When federal AI safety talks stall, frontier labs write their own rulebook. The Information reported September 23-24, 2026 that OpenAI, Google, and Anthropic are advancing a private standards organization — tentatively SAFA, the Standards Authority for Frontier AI — to define how frontier models get tested, audited, and incident-reported without government oversight.
For developers, SAFA is not a product launch. It is a signal about what evidence enterprises will demand before they trust the next GPT, Gemini, or Claude major release.
If SAFA launches with teeth — auditor lists, incident templates, optional pre-deploy tests — it becomes the lowest-friction pack you can attach to security reviews. If it launches as press release only, buyers will keep inventing bespoke red-team asks per RFP. The September reporting points toward the former, but nothing is filed or published yet.
TL;DR: SAFA vs Washington
| Question | Answer |
|---|---|
| Name (tentative) | Standards Authority for Frontier AI (SAFA) |
| Members (reported) | OpenAI, Google, Anthropic |
| Timing | Late 2026 or early 2027, per reporting |
| Trigger | Public-private safety partnership stalled in DC |
| Scope | Pre-deploy tests, auditor rules, incident reporting |
| Leadership | Discussed, not announced (Krishnan, Prabhakar, Rice, Friedberg named in press) |
| Related group | Frontier Model Forum (2023), may coordinate |
| Builder impact | More standardized eval artifacts for procurement |
What reporting says SAFA would do
PYMNTS and The Information summaries list four pillars:
- Support third-party testers before models ship broadly.
- Define how labs report safety and security incidents.
- Spell out voluntary commitments frontier developers would sign.
- Set qualifications for independent auditors of models and labs.
Working-group discussions reportedly include having the body run its own capability and safety tests, not just bless external ones. That would make SAFA closer to a rating agency than a trade association — if independence holds.
OpenAI's public line remains dual: voluntary standards with or without government, plus advocacy for mandatory US safety requirements in parallel — a hedge visible in its September UN Security Council blog post cited by PYMNTS.
Timeline: from Frontier Model Forum to SAFA
| Era | Body / event | Developer relevance |
|---|---|---|
| 2023 | Frontier Model Forum (Anthropic, Google, OpenAI, Microsoft) | Research papers, shared safety themes |
| 2024–2025 | METR-style third-party evals, enterprise red teams | Ad hoc buyer demands |
| June 2026 | US EO rhetoric; public-private safety talks | Hoped-for federal + lab partnership |
| Sept 2026 | Trump rejects new slowdown rules; US-first access fights | Labs seek non-legislative credibility |
| Sept 23–24 2026 | The Information: SAFA planning | Possible auditor + incident standardization |
| Sept 2026 | Oslo group (22 leaders) pushes stronger supervision | International pressure outside SAFA |
| Late 2026 / early 2027 | Reported SAFA launch window | Watch for published commitments |
SAFA is best read as FMF’s operational cousin — less “what should research study?” and more “what must we show before ship?”
SAFA vs FMF vs government review (three lanes)
| Lane | Who runs it | Typical artifact | Binding force |
|---|---|---|---|
| SAFA (reported) | OpenAI, Google, Anthropic-led private body | Auditor quals, incident forms, voluntary tests | Contractual / reputational |
| Frontier Model Forum | Multi-lab forum + Microsoft | Research, methodology critiques | Informative |
| US government review | ONCD / executive branch asks | Pre-release access, US-first queues | Policy + market access |
| Your enterprise | Security and legal | SOC2, internal red team, harness logs | What actually gates your ship |
Smart teams do not wait for SAFA PDFs. They build harness archives now so when SAFA (or a buyer) asks for evidence, you paste reproducible runs — the same discipline as loop engineering for coding agents.
What a SAFA-style audit might actually test
Reporting is high-level; below is a plausible scope if SAFA mirrors other standards bodies — use it to prep internal checklists, not as leaked requirements.
| Category | Example tests | Why procurement cares |
|---|---|---|
| Capability | Agentic tool use, multi-step planning, coding | Regression on “autonomy” claims |
| Misuse | CBRN-adjacent prompts, cyber exploit assistance | Insurance and gov’t questionnaires |
| Deception | Evaluator-aware behavior, hidden tool calls | Ties to METR deception work |
| Data exfil | RAG boundary tests, prompt injection to leak context | Enterprise data handling |
| Robustness | Jailbreak suites, multilingual abuse | Brand safety |
| Incident process | Timelines, customer notification templates | Post-Medicare-breach expectations |
If SAFA publishes named auditor lists, treat them like SOC2 firms — early adopters will pay premium; laggards will scramble before renewals.
Oslo 22 vs Washington: labs caught in the middle
The same week SAFA leaked, 22 world leaders backed a Norwegian-led statement urging stronger international supervision of the most powerful models. That is the external pressure track: multilateral rhetoric, potential treaty language, ally expectations.
Inside the US, President Trump called AI risk fears a hoax and rejected new slowdown rules — the domestic pressure track: speed, China competition, America First framing.
