The AI Standards Body Is the Ladder, Pulled Up
OpenAI, Anthropic and Google DeepMind have reportedly met since July about an AI standards body, two months before the essay calling for restraint. It is modelled on a financial-industry self-regulator, the EU has enforced a binding alternative since August 2026, and this is self-regulation built to avoid it.
Yesterday I wrote that the call to slow down AI tends to exempt the people making it. The rest of the story turned up a day later.
The Information reported on 13 September that OpenAI, Anthropic and Google DeepMind have been meeting since July about an AI standards body, with testing and auditing in scope. The essay asking everyone to pace themselves landed the day before, on the 12th. So the AI standards body conversation has been running for about two months longer than the public argument about it.
The meetings came first
Two months of private talks sat in front of the public case.
An argument that lands before anything else exists can be answered. You can push back on it, propose another direction, point at what it leaves out. An argument that lands after a working group has been meeting since summer is closer to terms being set.
I’ve sat in enough standards conversations to have a rough sense of the order of operations. The people in the room in July decide what the standard assumes. The people reading in September get the wording.
The model is finance
The reported shape is a self-regulatory organisation, the pattern finance uses. An SRO is funded and staffed by the firms it governs. It can write real rules and run real audits. It also tends to produce rules a large incumbent clears and a smaller entrant cannot, because the people drafting them describe what they already do and call it a floor.
Then there’s Altman’s condition: he wants a testing and auditing organisation, but one the labs build themselves, without the backing of the US government. The stated reason is that waiting for the state moves too slowly. The shape that leaves is a rulebook with no outside enforcement and no seat for anyone outside the room.
Brussels did it in public
The “too slow” claim has a checkable counter. The EU published its General-Purpose AI Code of Practice in July 2025, three chapters covering transparency, copyright, and safety and security. Obligations for general-purpose model providers have applied since August 2025. Enforcement powers, including information requests, model access and recalls, went live on 2 August 2026, a month before anyone reported these meetings.
The EU version is clumsy in places and slow where it matters, and a lot of it was written by people who have never shipped a model. It wasn’t drafted behind closed doors, though. It was written in the open, with a signatory taskforce. It covers copyright next to safety, because those obligations cost the companies it binds. It ends in enforcement that someone outside the industry gets to apply to them.
They built an AI standards body before
This would not be the first industry body these companies have set up. The Frontier Model Forum has been running since 2023, founded by Anthropic, Google, Microsoft and OpenAI. It has an executive director, a safety fund over $10 million, and a voluntary agreement to share information on vulnerabilities and dangerous capabilities, CBRN and cyber included.
So what does a new body do that the old one does not? Two answers point opposite ways. Either the Forum was never meant to write binding standards and this is the missing half, or a second body is easier to start than a first one is to reform. The reporting does not say. Microsoft is in the Forum and was not named in these meetings.
The closer precedent is the 2023 White House commitments. Fifteen companies, eight promises, covering safety testing, security practices and public trust. A year on, there was better red-teaming and watermarking, and no meaningful accountability. The post-mortem is blunter about why: the wording was vague enough that nobody could say what compliance meant, and nothing was built to check.
What I’d need to see
A real AI standards body would be worth having, and I’d take one gladly. Testing that happens beats testing promised in a policy paper, and three labs agreeing on one evaluation beats three labs grading themselves.
2023 failed on checking rather than ambition, so the list that matters is about who checks:
- who can join, and what it costs. If the fee or the compliance burden only clears at frontier-lab scale, that is a barrier dressed up as a bar
- whether evaluations get published in full, failures included. The summer we watched models escape their own sandboxes is exactly the material that needs to be public
- whether anyone outside the member labs can run the tests and get the same answer
- what happens when a member fails. An audit with no consequence is a press release with a methodology section
- who pays the auditors, and whether the people being audited can fire them
None of those checks need government. All of them can be run from outside the membership.
The first standard will give it away
Whatever this body publishes first is the tell. If it describes something the three founders already do, it is a floor drawn at their own feet. If it demands something none of them do, and one of them slows a launch to meet it, the pacing argument was real.
The EU wrote down what it expects, then handed someone else the power to enforce it against them. What these three are building has the rules written by the people they bind, the enforcement kept in-house, and the government politely declined. The meetings came before the argument, the rulebook is being written by the governed, and the first standard published will show whether the floor sits at their own feet or somewhere new.