google operates both a frontier model laboratory and major computing infrastructure. Microsoft and Amazon have deep relationships with leading AI developers.

Standards concerning secure training, model access, logging, and incident response would affect those platforms. Their participation or exclusion would shape whether the authority covers the wider AI supply chain.

Knowledge workers may encounter the rules indirectly. A model could refuse more requests, require confirmation before actions, or lose capabilities after a risk assessment.

Those changes can look like product decisions even when they originate in safety governance. Clear disclosure would help users understand why access changed and whether the restriction applies across providers.

Organizations tracking these decisions need evidence from model reports, policy updates, and incident notices. A searchable knowledge base can help teams connect changing standards with vendor assessments and internal deployment records.

The most valuable outcome would be comparability. Customers should be able to determine whether two vendors passed equivalent tests under equivalent conditions.

The least valuable outcome would be symbolic certification. If every founding member passes every review, regardless of incidents or disputed findings, the label will communicate little.

Developers and buyers should therefore examine the method behind any future SAFA mark. They should ask who tested the model, what access they received, and which risks remained outside scope.

Three Signals Will Show Whether SAFA Has Real Authority

SAFA should be judged by its governance, its consequences, and its relationship with public regulators.

The first signal is a formal charter. The reported name, launch window, and leadership discussions do not reveal how the organization would actually work.

A credible charter should identify the members, funding sources, voting structure, conflict rules, and appointment process. It should also explain whether independent experts hold decision-making power.

Watch for provisions that prevent founding companies from overruling evaluators. Without those protections, the authority would remain dependent on the laboratories it assesses.

The second signal is a published evaluation and enforcement process. The organization should define which models enter review, when testing begins, and what evidence evaluators receive.

It should state what happens after a serious finding. Possible outcomes include remediation, restricted deployment, delayed release, public notification, or removal from the organization.

The process should also include appeals. Companies need a way to challenge technical errors, while evaluators need protection from commercial retaliation.

A vague promise to promote best practices would weaken the case for a new organization. The Frontier Model Forum already performs research and coordination functions.

The third signal is formal recognition from regulators without regulatory surrender. Public agencies might use SAFA methods, participate as observers, or incorporate technical work into legal standards.

That cooperation would strengthen the proposal if governments retain oversight and enforcement authority. It would weaken the proposal if policymakers simply outsource judgment to the largest developers.

The reported selection of a politically experienced chief executive would support the view that government relations are central to the plan. It would not establish public accountability on its own.

The launch timeline is another test. A late-2026 or early-2027 debut leaves little room for extensive consultation if the body wants to begin with substantive authority.

A rushed launch might produce broad principles before detailed controls. That sequence is understandable, but the organization should not present aspirational rules as completed safeguards.

Readers should also watch which companies stay outside. Microsoft, Meta, Amazon, xAI, major open-model developers, and international laboratories all influence frontier AI markets.

A standard followed by only three companies can still matter. Its legitimacy will remain limited if other major developers reject its methods or governance.

The same applies to civil society and researchers. Participation must involve more than advisory meetings after the founding companies make key decisions.

The proposed OpenAI safety standards body could become useful infrastructure for testing increasingly capable models. It could also duplicate existing groups while giving private decisions a regulatory appearance.

The difference will be visible in documents, not promises. Look for independent votes, enforceable consequences, transparent methods, and a defined role for government oversight.

As SAFA approaches its reported launch window, developers and enterprise buyers should preserve vendor claims and compare them with later rules. Which safeguards become measurable, and which remain voluntary language? That comparison will reveal whether the initiative changes deployment behavior or merely changes how leading laboratories describe it.

Give every agent the context to do better work

Connect your agents to the knowledge, decisions, and history already organized in remio.

remio currently supports Windows 10+ (x64) and Macs with Apple silicon.

Your AI Partner at Work
Get more done with remio

Plan. Create. Deliver.
All in one place.

bottom of page