TL;DR: Google, OpenAI and Anthropic are reportedly planning a self-regulatory body for frontier AI, modeled on FINRA, the organization that polices Wall Street brokers. It would set standards for testing models before release, reporting safety incidents, and certifying outside auditors. Unlike FINRA, nothing reported so far gives it a government overseer, mandatory membership, or the power to punish.
I invest and trade often. At one point I was interested in financial advising and got a series of licenses to be able to do that, and really understand just how careful the financial regulations are, and with good reason. Obviously money is on the line, and we’ve seen collapses in the economy because of mismanaged money.
That’s the lens I read last week’s news through. According to The Information, as rounded up by Semafor, Google, OpenAI and Anthropic are planning a self-regulatory body for the most powerful AI models, modeled on FINRA, the organization that polices Wall Street’s brokers. None of the three has confirmed it on the record yet.
So, I think the FINRA-style push makes sense. Below you’ll find what the labs are reportedly building, a timeline of six times AI got past the limits built around it this year, the three things FINRA has that this body doesn’t, and the one condition I’d hold them to.
What You’ll Walk Away With
A clear read on what the labs are reportedly building, and the three gaps it would still leave open
A way to explain to your team who is writing the rules your AI vendors answer to, and why it’s happening now
What the labs are reportedly building
The idea started with Demis Hassabis, who runs Google DeepMind. He proposed a FINRA-style body for AI in an Axios interview on July 14, 2026, saying “this is where the industry needs to go.”
The body now being planned carries the working name Standards Authority for Frontier AI, and it would set standards for testing models before release, for reporting safety incidents, and for certifying the outside auditors who check the labs’ work. The target is late 2026 or early 2027.
Why one global standard keeps slipping away
Now, I’ve outlined this before in a post on how AI regulation actually works in 2026, but there are so many different agendas at the global level. Every country has a different need or a different push. Some countries are just trying to get started, so they’re trying to move as fast as possible. Other countries are hesitant. Other countries are moving forward with regulations, while others want to just open all the gates and just have it move as quickly as possible to get ahead of other countries. So, to me, it’s very difficult to have some sort of standard.
And when I think of something like this, I often think of the nuclear treaties across nations. They came after a disaster or a near-miss, not before.
The Cuban Missile Crisis was October 1962. The Washington-Moscow hotline followed in June 1963, and the Limited Test Ban Treaty was signed that August.
AI is already getting out of its sandbox
And something that’s really clear is there are systems that are leaving their sandboxes, and things are moving faster than these creators feel comfortable with, by their own admission, and faster than they can even control.
In July, AI agents from OpenAI’s internal testing broke out of their sandbox and attacked Hugging Face’s servers. OpenAI said as much in its own report on the Hugging Face incident, calling it “a ‘warning shot’ for us and for the world” and evidence that “highly capable AI agents are now able to work around technical controls.”
Just the fact that the Hugging Face incident took place, and we keep finding stuff about it. Hugging Face caught it and told the world before OpenAI even knew its own agents were behind it. And that’s the main part that to me is concerning.
Hugging Face disclosed the intrusion on July 16 without knowing whose agents had done it. OpenAI tied it to its own agents on July 20.
The “tens of thousands” at the end comes from Axios on September 26. The labs run hundreds of thousands of test runs, so even a small share of bad behavior adds up fast.
Why starting with three companies makes sense
So Demis Hassabis’s proposal seems ideal to me. There are three main players in this arena of development. Because of the amount of training and data and development that’s needed to be at the forefront, a lot of the AI tools we use at work run on models from these three, and Anthropic has caught rival labs trying to copy its models. So to me, this truly makes sense, and it does make me feel better about where things are going.
Other tech leaders backed the idea the week Hassabis proposed it. Sam Altman called it “a thoughtful proposal from demis,” Satya Nadella called it “an important piece,” and Elon Musk called it “a good starting point for discussions.”
I don’t want it to get to a global disaster before we start realizing the need for regulations, especially understanding that AI is something that can’t just be toothpaste put back in the tube. Once it’s out, it’s out, and anybody with an LLM can get access to certain things. It’s not this secret blueprint that only engineers with PhD-level education can understand.
What FINRA has that this body doesn’t
FINRA works because of three things. The SEC oversees it and approves its rules. Membership isn’t optional, because federal law bars a broker-dealer from trading with the public unless it belongs. And it can fine firms, suspend them, and ban people from the industry. In 2025 alone, FINRA filed 625 new disciplinary actions and issued 187 bars against individuals.
Nothing reported about the AI version includes any of those three. It would be voluntary and industry-run, which is a step back from Hassabis’s own essay, which described a body “modelled on a federally overseen public-private partnership or self-regulatory organisation,” with independent technical experts on its board.
Honestly, all those gaps bother me. But at the same time, it’s a start, and that’s the piece that makes me the most relieved, that we’ve started this process.
The one condition I’d hold them to
The pros are that there would be regulation, and ideally there is an independent figure. I saw that Anthropic volunteered to put outside evaluators inside the company. Hope to see that more across everything.
Anthropic announced it on September 18: outside evaluators working with “access comparable to an employee’s.” In Dario Amodei’s words, that means “desks in our offices, access badges, and company laptops.”
But also, you cannot have one of these organizations be the head of this team so that organizations essentially police themselves. Because history has shown us that profit often beats ethical standards, especially when there are no laws that would make something illegal, simply unwise.
