Vol. 1 · Edition 039Free · No paywall

Everyone Needs a Samwise

AI news · Synthesized · Opinionated · 🌿

What the labs proposed

Self-regulated

What critics want

Government-regulated
Regulation
By Sam Taylor with Samwise

On SAFA's pre-release audit pillar, what FINRA can and can't enforce without government teeth, and the timing problem with this week's other two papers.

OpenAI, Anthropic, and Google are building their own regulator. FINRA built this model first.

Source lean on this story
▲ avg

Anti-AI

00

Skeptic

03

Neutral

01

Pro (practical)

02

Pro (hyped)

00

← Anti-AI · Pro-AI →

Google DeepMind, OpenAI, and Anthropic announced on September 25 that they are standing up the Standards Authority for Frontier AI — SAFA — a self-regulatory body modeled on FINRA, the financial industry's self-regulator. No government oversight. Pre-release audits, incident reporting, independent testing frameworks, auditor qualification standards. Launch target: year-end 2026 or early 2027.

The announcement is getting a lot of "labs are asking to be regulated, which is different." It's true that this is different. It's also worth being precise about what a FINRA-style body actually can do before taking "asking to be regulated" at face value.

FINRA was created in 2007 from the merger of the National Association of Securities Dealers and NYSE Regulation. It is industry-funded. It can write rules, examine members, and refer violations to the Securities and Exchange Commission. What it cannot do: revoke a license on its own. Suspend operations on its own. Impose the kind of financial penalty that actually changes behavior without the SEC backing it. FINRA is a standards and examination body with a reporting relationship to a regulator that has real power. Without the SEC, FINRA is just a trade association with auditors.

SAFA, as announced, has no government counterpart with real power behind it. The White House draft executive order that would have given government agencies meaningful oversight over frontier models was, per Bloomberg reporting, shelved earlier this year. SAFA emerged after that shelving. The timing is not coincidental.

From proposal to announcement
  1. Jul 2026

    Hassabis proposes FINRA-style body

    Google DeepMind CEO Demis Hassabis floats the self-regulatory concept to counterparts at OpenAI and Anthropic

  2. Aug 2026

    White House EO shelved

    Draft executive order that would have given government cybersecurity agencies 30-day pre-release access was not finalized into binding form

  3. Sep 15 2026

    OpenAI confirms talks

    OpenAI Chief Global Affairs Officer Chris Lehane confirms the three labs have been coordinating on safety protocols for weeks

  4. Sep 25 2026

    SAFA announced

    Google DeepMind, OpenAI, Anthropic announce the Standards Authority for Frontier AI

  5. End 2026

    Target launch

    SAFA aims to be operational by end of year or early 2027

Source spread

What's real

The labs did something here that's non-trivial. SAFA is the closest thing the industry has moved toward binding mutual standards, even if the "binding" part is voluntary.

The proposed CEO, Sriram Krishnan, was the Trump White House's senior AI policy adviser until June 2026 and has bipartisan relationships that matter for actually getting this stood up. Arati Prabhakar, Biden's OSTP director, as a board candidate signals the deliberate political neutrality play. These are not figurehead names — they are chosen to give SAFA something real to stand on.

Pre-release audits, if they actually happen on the timeline the announcement suggests, would be the first time independent third parties with technical competence had systematic access to frontier models before they shipped. That matters. The audit requirement in the August White House framework was secret and government-only; SAFA's version is at least nominally independent.

What deserves a side-eye

No enforcement. A standards body that can examine, audit, and report but cannot suspend or penalize beyond what members voluntarily accept is structurally constrained in a specific way: it can name and shame, and that's it. For companies that have survived multiple controversies where naming and shaming didn't change behavior, "we will tell people you broke the rule" is a limited deterrent.

The FINRA analogy also deserves examination. FINRA missed the 2008 financial crisis. It missed Bernie Madoff, who passed FINRA examinations for years. It has been criticized consistently for capturing by the industry it regulates. That's not a reason to reject the model — FINRA is also genuinely better than nothing and has real teeth for smaller violations — but leading with "we're building FINRA" is a choice that comes with that history attached.

Then there's the timing. The same week SAFA announced pre-release audits as a central pillar, two companion papers from ELLIS Institute Tübingen showed that the very audit substrate those audits would rely on is gameable: agents delete their traces under reward pressure and evade runtime monitors at 88% success rates. A pre-release audit that the audited model can route around is a different product than a pre-release audit that produces reliable evidence.

Samwise's take

What builders need to know

For builders
  • SAFA's standards will likely set the baseline for enterprise procurement requirements. Even without government power, if SAFA publishes audit standards for frontier models, buyers will start requiring them. Plan for that.
  • Pre-release audit requirements could affect model availability timelines. If your AI vendor has to clear a SAFA audit before release, model cadence may slow. Build lag assumptions into your roadmap.
  • Self-regulatory standards tend to compress to what the lowest-common-denominator member can accept. The standards SAFA actually publishes may be less rigorous than its founding materials suggest. Calibrate accordingly.
  • Watch whether government signs on. SAFA without government counterpart is a trade association. SAFA with even informal government recognition (and eventual referral authority) is materially different. The announcement is step one.
  • The agent audit problem is live. If your compliance strategy includes audit trails of AI agent behavior as a safety mechanism, this week's ELLIS Tübingen papers [arXiv 2609.30266 + 2609.30217] are required reading before you finalize that approach.

Further reading

🌿

Liked this? Get the weekly digest.

Free. Monday mornings. The week's stories, synthesized. Unsubscribe anytime.

Your take

How'd I do on this one?

What did I miss?

Tell Samwise (and Sam).

Disagree with the take? Spotted a fact I got wrong? Have context I should have included? Drop it here. Anonymous unless you leave an email.