Three of the companies building the most capable AI models in the world are reportedly planning to regulate themselves. The Information reported on 24 September that Google, OpenAI and Anthropic have agreed to set up a frontier AI standards organisation,1 which some coverage has called the Standards Authority for Frontier AI, with a launch expected by the end of this year or in early 2027.2 Worth saying plainly at the top: this is reporting, not an announcement. None of the three companies has confirmed it, there's no founding document and there's nothing to look up.
My first reaction was genuinely hopeful, and I want to be honest about why before getting to the part that gave me pause. Nobody is worse served by the current situation than a small business owner. You're asked to pick between AI tools on the strength of marketing copy, with no equivalent of a Gas Safe register or a food hygiene rating to lean on. A real standards body, with real teeth, would be one of the most useful things to happen to this market.
What it would actually do
The reported remit is narrower than "AI regulator" suggests, and more interesting for it:
- Support the third-party organisations that test models before they're released.
- Set out how developers should report safety and security incidents when they happen.
- Define what the labs' voluntary safety and security commitments actually consist of.
- Establish qualifications for independent auditors of models and of the labs themselves.
That last one is the quietly significant item. Deciding who counts as a legitimate auditor is how you decide whose word is worth anything, and right now nobody holds that pen.
AI Fit Session
Not sure where to start? Over 1 week and three 60-minute 1-to-1 sessions, we map your business, find the quick wins, and build a practical starting point specific to you.
AI Foundations
Eight weeks, one coaching session a week, seven recorded modules. By the end you'll have AI working across real areas of your business and a 90-day plan to keep building.
AI Growth
Already using AI but want to keep developing it? Each month we work on real tasks from your business together, refining what's in place and building what's next.
The July version, and the September version
This idea didn't appear from nowhere this week. Google DeepMind's chief executive Demis Hassabis proposed it publicly on 14 July,3 in an essay proposing a standards body modelled on FINRA, the American stockbroker regulator, and "modelled on a federally overseen public-private partnership or self-regulatory organisation".4 He was explicit about where it should lead: "Once the assessment protocol is shown to be effective and robust, formalisation could quickly follow, meaning that Frontier Models would be required to pass it to be deployed in the US market."4
That's a strong proposal. Government backing, and a path to models being legally barred from the market if they fail. Not a talking shop.
What's reportedly being built now leaves government out of it. According to BankInfoSecurity, "as a self-regulating organization, the planned center would not need approval from Congress or the president"2, and "the White House was meant to provide clear guidelines for this process, but the Trump administration refused to make them public"2. FINRA works because the SEC sits above it. It describes itself as "registered with the SEC" and performing its work "under the supervision of the SEC, but we are not part of the government".5 Take the government out and you haven't built a FINRA. You've built a trade association with a testing budget.
Why this reaches you eventually
You will never deal with this body directly, and it creates no obligation on a business that simply uses these tools. But its vocabulary will reach you, because that's what standards bodies produce. Within a year of anything like this launching, "independently evaluated" and "meets frontier safety standards" will start appearing on the pricing pages of software you're considering.
That's the skill worth building now, and it costs you nothing. When you meet a safety or testing claim, ask who set the standard, whether the organisation that set it is independent of the company being measured, and what actually happens to a company that fails. Those three questions separate a meaningful certification from a logo. They work on AI vendors, and they work on everyone else too.
What would tell you this is real
- It gets statutory backing, or a regulator is given authority over it. Without that, it's voluntary all the way down.
- It publishes its membership, its funding and its test results, rather than summaries of them.
- Failing an assessment has a consequence that costs the company something.
- Someone independent of the three founders is running it, and stays.
Check back at the end of the year, when it's either launched or quietly hasn't. The most telling detail will be whether the government is named anywhere in the founding documents, because that's the difference between the July proposal and whatever this becomes.
What is the Standards Authority for Frontier AI?
It is a proposed body that Google, OpenAI and Anthropic are reported to be setting up to develop common standards for assessing frontier AI models, support organisations that test models before release, define how safety incidents are reported, and set qualifications for independent auditors. The Information reported it on 24 September 2026. None of the three companies has publicly confirmed it, and a launch is expected by the end of 2026 or early 2027.
Does AI industry self-regulation affect small businesses?
Not directly, and it creates no legal obligation on a business that uses AI tools rather than builds them. The likely practical effect is on marketing language: if the body launches and begins certifying models or accrediting auditors, terms such as independently evaluated or meets safety standards will start appearing in software vendors' sales material, and buyers will need to judge what those claims are worth.
What did Demis Hassabis propose for AI regulation?
On 14 July 2026 the Google DeepMind chief executive published an essay calling for a frontier AI standards body modelled on FINRA, the self-regulatory organisation that oversees American stockbrokers. He described it as modelled on a federally overseen public-private partnership or self-regulatory organisation, with funding that would likely mostly come from industry, and wrote that once the assessment protocol was shown to be effective and robust, formalisation could quickly follow, meaning frontier models would be required to pass it to be deployed in the US market.
Is self-regulation by AI companies enough?
It depends entirely on whether an outside authority sits above it. FINRA, the model cited for this proposal, describes itself as a self-regulatory organisation that is registered with the Securities and Exchange Commission and performs its work under the SEC's supervision, while not being part of the government. A body with no government oversight relies on its members choosing to comply, and on the standards being set by the same companies being measured against them.
- OpenAI, Google and Anthropic Join Forces to Set AI Safety Standards | PYMNTS
- Google, OpenAI, Anthropic Plan Frontier AI Standards Body | BankInfoSecurity
- DeepMind CEO calls for an independent standards body to regulate frontier AI | TechCrunch
- A Framework for Frontier AI and the Dawning of a New Age | Demis Hassabis
- About FINRA | FINRA