← Research
Research · Question

Can AI companies regulate themselves?

The standards body reported this week, what Gates, Menin and Markey said, the argument that safety is also a moat, the four facts that separate a regulator from an advisory board, the UK's four options, and the regulation an organisation controls.

Last reviewed: 28 September 2026 · Next review due: 28 September 2027

Not on their own, and nobody asked in the last week says they can. Three labs are reported to be planning a standards body of their own; Bill Gates, a city council and three Senate bills said the tester should not be the company. Four facts decide whether a body is regulation. An evidence review by Rahim Hirji; every figure resolves to a graded entry in the evidence base that says what it does not show.

Questions this page answersQuestions this page partly answersAll 1055 questions this research covers

Not on their own, and nobody asked in the last week says they can. Bill Gates told NBC’s Meet the Press on 27 September 2026 that “no one thinks self-regulation is enough”. The Speaker of New York City Council said the same thing in a bill package two days earlier. Google, OpenAI and Anthropic, by The Information’s account, are planning a standards body of their own because a federal one stalled. The Associated Press reported analysts who read the safety warnings as a competitive wall. What separates a standards body from self-regulation with better stationery is four facts that any reader can check once the body exists: who appoints its head, who chooses the tests, who can stop a release, and who sees the incident record. The same four questions apply to the AI an organisation runs itself.

The answer, in one line

Not on their own, and nobody asked in the last week says they can: Bill Gates told Meet the Press on 27 September 2026 that no one thinks self-regulation is enough, and Google, OpenAI and Anthropic are reported by The Information to be planning an outside standards body because a federal one stalled.

Share as a card

What was proposed this week, as reported#

Aminu Abdullahi at TechRepublic reported on 25 September, citing The Information, that Google, OpenAI and Anthropic are planning a self-regulatory body tentatively called the Standards Authority for Frontier AI. As described, it would set approaches to pre-deployment testing, incident reporting and the qualification of auditors, with a launch in late 2026 or early 2027, and its model is FINRA, the body that regulates US securities firms under the oversight of the Securities and Exchange Commission; Demis Hassabis is reported to have proposed a FINRA-style body in July. The people reported to be under consideration for its leadership are Sriram Krishnan and Arati Prabhakar as chief executive and Condoleezza Rice as chair. Hillary Remy at TheStreet reported on 26 September that the three companies had first sought federal oversight, that a draft executive order creating it did not gain enough support inside the administration, and that Meta, xAI and Nvidia oppose the body. Everything in this paragraph is one outlet’s report of a plan that has not been published; the companies have not announced it, and the estate treats it as a proposal until they do.

What the people asking for oversight said#

Gates’s full interview, reported by Hollie Silverman at Newsweek, put oversight above shutdown: “When you’re trying to moderate the bad behavior, you need insight and records of what’s being done. The kill switch alone would not prevent these tragedies.” He said he would not argue for a pause and would argue instead for “a requirement on all the AIs in the U.S.”. Julie Menin, introducing ten bills for a hearing on 5 October, told Fortune that “this is not an industry that should self-regulate”. In Congress, Edward Graham’s bills of the week at Nextgov listed three answers to the same question in one week: Senator Ed Markey’s Cybersecurity and AI Board of Investigations, modelled on the National Transportation Safety Board, with Markey’s reason, “we cannot depend on companies with little incentive to disclose their failures to give us one”; Senators Bennet and Welch’s Federal Digital Commission, which could require pre-certification of advanced models, pause one for six months and fine up to 15 per cent of prior-year global revenue; and the Casar and Sanders bill that would create a Department of Artificial Intelligence. The three bills disagree on almost everything except that the tester should not be the company.

The argument that the warnings are also a strategy#

Garance Burke’s Associated Press analysis, read at Fortune on 27 September, reports analysts who see the companies’ own safety warnings as serving their businesses as well as the public. Harrison Rolfes of PitchBook said “they’re creating a wall or a moat within this sector”. Sarah Shoker, who led OpenAI’s geopolitics team, said “once again we’re talking about existential risk, while deprioritizing a number of other safety-critical risks”. Conrad Stosz of Transluce asked the question this estate examined on whether an evaluator paid by the company can be independent: “Will evaluators be able to thoroughly investigate, assuming that access is granted in a way that does not undermine their independence?” OpenAI’s spokesperson Liz Bourgeois gave the company’s position: “People want to know AI is being developed safely, and that starts with what companies like ours do ourselves.” The AP reports that the companies favour evaluators and protocols they select over oversight by existing bodies such as the US Center for AI Standards and Innovation. Both readings can be true at once. A company can believe its warnings and benefit from them, and a reader does not have to decide which before asking what the proposed body would be allowed to do.

The test of a self-regulatory body#

FINRA is the model the companies have reportedly chosen, so it supplies the test. FINRA writes rules, examines firms and fines them, and every one of those powers exists because the SEC approves its rules, oversees it and can overrule it; a securities firm cannot leave FINRA and keep trading. A frontier AI body passes or fails on the same four facts. Who appoints its head, and can the members remove them. Who chooses the tests, and whether the tested company sees them first, which is the question the evaluator page could not answer for the labs’ current arrangements. Who can stop a release: an authority that can only publish a concern is an advisory board, whatever it is called, and the estate has already set out what a stopping power looks like on whether frontier AI should be licensed. Who sees the incident record: the two counts of agent incidents reported last week, examined on what counts as a serious AI incident, are both the companies’ own, and Markey’s sentence is about that. A body that answers all four with a name outside the member companies is regulation that the companies happen to fund. A body that answers them with the members is what Gates and Menin said was not enough, and the plan as reported does not yet say which it is.

