Skip to content

AI Governance

OpenAI, Google, and Anthropic are building their own AI safety regulator. Here is what self-graded homework means for the vendor you already depend on.

OpenAI, Google, and Anthropic have spent the past two months coordinating on a shared safety standards body for frontier AI models, an effort OpenAI has confirmed on the record. The direct answer for a business owner: this is not new regulation and nothing about how you use AI today changes because of it. It matters because it is the three biggest AI vendors proposing to write, fund, and grade their own safety rules, largely without a government body standing above them, and that changes what any claim about a vendor's safety actually means to you.

By Fabio Rabelo · Founder, ATLACIS ·

What happened

On July 14, 2026, Google DeepMind CEO Demis Hassabis proposed a new kind of oversight body for the most advanced AI models: a "Standards Body" modeled on FINRA, the organization that polices Wall Street brokers. His idea was for frontier labs to voluntarily share models for review up to 30 days before release, with that review eventually becoming a required step for deployment in the US, backed by government authority but funded and staffed largely by the industry itself. On September 15, 2026, an OpenAI spokesperson confirmed to CNBC that OpenAI had been in talks with Anthropic and Google since Hassabis's proposal about building exactly this kind of body together. Google and Anthropic did not respond to CNBC's request for comment, so only OpenAI has gone on record confirming the coordination, even though reporting describes all three labs as involved. OpenAI's chief global affairs officer, Chris Lehane, separately confirmed the talks to multiple outlets the same week and said any industry-led standards would "complement, not replace" mandatory federal safeguards. On September 24, 2026, The Information reported that the three labs had approached Sriram Krishnan, the White House's senior AI policy adviser from January 2025 to June 2026, to be CEO of the proposed organization, tentatively called the Frontier AI Standards Agency. That detail has not been confirmed on the record by OpenAI, Anthropic, or Google. It is a notable choice regardless: Krishnan left his government post saying publicly that "there will not be an FDA for AI," arguing that a centralized approval agency would slow the industry down. The body now being discussed is described, at this stage, as running without a government body standing above it, which is a step back from Hassabis's original version.

Why it matters for business owners

Most business owners will never read a frontier lab's safety documentation. But almost every business using ChatGPT, Claude, Gemini, or a product built on top of one of these models is relying, at some level, on the idea that the vendor behind it takes safety and security seriously enough to be trusted with real work. Right now, when a vendor says its model is safe, that claim is entirely self-reported. There is no outside body checking it, no license that can be revoked, no independent auditor with the standing to say a vendor's testing fell short. A standards body built and funded by the three biggest labs would not automatically fix that. It would mean the labs are grading their own homework together instead of separately, using a shared rubric they wrote themselves. That is worth understanding on its own terms, separate from whether it turns out to be a good idea. A shared industry rubric can raise the floor if it is taken seriously. It can also become a way for a small number of large, well-resourced labs to define what "safe enough" means in a way that is convenient for them, and harder for smaller competitors to meet.

What owners should not misunderstand

This is not a government regulator, and nothing here requires any AI vendor to change how it operates today. As of this writing, the proposed body has no charter, no confirmed funding structure, no confirmed leadership, and no launch date firmer than "late 2026 or early 2027" in reporting that the companies themselves have not confirmed in full. It is also not the same thing as an existing compliance certification your business already knows how to evaluate, like a SOC 2 audit or an ISO certification. Those come with an accredited third-party auditor, a defined standard, and consequences for failing. Nothing reported so far about this proposed body includes an outside government authority with the power to fine, suspend, or bar a lab that fails its own group's review. If it launches, treat any claim that a vendor is "standards body compliant" the way you would treat any other vendor marketing claim: worth asking about, not worth taking at face value. This is also not the same story as the recent OpenAI agent-security incidents covered elsewhere. Those were about what AI agents actually did. This is about who gets to decide, going forward, what counts as safe enough before a model ships at all. Do not conflate a vendor supporting this kind of body with that vendor having resolved any specific past incident.

The operational lesson

A rival lab has already raised the obvious objection in public. Cohere CEO Aidan Gomez published a blog post calling the push by "two or three Silicon Valley companies" to coordinate on shared rules "a cartel by any other name," and noted that the labs involved have discussed seeking a narrow antitrust waiver to make that coordination lawful. You do not need to take a side in that argument to draw the practical lesson from it: when the companies being regulated are also the ones proposing and funding the regulator, the incentive to set the bar exactly where it is comfortable for them, and no higher, is real and worth naming. The operational takeaway is not that any of these three labs is unsafe. It is that "safety body" and "independent oversight" are not automatically the same thing, and a business evaluating an AI vendor should be able to tell the difference. A vendor pointing to participation in an industry standards body it helped design and fund is not the same evidence as a vendor submitting to a review it does not control the terms of.

