What is SAFA? The frontier AI standards body labs want

Artificial Intelligence 7 min
SAFA interlocking rings and frosted seal on slate
Three frontier labs want a Standards Authority for Frontier AI. Here is what the SAFA reports actually claim, what is still rumor, and what a buyer should ask.

The Standards Authority for Frontier AI is, for now, a reported plan. OpenAI, Anthropic, and Google are said to be discussing an industry-led standards and self-regulatory organization under the provisional name SAFA. It has not launched. It is not a law, a government agency, or another name for a national AI Security Institute.

That distinction matters more than the acronym. If SAFA opens as reported, three companies that build frontier models would help shape rules for testing, incident reports, and auditor qualifications. Buyers should pay attention, but they should not mistake a proposed institution for a working assurance system.

Standards Authority for Frontier AI: reported, not launched

The Verge reported on September 24, relaying The Information, that the three labs were planning their own AI safety organization. The provisional name is Standards Authority for Frontier AI, and the group could launch by early 2027. “Could” is doing real work there.

CNBC TV18’s September 25 account, also based on The Information’s reporting, adds detail about the working group’s discussions. Neither report says SAFA is incorporated, open for membership, or already certifying models. Neither confirms a charter, a fee schedule, or a hired chief executive.

So the useful answer to “What is SAFA?” is narrow: a tentative industry institution being discussed by OpenAI, Anthropic, and Google, with an early-2027 start floated in reporting. Everything beyond the reported remit and names under consideration remains unsettled.

What the reports say SAFA would do

The proposed remit has three concrete pieces. First, SAFA would support third-party organizations that test models before deployment. Second, it would lay out how AI developers should report safety and security incidents. Third, CNBC TV18 says it would set qualifications for independent auditors.

Those jobs sound adjacent, but they are not interchangeable. A pre-deployment test probes a model before release. An incident-reporting rule governs what happens when a failure or security event is found. Auditor qualifications decide who is accepted as competent to inspect the work. A standards group can be credible at one and weak at another.

There is also an unresolved boundary. According to CNBC TV18, the working group is debating whether SAFA should conduct its own safety and capability tests alongside the US Center for AI Standards and Innovation, or CAISI. That is a consequential design choice. Supporting outside evaluators is different from writing their requirements; writing requirements is different again from running the tests and issuing a result.

The reports do not provide benchmark lists, pass marks, auditor exams, or enforcement procedures. Treating any of those as decided would fill blank pages that the labs themselves have not publicly filled.

Three layers: national institutes, industry SAFA, private EvalOps

Three governance layers: national institute, industry rings, and EvalOps tools
National institutes, industry SAFA, and private EvalOps are different layers. Do not collapse them into one stamp.

AI assurance is easier to read when the institutions are separated into layers.

The public layer includes national bodies such as CAISI in the United States and the UK AI Security Institute. They sit inside government structures and answer to public mandates. Their model-access disputes belong to a different governance track, as the recent White House and UK AISI access report shows.

SAFA would occupy an industry layer. Its founding companies would be frontier-model developers, and its proposed tools are standards, support for outside testing, incident rules, and possibly tests of its own. Calling that self-regulation is descriptive, not dismissive. Industry institutions can supply technical speed and shared procedures. Their incentives still need inspection.

Then come independent private evaluators, red teams, and EvalOps providers. They can test a model for a buyer, probe a specific deployment, or collect evidence against a defined control set. They do not become independent merely because a contract uses that word. Ownership, funding, access, methods, and publication rights all count. For a concrete view of that layer, see our work on independent AI evaluators in Turkey.

These layers can cooperate without becoming the same institution. SAFA should not be read as a replacement for CAISI or AISI. Nor should a SAFA-recognized auditor automatically be treated as a public regulator.

The leadership list is not a board of directors

Names make a proposed organization feel finished. Here they do the opposite: they show that leadership is still under discussion.

CNBC TV18 reports that Sriram Krishnan, Arati Prabhakar, Condoleezza Rice, and David Friedberg are under consideration. Krishnan is described in the report as a former venture capitalist and a top AI policy adviser in the Trump administration. Prabhakar formerly led the White House Office of Science and Technology Policy under President Biden. Rice and Friedberg are also on the reported list.

No appointment is confirmed in the cited coverage. None of those people should be called SAFA’s chief executive, chair, or accepted candidate. A shortlist is not an org chart.

The government relationship is unsettled too. CNBC TV18 says the companies first imagined an industry-led group with federal oversight. That partnership idea stalled after the White House had told OpenAI, Google, and Anthropic to find industry consensus first, and the current plan may operate more independently of government.

This follows a related proposal from Google DeepMind CEO Demis Hassabis in July 2026: a US-backed institution modeled in part on FINRA, the financial industry’s self-regulator. We examined the incentives and concentration risks in our earlier “pact or cartel” analysis. SAFA may inherit that debate, but the new reporting does not prove it will adopt Hassabis’s design.

Operator checklist before trusting a SAFA stamp

Blank buyer checklist beside a scale balancing a model cube and an independent seal
Before trusting a SAFA stamp, ask about charter, scope, independence, public artifacts, and incident rules.

A procurement team does not need to wait for a launch announcement to prepare. It does need to resist treating a future logo as the conclusion of due diligence. Ask these questions when SAFA, a member lab, or an auditor starts making assurance claims:

  1. Who writes and controls the charter? Identify the funders, voting rights, veto rights, conflict process, and route for admitting or removing members. If those details are private, say that in the risk record.
  1. What exactly is in scope? A benchmark score, an audit, a certification mark, and support for a third-party test are four different products. Request the control set, model version, test date, exclusions, and expiry conditions behind any claim.
  1. How is independence protected? Find out whether the organizations grading a model are paid by its developer, whether members approve auditors, and whether unfavorable findings can be published. Independence needs mechanics, not an adjective.
  1. Where do CAISI and AISI fit? Ask whether public institutes can inspect methods or results, whether tests are duplicated, and what happens when public and industry findings conflict. Do not let “aligned with” stand in for a documented relationship.
  1. Are the standards public? Buyers need artifacts they can examine: test protocols, reporting fields, severity levels, version histories, and correction records. Member-only rules may improve coordination among labs, but they offer outsiders little evidence.
  1. What happens after an incident? An incident-reporting framework should identify who reports, to whom, on what timetable, and with what disclosure. Until SAFA publishes such rules, map its future claims against your own escalation and evidence-retention process.

This checklist is deliberately less exciting than a new acronym. It is also closer to the buyer’s actual job.

What to watch next

Three signals would turn SAFA from an interesting report into an institution worth evaluating: a published governance document, a precise testing and incident remit, and evidence that qualified outsiders can challenge member labs without losing access. Those signals are not confirmed in the September 24 and 25 reports.

Until then, file SAFA under proposed industry infrastructure. Follow the oguzhan.co AI hub for the launch, if it comes, and for the documents that matter after the announcement. The acronym is easy. Accountability will be in the charter, methods, conflicts, and public record.

Oğuzhan Koçaklı

Oğuzhan Koçaklı writes and advises on AI engineering, agents, GenAI products, and applied ML. Daily digests and deep dives in EN + TR at oguzhan.co.

All posts

Leave a Reply

Your email address will not be published. Required fields are marked *