Public chatter around AI safety usually revolves around government oversight and slowing down frontier model development, but the interesting movement is now happening off the record.
Anthropic, OpenAI and Google DeepMind have been meeting in private working groups since July, to explore a self-regulatory body dedicated to safety auditing and pre-release testing for high-capability models. The initiative lacks a formal charter, press release or finalised governance setup. Instead, it shows the leading parties in AI discreetly attempting to design a common safety playbook on their own terms.
The working group is keeping its sights on a narrow set of operational rules. Rather than hammering out broad industry policy, the talks cover third-party evaluations before release, formal safety checks and unified risk protocols for cyber attacks, bioweapons risks and deceptive behaviour. It functions as a voluntary, lab-funded auditing system for frontier models, an arrangement that could start as a flexible agreement and eventually mature into an industry standard.
This move has clear roots. In July, Google DeepMind leader Demis Hassabis outlined a plan modelled on FINRA, proposing an industry-financed, federally monitored body staffed by independent experts to conduct pre-release evaluations about 30 days out. The ongoing working groups show those ideas gaining traction. Anthropic chief Dario Amodei built on the momentum in a recent essay, pushing for aligned benchmarks and official antitrust protection for safety-related coordination.
Navigating those regulatory boundaries is important, mostly because three direct competitors agreeing to hold back tech looks suspiciously like anti-competitive behavior to watchdogs. That danger alone explains why everyone involved wants a formal, structured standards body on paper rather than an unwritten understanding.
Complement Or Alternative To Real Regulation?
In practical terms, an industry body can establish technical criteria for frontier systems, draft evaluation rules, clear third-party auditors and shape market standards around safety cards. Where it falls down is enforcement. It has zero power to halt a launch or punish non-compliance, leaving it dependent on goodwill. The setup carries obvious risks, namely that letting giant tech companies oversee themselves creates a clear clash between corporate timelines and safety protocols.
This dynamic plays out very differently depending on the jurisdiction. Under the EU AI Act, binding laws dictate mandatory assessments, transparency requirements and government penalties. There, a voluntary body simply acts as a helpful partner, offering technical evaluation tools to meet legal requirements. In the US, where broad AI legislation doesn’t exist, that same group could easily turn into a proxy regulator, giving lawmakers a reason to skip binding laws altogether. Whether this initiative becomes a genuine safeguard or a clever shield against regulation depends on how much authority Washington decides to hand over.
Given how often corporate self-policing falls short in other markets, that history warrants a very close look. We posed the issue to insiders across AI safety, regulation and enterprise tech: what would an industry-driven standards body need to feature to hold real authority, and does joint oversight between three main competitors offer authentic safety or just a convenient way to derail tougher laws before they land?
More from News
- How Have Digital Nomads Created A New Market For Businesses?
- England’s New Tourist Tax Has No National Cap – What Does That Mean For Hospitality Businesses?
- The EU Cyber Resilience Act Starts Today: Can Businesses Really Report A Cyberattack In 24 Hours?
- Can Binge-Watching Be Addictive By Design? Inside The State Lawsuit Against Netflix
- Could Australia’s Proposed Algorithm Rule Break The Current Echo Chamber That Is Social Media Today?
- PASS Announces Schedule Hero: AI-Powered Scheduling Built For Home Care
- Portal26 Launches Recon: Ask Any Plain Language Question To Deliver Immediate, Actionable Answers To Any Question About AI Use In The Enterprise
- When AI Goes AWOL: What Should We Conclude From ChatGPT, Claude And Grok’s Simultaneous Outage?
Our Experts
- Lakshmi Hanspal, Chief Trust Officer, DigiCert
- Emily Hartstone, Founder, Hartstone Institute LLC
- Kirk Sigmon, Founding Partner, KellDann Law PLLC
- Sherif Higazy, Founder and CEO, Megaton AI
- NagaPranitha Chodavarapu, Senior Lead QMS, Insulet Corporation
Lakshmi Hanspal, Chief Trust Officer, DigiCert

“What could this body actually set rules for? Greater success towards shared technical basics: common tests before releasing a new model, agreed ways to check if a model could be dangerous, and a standard way to report problems when they come up.
“Why team up now? Partly safety concern. But also self-interest: if the big players set the rules themselves, they get ahead of governments doing it for them, and rules they write could end up favouring the companies that helped write them.
“Does this support the EU AI Act, or try to avoid it? In practice, likely a hedge, an attempt to demonstrate credible self-governance before harder regulation lands, particularly in the US.
“What would make this actually work, like IETF or CAB Forum did? Three things, from experience: independent audit that isn’t self-graded, real consequences for non-compliance, not just reputational, and governance open beyond the founding members. CAB Forum works because no single browser or certificate authority can unilaterally rewrite the baseline. Right now, this AI effort has none of those guardrails yet. That’s the gap to watch.”
Emily Hartstone, Founder, Hartstone Institute LLC