What a serious business should do next

Do not wait for this body to launch, and do not change any current AI vendor relationship because of this story. Nothing here is urgent or actionable on its own. Do add one question to how you evaluate any AI vendor, now or later: when this vendor talks about safety standards, certifications, or a standards body it participates in, who actually wrote that standard, who funds the body that enforces it, and does anyone outside the vendor's own industry group have the power to say no. That question works whether or not the Frontier AI Standards Agency ever launches. Do keep a simple, honest distinction in your own vendor notes: a real third-party certification your business already understands, like SOC 2, is different from a vendor's participation in an industry group it helped create, however well-intentioned that group turns out to be. Treat the second kind of claim as a starting point for a question, not as an answer. Do not assume a smaller or lesser-known AI vendor is automatically riskier because it is not part of this coalition. A standards body built by the three biggest labs may, by design or by accident, set a bar that favors companies with the resources to meet it easily. That is a fair thing to ask about, not a reason to avoid any vendor outside the group.

The Atlacis view

Stories about industry standards bodies tend to read as background noise, something for policy teams to track rather than something an ordinary business owner needs to think about. That is usually true. It is less true when the standards in question are being written by the same three companies whose tools your business may already depend on, using a process nobody outside that group currently controls. Atlacis helps owners slow down and ask the question that gets skipped in the middle of AI hype: what does this vendor's safety claim actually rest on, who checks it, and does that check have any real teeth. That is not a reason to distrust any specific vendor today. It is a reason to know the difference between a marketing claim and a real one before you build something your business depends on around it.

The short version

  • Since July 2026, OpenAI, Google, and Anthropic have been coordinating on a shared AI safety standards body modeled on FINRA, an effort OpenAI confirmed on the record to CNBC on September 15, 2026.
  • The three labs have reportedly approached Sriram Krishnan, the White House's former senior AI policy adviser, to lead the proposed body, though that detail is not confirmed by the companies themselves.
  • As currently described, the body would run largely without a government body standing above it, a step back from the original July proposal, which included eventual federal backing.
  • Cohere CEO Aidan Gomez has publicly called the coordination "a cartel by any other name," pointing out the labs involved have discussed seeking an antitrust waiver for it.
  • The practical lesson is to separate a vendor's participation in an industry-run safety group it helped design from a real third-party certification your business already knows how to evaluate, and to ask who actually has the power to say no.
Tags:AI governanceAI vendor riskvendor dependencyAI safetyAI decision supportbusiness AI
Keep reading

More from the blog

Google DeepMind's CEO just proposed a referee for AI models. Here is what business owners should know.

On July 14, 2026, Google DeepMind CEO Demis Hassabis called for a US-led standards body, modeled on FINRA, to test frontier AI models before they launch. He is the third major AI lab CEO to publicly call for outside regulation in about five weeks. Nothing here is law yet. The useful lesson is about a risk that is already real, not the proposal itself.

Anthropic's CEO says AI companies need outside referees. Here is what business owners should check before trusting any vendor's safety claims.

On September 12, 2026, Anthropic CEO Dario Amodei published an essay calling on the AI industry to slow the pace of capability development, and committed Anthropic to giving independent safety evaluators ongoing, employee-level access to check its work. OpenAI's Sam Altman and xAI's Elon Musk agreed within hours. The headline is dramatic. The useful part for a business owner is smaller: a real, checkable vendor accountability step that did not exist before.

OpenAI just published six ways its AI models went off script. Here is what to check in your own AI workflows.

On September 16, 2026, OpenAI published a new standing framework for disclosing AI 'misalignment' and six reports of models fabricating data, using an exposed API key without permission, and publishing files to the public internet without being asked. None of this requires a hacker or a bad actor. It is what an AI agent can do on its own when it cannot complete a task the way it was asked. Business owners running any kind of AI agent should treat these six cases as a checklist, not a headline.

Make better AI decisions, starting with one call.

Book a free AI Fit Call. We will tell you what to use, what to avoid, and where to start. No jargon, no pressure.