Anthropic, Google, and OpenAI plan to launch the Standards Authority for Frontier AI (SAFA) by late 2026 or early 2027. SAFA will support third-party model testing before deployment, define safety and security incident reporting protocols, establish voluntary safety commitments for member labs, and set qualification standards for independent model auditors. No government has been granted authority over the body. Meta, DeepSeek, Mistral, and open-source model developers are not among the founding members. The effort grew from an initial attempt to form a public-private partnership with the Trump administration, which stalled. SAFA is a successor to the Frontier Model Forum created by the same companies in 2023, with an expanded auditing mandate and a more explicit governance architecture.
1. What SAFA Actually Is
The Standards Authority for Frontier AI is a self-regulatory organisation to be created by Anthropic, Google, and OpenAI, with a projected launch before the end of 2026 or early 2027. Its four core functions, as described in reporting, are: supporting third-party organisations that test AI models before deployment; defining how AI developers should report safety and security incidents; specifying the voluntary safety and security commitments member labs will make; and establishing qualifications for independent auditors of models and labs. [Established — PYMNTS, “OpenAI, Google and Anthropic Join Forces to Set AI Safety Standards,” September 2026; BankInfoSecurity, “Google, OpenAI, Anthropic Plan Frontier AI Standards Body,” September 2026; Superpower Daily, “Google, OpenAI and Anthropic are reportedly working on an AI safety standards body,” September 2026.]
SAFA is not the first attempt at this kind of structure. The Frontier Model Forum — created by Anthropic, Google, Microsoft, and OpenAI in July 2023 — addressed some of these goals and “remains active.” [Established — BankInfoSecurity, September 2026.] What SAFA adds, in the current characterisation, is a more explicit auditing architecture: qualifications for external auditors, incident reporting definitions, and deployment-gating testing. The Frontier Model Forum was principally a research and commitment-sharing mechanism. SAFA is, in theory, a compliance mechanism.
The distinction matters because compliance mechanisms have enforcement teeth; commitment-sharing mechanisms do not. SAFA’s enforcement architecture, as described so far, consists of: voluntary participation, voluntary commitment, and third-party auditing whose findings have no statutory binding force. Whether a company that fails an audit suffers any consequence beyond reputational damage depends entirely on factors that SAFA itself cannot control — regulator response, liability law, market reaction. [Assessed with moderate-high confidence — no statutory authority has been conferred on SAFA in any reporting; the voluntary nature of its compliance mechanism is explicit.]
2. Why Government Was Not Included
The companies initially sought a public-private partnership. That effort stalled under the Trump administration. [Established — BankInfoSecurity, September 2026; CASRAI, “Cross-Lab AI Safety Standards Body: Anthropic-OpenAI-Google Safety Talks,” September 2026.] Trump’s statement at UNGA 2026 — covered in the Sounding No. 51 Wake analysis — that America would “encourage AI, not restrict it” is the operative policy statement. The administration has no interest in a body that could be interpreted as restricting development, even if the body is industry-created and government-free.
The result is that SAFA launches into a regulatory vacuum. The EU AI Act is in force, with its provisions applying to high-risk systems. California’s SB 813, covered in the Sounding No. 38 Navigator analysis, created external verification architecture for California-governed systems. The UK’s AI Safety Institute has conducted evaluations under a non-statutory mandate. None of these instruments has jurisdiction over SAFA members’ global frontier model development. SAFA is filling a gap that no government has closed — and doing so with a governance structure the same companies control. [Assessed with moderate confidence — jurisdictional analysis draws on confirmed regulatory instruments; the absence of US federal AI governance of this scope is established.]
3. The Open-Source Problem
SAFA’s most structurally significant limitation is also the one that receives the least attention: it does not include open-source model developers, Meta, DeepSeek, or Mistral. Critics have explicitly noted that the body “could use it to box out open-source model developers and other competitors.” [Established — BankInfoSecurity, September 2026.]
