Google, OpenAI and Anthropic plan their own AI regulator
The three labs are finalizing SAFA, a self-regulatory body for frontier AI modeled on FINRA. It launches in 2027 at the earliest. Your renewal is sooner.
The companies building frontier AI are now writing the rules that will grade it. The Information reported on September 24 that Google, OpenAI and Anthropic are finalizing plans for an industry-run standards body, tentatively named the Standards Authority for Frontier AI — SAFA. It would set risk assessment, testing and pre-release review practices for frontier models, and it would do so without any government sitting at the table. Target launch is late 2026 or early 2027. If you buy model capacity, this is a procurement story, not a policy story.
What actually happened
Three labs, one self-regulator. Per the reporting, SAFA is modeled on FINRA — the securities industry's self-regulatory organization — which is a precise choice. FINRA writes rules its member firms follow, runs exams, and is funded by the industry it polices. It needs no act of Congress to exist, and SAFA would not either.
The scope under discussion is more specific than the usual set of AI principles: common technical evaluations, third-party pre-deployment assessments, incident reporting requirements, and qualification standards for who counts as a legitimate auditor. That last item matters more than it sounds. Whoever defines auditor qualification defines who is allowed to check the homework.
Leadership is still open. The three companies have reportedly approached Sriram Krishnan, who served as a White House AI policy adviser until June 2026, along with Arati Prabhakar, Condoleezza Rice and David Friedberg. Krishnan's stated position on exit was that there will not be "an FDA for AI." Funding would come mostly from industry, which is to say from the three founding members.
Two things are missing. SAFA has no legal authority, so its standards bind only the companies that choose to join. And it does not exist yet — the earliest credible date is next year.
Why AI governance matters for your business
The gap is the problem. Your Anthropic, OpenAI or Google contract renews on a date that is almost certainly before SAFA publishes anything. Between now and then, the only governance that applies to your AI stack is the governance you wrote into your own agreements. A standards body arriving in 2027 does not cover a model swap in November.
Ask for the artifact, not the membership. When SAFA ships, every vendor pitch deck will carry a logo. A logo is not an audit. The questions that survive: which of your models were independently assessed, by whom, at what stage — training, pre-deployment, or post-launch — and can we read the report or a summary of it? Anthropic already committed to embedded outside evaluators with publication rights, and OpenAI published its own assessment priorities in September. Those are bars you can hold every vendor to today, without waiting.
Write the terms a standards body would write, into your contract. Four clauses do most of the work for a small operator: notification windows for safety incidents that affect your deployment, advance notice before a model version is deprecated or silently swapped, a data-use commitment covering your prompts and outputs, and the right to exit without penalty if any of those change. None of that requires an industry body. It requires a redline.
Assume the standard will be set by people who benefit from it. That is not cynicism, it is how self-regulation works — sometimes well. FINRA is a real regulator with real enforcement. But its rules are written by its members, and the smallest firms live with standards calibrated for the largest. If your AI risk looks different from Google's AI risk, SAFA will not be optimizing for you.
Key takeaways
- Google, OpenAI and Anthropic are finalizing SAFA, a FINRA-style self-regulatory body for frontier AI, per reporting by The Information on September 24
- Scope under discussion: common evaluations, third-party pre-deployment assessments, incident reporting, and auditor qualification standards
- Target launch is late 2026 or early 2027; it has no legal authority and would be funded mostly by industry
- Sriram Krishnan, Arati Prabhakar, Condoleezza Rice and David Friedberg have reportedly been approached for leadership roles
- Your contract renewal will land before SAFA publishes anything — write the terms yourself
- Ask vendors for the assessment report, not the membership badge
- Four clauses to redline now: incident notification, model-deprecation notice, data-use commitment, penalty-free exit
A standards body in 2027 does not govern the model you ship on this month. We build AI systems with the vendor terms written down, the model version pinned, and a documented path off any single provider — so a governance change at your vendor is a scheduling problem, not a rebuild. See how we scope AI vendor risk or bring us your contract.
Sources: CIO, BankInfoSecurity.
- #ai-governance
- #vendor-risk
- #procurement
- #ai-safety
- #model-vendors
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
37,649 records of AI agents probing public databases
Transluce published a dataset of suspected AI agent activity going back to March. The agents weren't hacking on purpose — they were stuck. Classify your bot traffic.
Read itStrada browser automation: agents for portals with no API
Strada shipped browser automation on September 24 so AI agents can drive carrier portals that have no API — recorded once, run on live data, logged end to end.
Read it