← Back to blog
AI safety

If frontier labs cannot yet prove control, regulated institutions cannot outsource it

Fahd Rachidy, CEO ·

Guidelight AI Standards’ newly published safety assessment should be a wake-up call for banks and healthcare providers deploying AI agents. Guidelight has assessed OpenAI, Anthropic, Google, xAI, and Meta and all of them failed!

Steven Adler, co-founder of Guidelight and former OpenAI Safety & Governance lead said “It is totally unacceptable that Frontier Labs are only cleaning up incidents after the facts and none of them have preventative systems in place”

Rated against a practical question: can these organisations actually control the agents they are building, OpenAI and Anthropic received no more than a C+. Google received D+, xAI D-, and Meta F. Even the firms building the models have not yet demonstrated controls sufficient to prevent harmful agent actions consistently. So why would businesses in regulated industries deploy them without guardrails?

Guidelight Control assessment grades for Anthropic, OpenAI, Google, xAI and Meta

That matters because the current enterprise conversation is dangerously complacent. A bank or hospital buys a model from a reputable provider, writes a good prompt, adds a policy document, and assumes it has deployed safe AI.

It has not.

Guidelight’s standard makes the distinction clear. Control requires more than monitoring. It requires visibility into what an AI is doing, testing whether monitoring works, defining actions the AI may never take without human sign-off, gating sensitive actions before execution, circuit-breaking when warning signals accumulate, independent third-party testing, and a plan to revoke permissions or shut the system down when control fails.

It is the minimum architecture for any agent acting in a regulated institution.

Consider a bank’s customer-service agent. It may be permitted to answer questions about a mortgage, a complaint, a fraud claim, or a targeted investment-support journey. But it cannot have permanent permission to say anything it likes. A change in the customer’s circumstances, vulnerability, product status, jurisdiction, or regulatory obligation can make a previously ordinary response inadmissible. The agent must be able to be stopped, amended, escalated, or prevented from acting before the customer is harmed.

The same is true in healthcare. A doctor’s prompt-configured chatbot that checks in with a patient, collects symptoms, and emails the conversation may sound helpful. But if the agent misses a red flag, discloses health data incorrectly, fails to escalate a dangerous symptom, or gives advice outside the approved care pathway, the fact that it came from Claude, ChatGPT, Gemini, or another respected model is no defence. The model provider cannot know the clinician’s current protocols, consent arrangements, patient-specific care plan, legal duties, or escalation policy unless those are structured and governed by the deploying institution.

This is also the point the open-versus-closed weights model debate misses. Openness prevents none of this. Closedness prevents none of this. Model intelligence is not governance.

Guidelight’s assessment is yet another example showing that banks and healthcare providers cannot responsibly delegate control to the model vendor.

They need an independent compliance and reasoning layer around the agent: one that applies current law, regulation, company internal policy, authority, and context before an action occurs; produces an auditable explanation; escalates exceptions; and revokes authority when conditions change.

That is the purpose of ZebraTruth compliance context layer.

Guidelight’s Control standard