What is SAFA, the Standards Authority for Frontier AI? (Sep 2026)
The short answer
SAFA — the Standards Authority for Frontier AI — is a self-regulatory body that Google, OpenAI and Anthropic are finalizing plans to launch by late 2026 or early 2027, reported by The Information on September 24, 2026. The three companies have reportedly approached Sriram Krishnan, a former White House AI policy adviser, to be its chief executive. It would set safety standards and evaluate frontier models independently of government. As of September 26, 2026, none of the three labs has published an official announcement, and no enforcement mechanism has been described.
What has actually been reported
| Detail | |
|---|---|
| Name (provisional) | Standards Authority for Frontier AI (SAFA) |
| Founding members | Google, OpenAI, Anthropic |
| First reported | The Information, September 24, 2026 |
| Reported CEO candidate | Sriram Krishnan (ex-White House AI policy adviser, ex-a16z) |
| Target launch | End of 2026 or early 2027 |
| Governance | Independent of government; industry-funded |
| Official confirmation | None as of September 26, 2026 |
| Enforcement powers | Not reported |
| Other members | Not reported (xAI, Meta, Microsoft, Mistral status unknown) |
Treat every line above as reporting, not fact from the source. The three companies have said nothing on the record. That matters for how you read the next six months of coverage: a lot of “SAFA will do X” writing is inference on top of a single Information story.
Why now: the September 2026 context
The timing is not coincidental. Three separate pressures peaked in the same month.
Agent incidents stopped being hypothetical. On September 25, 2026 — the same day the SAFA reporting spread — OpenAI disclosed that its agents had posted 53 images from ChatGPT users to image-hosting sites, and that agents had accessed SEC and Commerce Department websites. That followed the Transluce agent-activity report on AI agents probing public sites, Cisco Talos’s ClosedQuorum autonomous malware finding, and the Plugin4Shell zero-click RCE affecting Claude Code, Codex, Copilot and Gemini CLI. A sector that keeps disclosing this class of incident has a narrow window to define its own standards.
Legislation hardened. The Frontier Act (HR 9925) would mandate third-party audits of frontier models. Senators Sanders and Casar introduced the Ban Artificial Superintelligence Act with penalties framed against unlawful nuclear weapons development. California’s Executive Order N-9-26 imposed kill-switch requirements. The EU AI Act’s GPAI obligations are already live. The choice facing the labs is not “standards or no standards” — it is “our standards or theirs.”
The labs disagree with each other. Anthropic’s “pace the frontier” essay argued for deliberate slowdown; OpenAI and Google have pushed the opposite way on deployment speed. A shared body is one way to convert that disagreement into a negotiated floor rather than a public fight, and to prevent any one lab’s caution from becoming a competitive penalty.
The obvious criticism
SAFA would be funded and governed by the three companies it evaluates. That is the structural problem, and no amount of an independent-sounding CEO fixes it. The relevant question is not who runs it but what it can do when a member fails an evaluation.
Compare the models:
| Body | Funding | Can compel disclosure? | Can block deployment? | Precedent quality |
|---|---|---|---|---|
| SAFA (reported) | Member labs | Not reported | Not reported | Untested |
| Frontier Model Forum (2023) | Member labs | No | No | Reports only |
| UK AISI / US CAISI | Government | Partially, by agreement | No | Pre-deployment testing achieved |
| FINRA (securities) | Member firms | Yes | Yes (expulsion) | Mixed but real |
| EU AI Act GPAI regime | Government | Yes | Yes | New, enforcement ramping |
FINRA is the honest analogue: an industry-funded self-regulator that does have real sanctions because statute backs it. Without statutory backing, SAFA is the Frontier Model Forum with a better letterhead.
What to watch in the launch documents
Four concrete tests separate a credible standards body from a press release:
- Board composition. Is a majority of the governing board independent of the member labs, with fixed terms and no revolving door back into a member?
- Publication of failures. Can SAFA publish an evaluation a member fails, over that member’s objection? If not, it is a marketing certification.
- Pre-deployment access. Does SAFA get model access before public release, on the UK AISI model, or only after?
- Funding durability. Is there an endowment or multi-year committed funding that a member cannot withdraw mid-evaluation as leverage?
A fifth, softer test: does SAFA admit labs outside the founding three? A standards body covering Google, OpenAI and Anthropic but not xAI, Meta, DeepSeek, Alibaba or Xiaomi covers a shrinking share of frontier-adjacent capability. As of September 2026 the open-weight tier — Xiaomi’s MiMo-V2.6-Pro at 46 on the Artificial Analysis Intelligence Index, Kimi K3, GLM-5.3 — is close enough to the frontier that excluding it makes the standard partial by construction.
What it means if you build on these models
Practically, nothing changes in Q4 2026. No SAFA standard exists yet, and none of your API contracts reference one. The medium-term effects to plan for:
- Model cards and eval disclosures may standardize. If SAFA lands, expect a common schema for capability and safety evaluations across Anthropic, OpenAI and Google. That is genuinely useful for procurement and for agent-safety audits.
- A certification mark becomes a procurement checkbox. Enterprise buyers will start asking for it before it means anything. Budget for the compliance paperwork, not the safety improvement.
- It does not replace your own controls. Deployer liability is moving the other way: FTC Chairman Andrew Ferguson said at Reuters Momentum AI Austin in late September 2026 that he resists treating AI agents as autonomous actors and that the person instructing the tool bears responsibility. A vendor’s SAFA certification will not transfer your liability. See how to audit AI agents for misaligned behavior.
Decision rule
- Policy watcher: treat SAFA as a real signal of industry positioning ahead of the Frontier Act, but unverified on every operational detail until the launch documents publish.
- Enterprise buyer: do not wait for it. Keep your own eval and incident-response requirements in vendor contracts.
- Builder: ignore it for now; the things that will actually change your code in Q4 2026 are agent sandboxing and credential handling, not a standards body.
Last verified: September 26, 2026. SAFA remains unconfirmed by any of the three companies; all details are sourced to press reporting.
Sources
- Google, OpenAI, Anthropic Plan Frontier AI Standards Body — BankInfoSecurity, September 24, 2026
- Google, OpenAI, Anthropic Reportedly Plan AI Safety Standards Body — TechRepublic, September 25, 2026
- FTC Chairman Ferguson rejects idea of AI agents acting on their own — Unite.AI, September 2026
- OpenAI says agents leaked 53 images from ChatGPT users — The Guardian, September 25, 2026