← Back to blog
AI safety

AI Safety Needs Common Standards but Independent Enforcement

Fahd Rachidy, CEO ·

OpenAI’s call for international AI safety standards is a welcome change in direction. The company now recognizes that common definitions, evaluations and incident-reporting protocols are necessary as AI systems become more autonomous and begin contributing to AI research itself. It also correctly states that each frontier lab remains responsible for developing its systems safely. OpenAI’s proposal https://openai.com/index/building-standards-next-phase-ai/ is an good starting point.

But a standard is not a control, and coordination must not become shared absolution.

Meta is right that every laboratory has both the responsibility and commercial incentive to train and release its models safely. Treasury Secretary Scott Bessent made the same point more bluntly: government must not become a liability shield for frontier laboratories.

When an AI system causes harm, responsibility remains with the humans and companies that built and deployed it. Bessent said that the OpenAI agents’ intrusion into Hugging Face systems was the responsibility of OpenAI’s management https://fortune.com/2026/09/22/bessent-ai-labs-responsibility-government-liability-shield/ .

International standards should strengthen that responsibility, not redistribute it until nobody clearly owns the outcome. It should also not set a bar so high that it excludes smaller competitors.

OpenAI’s proposal is weakest precisely where governance becomes real. It says the standards would not constitute licensing, mandatory prerelease review or approval requirements. Governments could choose whether to incorporate them into law. That may make international agreement politically easier, but it leaves us with definitions of good practice that laboratories remain largely free to interpret and apply themselves.

We should welcome consensus on what must be measured. But somebody independent must also determine whether it was measured properly, whether the evidence is sufficient and what happens when a model fails.

Independence cannot simply mean placing an organization outside the laboratory’s corporate structure. An evaluator may be legally separate while remaining financially, technically or intellectually dependent on the companies it evaluates. Some AI safety organizations share investors, personnel, professional networks or research assumptions with frontier labs. Axios has reported concerns about close relationships between potential evaluators and the companies they may police. The community is small, and that makes conflicts especially difficult to avoid. Its reporting https://www.axios.com/2026/09/18/ai-safety-evaluators-metr-white-house-trump shows why goodwill alone cannot establish independence.

A credible evaluator needs transparent funding, independent governance, conflict disclosures and legal protection for publishing adverse findings.

It also needs the practical ability to challenge a laboratory’s conclusions.

That means access to the model, an independent evaluation model where appropriate, its own evaluation harness, suitable tools and computing resources, and experts who understand both frontier capabilities and the domain in which harm could occur. Giving an outside organization the laboratory’s test results is not an independent evaluation. Nor is asking it to run tests designed by the developer, inside the developer’s harness, using the developer’s definitions of success.

This is one reason Demis Hassabis’s proposal is for example stronger in this case. He has called for a FINRA-style frontier AI standards body, funded by industry but answerable to government, with a majority-independent board and the technical resources to test advanced models. This framework would begin with voluntary prerelease testing but could become mandatory once the regime proves robust, applying to frontier systems regardless of their country of origin or whether their weights are open or closed. The proposed structure https://www.axios.com/2026/07/14/demis-hassabis-ai-regulation-google-deepmind is closer to supervision than industry coordination and this is what I have been advocating for a while now.

The financial-services analogy matters. Banks assess their own risks, but they do so inside defined frameworks, under regulatory scrutiny and with independent assurance. The regulator does not become responsible for the bank’s conduct. The bank cannot escape liability by saying that it followed an industry standard. Standards create comparability; supervision tests compliance; liability preserves accountability.

AI needs the same separation.

But even an excellent international body would address only part of the problem. OpenAI’s proposal concentrates on frontier-model development, catastrophic risk and recursive self-improvement. Those risks matter, but most AI harm will occur when models act inside businesses: sending a misleading financial communication, exposing patient data, approving a transaction or taking an action outside the authority granted by a customer.

A model can pass a frontier safety evaluation and still take an inadmissible action in a specific institution. The laboratory cannot know every customer’s circumstances, every hospital’s escalation protocol or every bank’s obligations.

Deployment therefore needs another independent control: a harness outside the agent that intercepts consequential actions before execution. The model may propose an action. The harness must determine whether the action remains authorized and admissible under current law, policy, context and user intent. It must be able to allow, narrow, escalate or block the action and preserve evidence the agent cannot alter.

For example, an investment agent might be authorized to draft client communications. That does not give it permanent permission to send a performance claim. An external control should check the actual message against the applicable marketing rules, the firm’s policies and the client’s status before the email leaves the system.

The right framework therefore has three parts: laboratory responsibility backed by liability, international standards supported by genuinely independent evaluation, and enforceable controls around AI systems when they act in the real world.

OpenAI is right to call for international coordination. But such proposal becomes credible only when standards can be tested independently, failures have consequences and control extends beyond the frontier lab into deployment.