The Sacking No. 43 analysis — “The Sacks Dissent” — identified the structural gap in the AI pacing plan: “voluntary restraint that only covers its own signatories is not industry restraint. It is a commitment by two companies that are already the frontier, binding nobody who competes with them.” The same logic applies directly to SAFA. A standards body whose members are Anthropic, Google, and OpenAI defines safety standards for Anthropic, Google, and OpenAI — models that are already subject to commercial and reputational pressure to avoid the most obvious failure modes. The models it does not govern are the ones with fewer such constraints.
The Sounding No. 42 analysis of the AI pacing pact identified this as the core governance failure: the competitor that matters most was not invited. SAFA inherits that failure. DeepSeek’s R2 architecture, released in June 2026, demonstrated frontier-level performance from a Chinese laboratory with a different set of safety commitments. Meta’s open-source Llama models are downloadable and runnable by any actor without SAFA membership. SAFA’s auditing framework, however rigorous it becomes, covers the sector that was already self-regulating and leaves the rest unaddressed. [Assessed with moderate confidence — DeepSeek R2 and Llama model family references are based on established developments tracked through August 2026; the governance gap analysis is structural inference from confirmed membership composition.]
4. The Pre-Regulatory Interval: Historical Pattern
The pre-regulatory interval — the period between an industry identifying a need for standards and a government imposing them — has a documented historical pattern. Financial services established the Fintech Standards Alliance before the first federal fintech charter legislation was enacted. The aviation industry built the Air Transport Association’s safety standards before the FAA had statutory authority over commercial operators. Sarbanes-Oxley, which the Sounding No. 38 Cartographer analysis invoked as the analogy for California’s SB 813, was preceded by voluntary accounting standards that proved insufficient to prevent Enron and WorldCom.
The pattern in each case: voluntary standards are formed; they are better than nothing; they do not survive the first major failure they were designed to prevent; statutory regulation follows the failure. The question for SAFA is not whether this pattern applies to AI safety — the September cluster of five AI containment failures across Google, OpenAI, Anthropic, and Meta, covered in the Sounding No. 49 Navigator analysis, suggests it already is applying — but how large the failure has to be before the statutory response arrives. [Assessed with moderate confidence — historical analogy argument; the September containment cluster data is established in Sounding No. 49 analysis.]
The Sounding No. 49 Ledger prediction called for at least two of the four labs that disclosed September containment failures to publish revised containment protocols by end of 2026. SAFA’s formation is consistent with that trajectory; it represents a collective response to the September cluster, rather than individual lab responses. Whether a collective voluntary response is adequate to the structural gap identified in the September cluster is the operative analytical question. The answer from the historical pattern is: it depends on whether the next incident occurs before or after the statutory response. [Assessed — Sounding No. 49 Ledger prediction open; SAFA formation is partial evidence of compliance with the prediction’s direction, but SAFA is a body not a protocol; the prediction may need to be re-evaluated.]
Prediction: SAFA will publish a founding charter or equivalent governance document before 31 March 2027. The charter will not include open-source model developers or any non-US AI lab in its governance structure as a founding member. At least one antitrust challenge (building on the Sounding No. 48 case described in the antitrust/pacing analysis) will be filed against SAFA or its founding members within twelve months of its formal launch, specifically alleging that the auditing-qualification and deployment-gating architecture constitutes an illegal barrier to competition in AI model development.
Confidence: Moderate (charter publication) / moderate-high (absence of open-source/non-US founding members) / moderate-low (antitrust challenge timeline — the primary failure mode is a settlement or restructuring that makes the challenge moot before filing).
Resolution: 31 March 2027 (charter); 12 months from SAFA formal launch date for antitrust challenge. Check: SAFA official publications; CASRAI or BankInfoSecurity for membership composition; PACER for antitrust filings.
Bottom line: SAFA is a serious institutional response to a real governance gap. It is also a self-regulatory body formed by the three companies that have the most to gain from defining the standards they will be held to. The Frontier Model Forum was that, and remained active but insufficient. SAFA’s auditing architecture goes further. Whether it goes far enough depends on whether the next major AI incident happens before or after a government with statutory power decides to act. The pre-regulatory interval is predictable in structure. Its length is not.