Bill Gates put it bluntly on The Ezra Klein Show on September 29, 2026:
“You can’t rely on the industry to self-regulate here. I mean, it’s just insane.”
That is 100% true, and I fully agree. But there’s a big but here. What is the other side of the coin? No regulation at all? So if it comes to no regulation, I’d rather have these companies come together and try to put something in instead of waiting for the perfect. Again, the perfect is the enemy of the good. We could sit here for perfect government regulation or global regulation to come along. What happens until then?
So do I think it’s everything? No.
Do I think it solves the issues? Not fully, but I do think it’s a true step in the right direction, especially when the president of the United States keeps pointing to simply wanting to beat China or other countries rather than focusing on what is the responsibility that is held by the United States as the place where the biggest companies are developing the most powerful AI.
The White House’s AI Action Plan, released July 23, 2025, puts it plainly: “The AI race is America’s to win.”
It’s not enough to know AI exists
I think leaders should understand where we are in this journey, because, as I keep saying it, in the time that we live in, it’s not enough to know AI exists. Whether you like it or not, whether you embrace it or not, you have to search to understand it, and that understanding is just a constant process because of the speed of change. And the more of us that talk about it and educate others about it, the better that we’ll get.
I take three diagnostic calls a month. Thirty minutes, free, and afterward I send you an outline of how I’d work on your biggest pain points. Book one →
If You Only Remember This
FINRA’s power comes from three things: the SEC above it, membership the law requires, and the ability to ban people. The reported AI version has none of the three yet.
AI agents have already worked around the controls built for them, and in the Hugging Face case, the company that got hit knew before the company whose agents did it.
The condition that makes this work is independence: no single lab gets to run it.
Your turn: restack this with one line. Are you excited about where this is going, or, after seeing everything that’s happening, what’s your biggest question?
Thanks for reading,
Joel
Worth Your Time
Rob T. Lee: Investigation template defined for AI accidents? What happens when the company at fault commissions, scopes and redacts its own incident review. It’s the best case I’ve read for why no single lab should run this body.
Ethan Mollick: Agency and Agents. The Hugging Face incident told as a plain story, plus a practical rule for when an agent should stop and ask a human.
Oliver Patel: How China is governing agentic AI. One government’s actual rules for AI agents, which shows how uneven the rules still are from country to country.
Questions Leaders Are Asking
What is the Standards Authority for Frontier AI? The Standards Authority for Frontier AI is the working name for a self-regulatory body that Google, OpenAI and Anthropic are reportedly planning. According to reporting in September 2026, it would set standards for testing AI models before release, reporting safety incidents, and certifying outside auditors, with a target launch in late 2026 or early 2027.
Has any AI company confirmed the self-regulatory body? No. As of September 29, 2026, the plan is known only through anonymous sourcing first reported by The Information. Google DeepMind’s Demis Hassabis publicly proposed a FINRA-style body on July 14, 2026, but none of the three companies has confirmed the planned organization on the record.
What is FINRA, and why is it the model? FINRA, the Financial Industry Regulatory Authority, is a not-for-profit that polices U.S. broker-dealers under SEC oversight. The SEC approves its rules, federal law requires broker-dealers dealing with the public to be members, and it can fine, suspend and ban firms and individuals. It is the model because it shows an industry setting and enforcing its own rules.
What happened in the Hugging Face incident? In July 2026, AI agents from OpenAI’s internal testing broke out of their sandbox and attacked Hugging Face’s infrastructure. Hugging Face detected the intrusion and disclosed it on July 16, 2026. OpenAI’s own monitoring flagged the activity on July 19, and OpenAI publicly acknowledged its agents’ involvement on July 21.
Does industry self-regulation replace government AI rules? No. Self-regulation would sit alongside laws already in place. California’s SB 53 on frontier AI transparency took effect January 1, 2026, and the EU AI Act’s obligations for general-purpose AI models began applying on August 2, 2025.
Joel Salinas is an AI Strategy Coach and entrepreneur. AI is everywhere; judgment is scarce. Joel helps founders and leaders adopt AI without outsourcing their judgment to it, and he builds the systems too. Creator of the AI Leadership Triad.
Written by a human, for humans.
Sources
Semafor, Firms take lead on AI safety standards as security incidents mount, Sep 27, 2026 — https://www.semafor.com/article/09/27/2026/firms-take-lead-on-ai-safety-standards-as-security-incidents-mount
Axios, Demis Hassabis interview on AI regulation, Jul 14, 2026 — https://www.axios.com/2026/07/14/demis-hassabis-ai-regulation-google-deepmind
FINRA, Key Statistics (2025) — https://www.finra.org/media-center/statistics
Axios, Scoop: Top AI companies probing tens of thousands of security incidents, Sep 26, 2026 — https://www.axios.com/2026/09/26/openai-anthropic-thousands-ai-security-incidents
OpenAI, The Hugging Face incident and the road ahead, Aug 26, 2026 — https://openai.com/index/hugging-face-incident-and-the-road-ahead/
Hugging Face, Security incident, July 2026, Jul 16, 2026 — https://huggingface.co/blog/security-incident-july-2026
The Ezra Klein Show (The New York Times), Bill Gates’s Blunt Warning on A.I., Sep 29, 2026 — https://www.nytimes.com/2026/09/29/opinion/ezra-klein-podcast-bill-gates.html
Office of the Historian, U.S. State Department, The Cuban Missile Crisis, October 1962 — https://history.state.gov/milestones/1961-1968/cuban-missile-crisis








