SAFA vs Frontier Act vs EU AI Act vs California EO: Who Regulates AI?
The short answer
Four regimes are competing to govern frontier AI as of September 2026, and only two of them can compel anything. The EU AI Act is binding law with GPAI obligations in force. California’s Executive Order N-9-26 imposes kill-switch requirements on models deployed in state. The Frontier Act (HR 9925) would mandate third-party audits but is still a bill. SAFA — the Standards Authority for Frontier AI reported on September 24-25, 2026 — would be industry-funded, industry-governed, and has no described enforcement power. Meanwhile the FTC is applying existing consumer protection law to deployers without waiting for any of them.
Side by side
| SAFA | Frontier Act (HR 9925) | EU AI Act | California EO N-9-26 | |
|---|---|---|---|---|
| Type | Industry self-regulation | US federal bill | Binding EU law | State executive order |
| Status (Sep 2026) | Reported, unconfirmed | Not enacted | In force | In force |
| Backers | Google, OpenAI, Anthropic | Congress | EU institutions | California governor |
| Funded by | Member labs | Taxpayer | Taxpayer | Taxpayer |
| Core mechanism | Standards + evaluation | Third-party audits | Risk tiers + GPAI obligations | Kill-switch requirement |
| Can compel disclosure | Not reported | Yes, if enacted | Yes | Yes, in scope |
| Can block deployment | Not reported | Yes, if enacted | Yes | Yes, in state |
| Penalties | None described | Statutory, if enacted | Up to % of global turnover | State enforcement |
| Applies to deployers | Unclear | Frontier developers | Yes | Model deployment |
| Geographic reach | Member labs | US | Extraterritorial (EU market) | California |
| Target launch | Late 2026 / early 2027 | Unknown | Phased, live | Live |
The honest ranking by teeth
1. EU AI Act. It is law, it is extraterritorial, and the penalties are a percentage of global turnover. If you put a system on the EU market you are in scope regardless of where you incorporate. It also reaches deployers, not just model providers, which is why it is the regime most likely to affect a company that merely builds on APIs.
2. California EO N-9-26. An executive order is weaker than statute and faster to issue. The kill-switch requirement is narrow but concrete, and California’s market position means compliance tends to become the national default. See what the California AI kill switch executive order requires.
3. FTC enforcement under existing law. Not a new regime at all, which is the point. Chairman Ferguson’s late-September 2026 position — that developers and instructing parties bear liability, and that existing product liability and consumer protection law should be tested before new AI statutes — means enforcement can start tomorrow under authorities that already exist. For most companies this is the nearest-term legal exposure, and it lands on deployers.
4. Frontier Act (HR 9925). Real teeth if enacted — mandatory third-party audits would restructure the evaluation market — but it is a bill. See the Frontier Act explained.
5. SAFA. Last, because as of September 26, 2026 it does not exist, has not been confirmed by any of the three companies, and no enforcement mechanism has been described. See what SAFA is.
What SAFA is actually for
Reading SAFA as a safety mechanism misreads it. Read as a positioning move it makes immediate sense.
The industry faces the Frontier Act’s audit mandate, the Sanders-Casar Ban Artificial Superintelligence Act with penalties framed against unlawful nuclear weapons development, California’s kill-switch order, and EU obligations already biting. A voluntary standards body launched before binding rules arrive does three useful things for its members: it produces a technical vocabulary that later legislation tends to adopt, it gives legislators an off-ramp (“industry is handling it”), and it sets a floor so that one lab’s caution — Anthropic’s “pace the frontier” position, for instance — does not become a unilateral competitive penalty.
That is not cynical, exactly. Industry standards bodies have produced real safety outcomes in aviation and finance. But they did it with statutory backing and independent funding, and SAFA as reported has neither.
The four tests
Whether SAFA becomes FINRA or becomes the Frontier Model Forum depends on four things visible in its launch documents:
- Board independence — is a majority not employed by member labs, with fixed terms?
- Failure publication — can it publish an evaluation a member fails, over that member’s objection?
- Pre-deployment access — does it see models before release, on the UK AISI model?
- Funding durability — endowment or committed multi-year money a member cannot withdraw as leverage?
A fifth: membership breadth. A body covering Google, OpenAI and Anthropic but not xAI, Meta, Mistral, DeepSeek, Alibaba or Xiaomi covers a shrinking slice of frontier-adjacent capability. The open-weight tier reached 46 on the Artificial Analysis Intelligence Index in September 2026 with Xiaomi’s MiMo-V2.6-Pro, and an Apache-2.0 agentic model that runs on one consumer GPU shipped the same week. Standards that only bind three American labs do not bind the capability frontier.
What to do, by role
If you train frontier models: all four matter, in the order above. Engage with SAFA’s formation if invited, because the standards written now become the statutory language later.
If you build products on AI APIs: the EU AI Act deployer obligations and FTC enforcement are your real exposure. SAFA and the Frontier Act reach you only as vendor attestations. Do not let a future SAFA certification substitute for your own controls — Ferguson’s hammer analogy cuts directly at the “our vendor was certified” defense.
If you procure AI: write your own eval and incident-disclosure requirements into contracts now. Every regime above is either unsettled or under-enforced, and contract terms are the only instrument you control. Ask specifically about agent egress boundaries and credential handling, which is where September 2026’s incidents concentrated — see how to give AI agents credentials without leaking them.
If you are forecasting policy: watch the Frontier Act’s committee progress. Its fate determines whether SAFA is the governing layer or a compliance vendor underneath a statutory one.
Decision rule
- Binding today: EU AI Act, California EO N-9-26, existing FTC authority.
- Binding if enacted: Frontier Act.
- Not binding, possibly influential: SAFA.
- Applies to you as a builder rather than a lab: EU AI Act deployer duties and FTC deployer liability. Those two, first, before anything in the news cycle.
Last verified: September 26, 2026. SAFA remains unconfirmed by Google, OpenAI or Anthropic; all details are sourced to press reporting of The Information’s September 24, 2026 story.
Sources
- Google, OpenAI, Anthropic Plan Frontier AI Standards Body — BankInfoSecurity, September 24, 2026
- Google, OpenAI, Anthropic Reportedly Plan AI Safety Standards Body — TechRepublic, September 25, 2026
- FTC Chair pushes back on treating AI agents as independent actors — MarketScreener, September 2026
- FTC Chairman Ferguson rejects idea of AI agents acting on their own — Unite.AI, September 2026