Google, OpenAI, and Anthropic Push for an AI Safety Self-Regulatory Body, Raising Independence Concerns

Google, OpenAI, and Anthropic are jointly advancing a new self-regulatory body for frontier AI safety, tentatively named the Standards Authority for Frontier AI (SAFA), with a target launch in late 2026 or early 2027. The effort raises questions about independence and enforcement as it proceeds without government regulatory involvement.

According to Bloomberg and CNBC on September 15, 2026, Google, OpenAI, and Anthropic are jointly advancing the creation of an industry standards body focused on frontier AI safety, tentatively named the "Standards Authority for Frontier AI" (SAFA), with a target launch in late 2026 or early 2027. This is the largest joint self-regulatory attempt by leading AI companies to date, and a proactive effort to fill the gap as a federal AI regulatory framework in the United States has yet to be enacted.

Where the Initiative Came From

The prototype of this body can be traced back to July 14, 2026. That day, Demis Hassabis, co-founder and CEO of Google DeepMind, publicly proposed the idea of establishing a "US-led frontier AI standards body," modeled on the U.S. Financial Industry Regulatory Authority (FINRA)—a public-private, industry self-regulatory structure rather than a newly created federal agency. According to reports, representatives from Anthropic, OpenAI, and Google then formed a working group under this framework, meeting regularly throughout the summer to shape the proposal.

The three companies had already collaborated before: in 2023, they jointly founded the Frontier Model Forum, but that forum achieved limited results in substantively advancing safety standards. The proposal for SAFA is, to some extent, a response to that limitation and reflects the industry's choice to step in itself after federal regulatory legislation stalled.

Institutional Design: What It Will Do, What It Won't

Based on information disclosed so far, SAFA's planned functions cover four areas: supporting third-party organizations in conducting safety testing before model deployment; establishing industry protocols for AI developers to report safety and security incidents; developing a list of voluntary safety commitments for participating organizations; and setting qualification and certification standards for independent model auditors.

The logic behind this design is to establish a binding set of industry norms without government enforcement powers by standardizing testing processes and information-disclosure requirements. According to reports, Sriram Krishnan has been approached about serving as the organization's CEO.

A key point is that the overall structure of this body involves no government regulatory involvement. Earlier, the three companies sought to establish a public-private framework, but because consensus within the AI industry was difficult to form and policy priorities shifted, federal participation has been largely shelved. SAFA is taking a fully self-regulatory route.

Impact on the Industry Landscape

For leading vendors themselves, promoting standardization is essentially a means of actively shaping the regulatory narrative. When industry leaders participate in setting standards, the standards themselves tend to lean toward their existing capabilities and deployment models—this is the deeper business logic behind the invocation of the FINRA model.

But this also directly raises concerns among the open-source community and smaller and mid-sized vendors. According to reports, some industry observers worry that SAFA could, by setting high testing or auditing thresholds, effectively shut open-source model developers and other competitors out, turning safety standards into market-access barriers.

For enterprise users, if the standards body can truly make third-party testing a routine step before deployment, it will reduce the information cost of assessing vendors' safety claims. Currently, AI vendors' self-reported safety claims lack comparable benchmarks, and enterprises cannot independently assess them. A unified testing framework and incident-reporting system could, in theory, change this situation.

For regulators, SAFA's emergence is a complex signal. A self-regulatory body can serve as an effective complement to government regulation, or it can become a political firewall blocking mandatory legislation. Historically, Wall Street's self-regulatory bodies long played both roles.

Comparison with Its Predecessor: The Leap from Forum to Body

The Frontier Model Forum, established in 2023, is a useful reference point. At the time, OpenAI, Google, Microsoft, and Anthropic were also co-founders, pledging to conduct AI safety research and share risk information. However, three years later, the forum has left a rather limited mark in advancing actionable safety standards: it has neither formed quantifiable testing benchmarks nor established an incident-reporting system that members must follow.

SAFA clearly intends to upgrade the institutional design—moving from "advocacy consensus" to an "operating entity," introducing a CEO position and an auditor qualification and certification mechanism. But a report by Superpower Daily points out that a key question remains unresolved: who will actually conduct the assessments, and how will assessment results bind participants? In currently public information, these two responsibilities have not yet been assigned to any specific mechanism.

Forward-Looking Assessment

Whether SAFA can build genuine credibility depends not on whether the organization is established, but on whether it can achieve the following two things in operation.

First, whether the process of setting testing standards opens substantive participation to organizations other than Google, OpenAI, and Anthropic, rather than being merely formalistic. If the initial members are the rule-makers, independence is hollow from the start.

Second, whether the incident-reporting mechanism has genuine enforceability. A PYMNTS report mentioned that there have recently been incidents in which AI models accessed the internet and penetrated enterprise systems, some of which were not disclosed. If SAFA's incident reporting is merely voluntary, its binding force will be extremely limited.

Whether the organization's charter includes governance seats for non-founding members, whether the selection of third-party testing organizations is openly competitive, and whether the first batch of "voluntary safety commitments" comes with specific consequences for non-compliance are observable indicators to watch. Self-regulatory bodies in the technology industry are not inherently ineffective, but every effective precedent has included some form of external check: scrutiny pressure from regulators, genuine conflicts of interest among members, or publicly visible accountability mechanisms. In SAFA's current design, none of these three has yet been made concrete.