SAFA is the labs’ attempt to thread the needle: offer allies something concrete to cite (standards, incidents, auditors) without accepting a US licensing agency for every weights release. It runs parallel to — not instead of — US-first tester queues and anti-doom political memos aimed at Anthropic.
Capture risk and independence (honest caveats)
A body funded and founded by the three largest closed frontier labs will face immediate capture critiques — especially after agent breach headlines and while labs negotiate Washington access.
| Strength | Weakness |
|---|---|
| Fast iteration vs Congress | Founders are also subjects of audit |
| Shared formats reduce RFP friction | Weak sanctions if a member skips disclosure |
| Can harmonize tester requests | Open-weight ecosystem may reject membership |
| Signals maturity to enterprise | Opponents call it self-dealing |
Builders should use SAFA artifacts if they appear — standardized incident templates help everyone — while keeping independent harness results as the source of truth for routing decisions.
Enterprise RFP: how to reference SAFA before it exists
Until bylaws publish:
- Cite your eval methodology and dates, not SAFA press leaks.
- Ask vendors: “Will you publish SAFA commitments if launched?” and log answers in vendor records.
- Require incident notification SLAs in contracts regardless of industry body — SAFA may template language labs already accept.
- For Google launches, cross-read Demis Hassabis frontier framework — Google’s public science story may align with SAFA tests even before branding matches.
Product clocks vs standards clocks
September 29 OpenAI DevDay, Gemini 4 post-training fast track, and Claude tier updates ship on product calendars. SAFA, if real, lands on standards calendars — often quarters later.
Do not block a GA migration waiting for SAFA badges. Do archive model-version evals so when standards arrive, you can map old runs to new checklists.
Builder checklist: safety evidence you control
- Harness repo: Versioned prompts, tool mocks, and pass/fail thresholds per model ID.
- Incident runbook: Internal severity levels, customer comms, regulator contacts — draft now.
- Data flow diagram: Where prompts go for safety classifiers (OpenAI ZDR options vs default retention).
- Regional routes: Document US-first or geo-gated models separately in config.
- Research vs prod keys: Separate credentials so breach stories do not implicate your production surface.
- Anthropic-specific research: Emotion-vector and refusal studies (Anthropic emotion vectors fact-check) inform your abuse monitoring, not SAFA membership.
Why Washington stalled while Oslo pushed
The same week, 22 world leaders backed a Norwegian-led statement urging stronger international supervision of the most powerful models. Inside the US, President Trump called AI risk fears a hoax and rejected new slowdown rules, while the White House separately pushed US-first model access and circulated anti-doom political memos targeting Anthropic.
SAFA is the labs' answer to split governments: write standards industry can live with, hope allies adopt the technical pieces, and avoid a US FDA-for-AI licensing regime — a framing former White House AI adviser Sriram Krishnan used before leaving government, according to reporting on SAFA CEO discussions.
Frontier Model Forum and evaluator chaos
Anthropic, Google, OpenAI, and Microsoft created the Frontier Model Forum in 2023. It still publishes safety research — including third-party assessment methodology critiques Hassabis referenced in Google's frontier framework essay.
SAFA would not replace FMF overnight. Reporting says the groups may coordinate. For builders the distinction matters:
| Body | Likely output for you |
|---|---|
| Frontier Model Forum | Research papers, best practices |
| SAFA (if launched) | Checklists, auditor lists, incident templates |
| Your enterprise buyer | SOC2 + red-team + model-specific eval packs |
If SAFA standardizes eval packs, agent vendors can stop reinventing safety regression suites for every customer RFP.
What this means for what you build or pay
Procurement: Start archiving eval reports, incident disclosures, and auditor names per model version. When SAFA or buyers ask for proof, screenshots of leaderboard scores will not suffice — you want reproducible harness logs like those in loop engineering for coding agents.
Trust boundaries: Private standards without government oversight invite capture critiques, especially while labs face agent breach headlines. Design systems assuming models can misbehave — tool scopes, human gates on writes, and OpenAI private safety processing limits for API data.
International apps: SAFA may align with UK/EU tester demands, or conflict with US-first review. Architect region-specific model routes now.
What people are asking
Is Sriram Krishnan running SAFA?
Not confirmed. Press reports list him among CEO candidates alongside Arati Prabhakar. Until SAFA publishes bylaws, ignore org-chart rumors.
Will open-weight labs join?
Reporting centers on closed frontier labs. Small and open-model developers may get tiered rules later — watch whether SAFA grandfathers open releases or tries to gate weights.
Does SAFA help with DevDay or Connect launches?
It is background infrastructure, not a feature flag. September 29 OpenAI DevDay and ongoing Google Gemini 4 post-training (timeline) will ship on product clocks, not SAFA's.
Related on explainx.ai
- Pace the Frontier reactions
- Demis Hassabis frontier AI framework
- OpenAI private safety processing and ZDR
- OpenAI agent deception evals
- Anthropic emotion vectors and safety research
- What is MCP?
Based on The Information reporting summarized September 23-24, 2026. SAFA name, scope, and leadership remain tentative until the labs publish formally.
