Regulation5 minNewsroom

Google, OpenAI, Anthropic plan self-regulation, report says

According to The Information, the three companies agreed to create a safety standards body without US government oversight and approached Sriram Krishnan and Arati Prabhakar for leadership.

Lago Shoreline em Mountain View com ciclovia e telhados baixos ao fundo.

Google, OpenAI, and Anthropic have agreed to establish their own entity to set safety standards for frontier models, provisionally called the Standards Authority for Frontier AI, according to a report from The Information published on Thursday (24). The entity could begin operations by the end of this year or early 2027, functioning without oversight from the US government.

None of the three companies had publicly confirmed the plan by the time this report went to press.

Who was considered for leadership

According to the report, the three companies sought candidates with opposing profiles for leadership. Sriram Krishnan, who served as AI advisor to the White House during the Trump administration until June 2026, and Arati Prabhakar, who led science and technology policy in the Biden administration, were considered for the CEO position. For the chairmanship, names like Condoleezza Rice, Secretary of State under George W. Bush, and investor David Friedberg were included in the list.

The described scope is operational: to support independent organizations testing models before launch, define how developers should report security incidents, consolidate companies' voluntary commitments, and establish qualifications for independent auditors of models and labs.

From FINRA oversight to a regulator-free club

The idea has a known origin. In an essay published on July 14, Demis Hassabis, CEO of Google DeepMind, proposed an industry-funded standards body similar to FINRA, the self-regulatory organization for American brokers, with federal oversight. Representatives from the three companies then formed a working group and met throughout the summer, according to the report.

Federal oversight fell by the wayside. The Wall Street Journal published on September 16 that Mark Zuckerberg, Elon Musk, and Jensen Huang had separately spoken with Donald Trump the previous month and persuaded him to abandon the model involving government participation. What remains now is a version without the regulator: the companies write the rules, fund the entity, and choose who leads it.

The most obvious objection has already surfaced. Critics quoted in the coverage argue that the body could be used by the three companies to eliminate competition from smaller developers and rivals, who would have to comply with standards defined by market leaders. The defense of the model is that FINRA has operated for decades precisely because those who understand the product write the technical rules, and that a common testing standard is better than none.

The contrast with New York, Brussels, and Beijing

The news came out a day after Sam Altman and Dario Amodei spoke at the UN Security Council on Wednesday (23). Altman advocated for countries to develop common standards to test what the models can do and whether the safeguards work. Amodei proposed tight global agreements, including a ban on the use of AI for biological weapons, verification systems between countries, and an incident notification mechanism. In the United States, the practical response to this speech is a private entity.

In the European Union, the path is different. The AI Act has already imposed obligations on providers of general-purpose models since August 2025, with oversight from the AI Office of the European Commission. A private American standard does not replace these obligations but may become the technical reference that companies take to Brussels to demonstrate compliance.

In China, the Cyberspace Administration (CAC) operates in the opposite manner, requiring prior registration of algorithms with the state and periodic oversight campaigns of AI applications throughout 2026. The result is that, for the same model, security testing now has three distinct arbiters with incompatible logics.

What this means for AI buyers

For CIOs and CISOs, the immediate consequence is contractual. If the entity is realized, the pre-launch testing reports and incident notifications that it standardizes will become contract attachments and supplier questionnaire items, similar to what happened with SOC 2 certifications in the cloud. Those purchasing models from Meta, xAI, Mistral, or Chinese labs will want to know why these suppliers do not comply.

This is the point still needing resolution. Meta, xAI, and Nvidia, whose leaders dismantled the version with federal oversight, are not among the founding companies described. A security standard that covers three labs while excluding one of the largest developers of open models in the US measures the conduct of those who joined, not the wider market.

Sources

  1. theinformation.comhttps://www.theinformation.com/articles/google-openai-anthropic-ai-safety-group-takes-shape
  2. bankinfosecurity.comhttps://www.bankinfosecurity.com/google-openai-anthropic-plan-frontier-ai-standards-body-a-32926
  3. yahoo.comhttps://www.yahoo.com/news/politics/articles/google-openai-anthropic-move-closer-154300474.html
  4. thestreet.comhttps://www.thestreet.com/technology/zuckerberg-musk-huang-ai-regulator
  5. cnn.comhttps://www.cnn.com/2026/09/23/tech/altman-amodei-ai-safety-un-security-council

The week's analysis, by email

One weekly edition with what matters to people who decide. No ads, no sponsorship.

One-click cancellation, at any time.

Regulation →