“Three labs cooperating on standards is more interesting for what it wouldn’t cover than for what it would. A body like this can realistically set model-layer standards: evaluation methods, safety benchmarks, disclosure practices, incident reporting between labs. Those are useful, and only the labs can do them, because nobody else has the access.
“What it cannot set is what happens at deployment. The model isn’t where people get denied, scored or flagged. That happens inside an enterprise, configured by an operator the lab never meets, acting on a person who never chose either of them. Look at Microsoft’s Code of Conduct, published this week and open for consultation. It’s the most concrete document of its kind, and every obligation in it terminates at the operator or the user. The person the model acts upon appears only once, as an affected third party who shouldn’t be directly harmed. That’s protection, not standing.
“So my answer on whether it complements or replaces regulation is neither. It occupies a different layer. The risk isn’t that it pre-empts the EU AI Act. It’s that it looks like coverage while leaving the deployment layer untouched, and then everyone points at it. Why now is simpler. After this summer’s agent incidents, shared incident reporting is in all three companies’ interest, and a standards body is a reasonable way to build it.”
Kirk Sigmon, Founding Partner, KellDann Law PLLC

“An industry-led body for AI governance is a nice idea and a good development, but it won’t likely change many of the issues regulators are concerned about. Realistically speaking, such standards would be opt-in and thus wouldn’t really stop third parties from using their own models, including locally-executing ones, to circumvent those regulations. It’s also unlikely that any of those parties would agree to regulations with enough teeth to significantly affect their bottom line. That self-regulating body may calm regulators’ concerns somewhat, but I still suspect various jurisdictions will legislate where necessary to protect the public against major concerns, like deepfakes or failure to disclose AI usage in certain medical decisions.
“Plenty of other industries have self-regulated successfully. The video games industry’s ESRB helped avoid Congressional regulation of video games after a scare regarding violent video games. That said, the success of those efforts is often not just the product of regulatory fear: the ESRB was in many ways successful because the vast majority of commercially sold video games went through a relatively small number of publishers who all shared an interest in avoiding regulation, and because video game console manufacturers, of which there were even fewer, could help push forward its use. I don’t see similar dynamics in the AI industry, where there may be relatively few major players but where the underlying technology can be run by virtually anyone with a sufficiently powerful computer.”
Sherif Higazy, Founder and CEO, Megaton AI

“The Trump Administration’s position has been a light touch to regulation, and instead has signalled a preference for a self-regulating body, lest government intervention slow down the US’s AI lead. At the same time, the AI companies have signalled quite strongly that they would welcome some industry and government regulation in the US, which remains the primary market for frontier labs outside of China.
“Two things this body could accomplish. First, sharing and working together on alignment: how to ensure AI systems align with human goals, and how to interpret what an AI system ‘thinks’ and ‘does’ without hiding it from researchers. Second, slowing down and pacing model releases to allow companies to harden their cybersecurity and biosecurity infrastructure.”
NagaPranitha Chodavarapu, Senior Lead QMS, Insulet Corporation

“I can’t speak to what Anthropic, OpenAI and Google are actually planning, but with 13-plus years working in governance, risk and compliance across medical devices, pharmaceutical and biotechnology industries, I’ve watched something pretty similar play out in a different regulated industry, and it might be useful context here.
“Our field’s main professional body, ISPE, published an AI governance guide back in July 2025. Six months later, the FDA and EMA published their joint AI principles. I work right at that overlap, and I’ve built a framework for how AI tools should actually be governed inside regulated validation work, currently going through peer review with that same industry body.
“What stood out to me is that the industry guidance didn’t show up first and try to get ahead of regulators. It came out alongside them, and it’s stayed deferential. FDA enforcement has continued regardless of the industry framework existing. What the industry body actually did well was the unglamorous part: translating a broad regulatory principle into something a company can actually follow in daily operations. If this AI standards body works the same way, filling in the practical gaps around something like the EU AI Act, that’s a model with a real track record. What I’d watch for is how the industry actually handles it in practice.”
