
AI governance just took a new turn, without going through legislation. According to reporting from The Information, relayed on September 24, 2026 by several specialized outlets, Google, OpenAI and Anthropic are actively discussing the creation of a private AI safety standards body, tentatively named SAFA (Standards Authority for Frontier AI). For an SME already using Claude, ChatGPT or Gemini day to day, this announcement is worth understanding before reacting: it changes none of your legal obligations, but it reshapes how AI providers intend to prove their seriousness.
In brief
- Google, OpenAI and Anthropic are working toward an independent body, SAFA, tasked with setting safety standards for frontier AI models, according to The Information.
- The idea originates from an essay published on July 14, 2026 by Demis Hassabis, CEO of Google DeepMind, proposing a regulator modeled on FINRA, the US authority overseeing financial brokers.
- On September 23, 2026, Sam Altman (OpenAI) and Dario Amodei (Anthropic) separately urged the UN Security Council to adopt common international standards for testing and monitoring AI systems.
- SAFA would remain voluntary and industry-funded, with a launch targeted for late 2026 or early 2027; no final legal structure has been settled yet.
- For an SME, this has no immediate technical impact: GDPR and the EU AI Act remain the only binding obligations in Europe.
What is SAFA, and why now?
SAFA (Standards Authority for Frontier AI) is the working name for a body that three of the largest AI labs are considering building together, outside any government oversight. Its role would be to define common safety standards (pre-deployment testing, incident reporting rules, qualification of independent auditors) and support third-party model evaluations, somewhat like FINRA does for stockbrokers in the United States.
This initiative did not appear out of nowhere. It follows a precise, public, dated sequence of events.
July 14, 2026
Demis Hassabis's essay
July-August 2026
First public endorsements
September 23, 2026
Address to the UN
September 24, 2026
SAFA takes shape
According to the reporting, several figures have reportedly been approached to lead the body, including Sriram Krishnan (former White House AI adviser) and Arati Prabhakar (former Biden administration technology official). Nothing has been officially confirmed by the three companies at this stage: these are ongoing discussions, not an actual launch.
Private self-regulation vs. European regulation: two different logics
For an SME, the most useful point is not SAFA itself, but what it reveals: two approaches to AI safety coexist, and neither replaces the other.
SAFA (self-regulation)
The EU AI Act (regulation)
The table below summarizes the concrete differences between the two approaches.
| Criterion | SAFA (proposed) | AI Act (European Union) |
|---|---|---|
| Nature | Private body, industry-led initiative | Binding legal regulation |
| Geographic scope | Mainly US, no fixed borders | European Union, with extraterritorial effect |
| Character | Voluntary, at this stage | Mandatory since August 2, 2026 (see our guide to the AI Act) |
| Penalty for non-compliance | None beyond reputation | Fines up to several percent of global revenue |
| Timeline | Launch targeted for late 2026 or early 2027 | Already in force, further deadlines through 2027 |
One key point to remember
Even if it materializes, SAFA would not replace any legal obligation. A European SME must still comply with the AI Act and GDPR, regardless of the voluntary guarantees its providers offer.
What this actually means for an SME
No immediate action is required. But three habits become relevant in the medium term:
- Add governance to your AI vendor selection criteria. At comparable budget and performance, a provider that publishes its safety testing and submits to third-party audits (via SAFA or an equivalent) becomes a differentiator, on par with customer support or price.
- Do not confuse communication with compliance. A voluntary commitment, however serious, does not exempt an SME processing EU citizens' data from its GDPR and AI Act obligations. The two stack; they do not substitute for each other.
- Track the story rather than react urgently. SAFA does not formally exist yet: its funding, governance and exact scope remain to be clarified by late 2026 or early 2027. Light monitoring is enough for now.
Measured optimism
Three direct competitors, Google, OpenAI and Anthropic, discussing a shared safety framework together is a fairly positive signal: it reflects a shared awareness of risks, without slowing down the innovation that SMEs already benefit from every day.
Limits worth keeping in mind
In fairness, three caveats apply. First, SAFA has not, to date, been the subject of any official announcement from the three companies involved: the available information comes from journalistic sources (The Information, relayed by outlets such as BankInfoSecurity or Yahoo News), not a press release. Second, a body funded by the very labs it is meant to oversee raises a legitimate independence question, already flagged by several observers. Finally, the US political context remains uncertain: the current administration currently favors rapid development over additional guardrails, which could slow down or reshape the project.
FAQ
What is SAFA (Standards Authority for Frontier AI)?
SAFA is the working name for a private body that Google, OpenAI and Anthropic are considering creating to define shared safety standards for the most advanced AI models, modeled on FINRA, which oversees financial brokers in the United States.
Does SAFA replace the EU AI Act?
No. SAFA would be a voluntary body with no legal enforcement power. The EU AI Act is a binding regulation, already in force since August 2, 2026, with possible fines for non-compliance. Neither replaces the other.
Does an SME need to act now because of this announcement?
No. No obligation or technical change follows at this stage. These are discussions between labs, not a finalized framework. Simple monitoring is enough.
When could SAFA officially launch?
According to the reporting, a launch is targeted for late 2026 or early 2027, with no date or legal structure confirmed as of now.
In conclusion
SAFA's announced creation illustrates a broader trend: major AI providers are trying to prove their seriousness before the law forces them to everywhere. For an SME, the point is not to track every announcement, but to keep two simple markers in mind: legal compliance (AI Act, GDPR) is never optional, and a provider's seriousness is also judged by its transparency on safety. To dig deeper into your current regulatory obligations, see our complete guide to the EU AI Act or explore more LUWAI Mag resources.