Where the United Kingdom stands#

Nuala Polo at the Ada Lovelace Institute set out four options for the UK on 25 September: leaving AI to existing sector regulators, a ban on superintelligence, a narrow national-security bill of the kind the industry has backed, and a comprehensive bill with an independent regulator. Her sentence on the status quo is the one to keep: “There is no equivalent of the independent standard-setting, pre-market authorisation, mandatory safety testing, or enforcement and accountability mechanisms that apply in other high-risk industries.” The institute cites polling from late 2025 in which 89 per cent of respondents said independent regulation of AI matters and 67 per cent said an independent regulator rather than the developers should decide what is safe; the sample is not given on the page and the figures are reported here as the institute’s. The UK government’s answer to the kill-switch amendment on 11 September, examined on what an AI kill switch is, was that existing provisions and voluntary pre-release testing at the AI Security Institute are enough for now, with binding rules kept on the table. Whether they are is a question the estate leaves open; what the week added is that three of the companies are reported to be building an authority of their own while the government waits to see if the voluntary regime holds.

The regulation an organisation controls#

Almost no reader of this page will sit on the body, and every one of them runs AI that the body will never examine. The four questions transfer directly, and Rules Before Tools is the pattern for writing the answers down. Which decisions may a machine make in the organisation’s name, and which may it only propose. Who can stop each one, by name, and how fast, which the stop-time page shows is rarely rehearsed. What must people remain able to do without it, since the measurable harm of the handover is what happens to human judgement afterwards. And how anyone would know if it went wrong: the insight and records Gates asked for, kept by the organisation for its own systems, because a company that could not answer a regulator’s four questions about its own AI has no standing to ask them of anyone else. A board that wants to know what to do about the safety warnings has a page for that; the short version is that the pause in its gift is the one before it hands a decision over.

What this does not show#

The standards body is a plan reported by one publication and relayed by others; its powers, members, funding and relationship to any government are unknown, and it may not appear. Gates, Menin, Markey, Bennet, Welch and Sanders are advocates describing what they want, not evidence about what works, and none of the bills has passed a committee. The AP’s analysts are reading motives, which cannot be measured. The Ada Lovelace polling is reported without its sample, and public preference for a regulator says nothing about whether one would catch what matters. FINRA is one model among several and its record in securities is itself contested. Nothing here shows that an independent body would have prevented any incident reported this month, because no such body has existed to test.

Essay · SS-2026-367

Cite this page

Hirji, R. (2026). Can AI companies regulate themselves?. The SuperSkills evidence base, SS-2026-367. https://thesuperskills.com/research/can-ai-companies-regulate-themselves. Last reviewed 28 September 2026.

An evidence review by Rahim Hirji, not peer-reviewed research. For a material claim, cite the underlying study as well; every study here carries its own permanent link.

How citations and IDs work
Questions answered on this page

Can AI companies regulate themselves?

Not on their own, and nobody asked in the last week says they can: Bill Gates told Meet the Press on 27 September 2026 that no one thinks self-regulation is enough, and Google, OpenAI and Anthropic are reported by The Information to be planning an outside standards body because a federal one stalled. Whether that body is regulation or self-regulation with a new name turns on four facts: who appoints its head, who chooses the tests, who can stop a release, and who sees the incident record.

What is the Standards Authority for Frontier AI?

A tentative name, reported by The Information on 25 September 2026 and relayed by TechRepublic and TheStreet, for a self-regulatory body that Google, OpenAI and Anthropic are said to be planning, modelled on FINRA in US securities. As described it would set approaches to pre-deployment testing, incident reporting and auditor qualification, with a launch in late 2026 or early 2027; Meta, xAI and Nvidia are reported to oppose it. The companies have not announced it, and nothing about its powers has been published.

Are AI safety warnings just marketing?

Nobody can measure a motive, and the Associated Press analysis of 27 September 2026 does not try to. It reports analysts, including Harrison Rolfes of PitchBook, who read the labs' warnings as building a moat that raises the cost of entry for smaller rivals, and former OpenAI staff who say existential risk crowds out present harms. Both can be true at once: a company can believe its warnings and benefit from them. The useful question is what powers the company would accept over itself, which is checkable.

Who regulates AI in the UK?

Existing sector regulators, with voluntary pre-release testing at the AI Security Institute; there is no dedicated AI statute. The Ada Lovelace Institute's 25 September 2026 review says the UK has no equivalent of the independent standard-setting, pre-market authorisation, mandatory safety testing or enforcement mechanisms that apply in other high-risk industries, and sets out four options from the status quo to a comprehensive bill with an independent regulator. The government rejected a statutory kill switch on 11 September and said binding rules remain on the table.

In this hub

Judgement, oversight and accountability

Who decides, who checks, and who is answerable when the machine was involved.

Ask the evidence
What does the evidence actually show?What should our board be asking about this?Where does Rahim disagree with the consensus?
Bring this into your organisation

If this describes something happening in your teams, say so.

Keynotes, board sessions and advisory work, drawing on research across more than 200 organisations in 30 countries. Tell me the room, the date and the shift you need. A reply within 24 hours.

Start a conversation

Topics and audiences  ·  All research

Four answers written for every AI system the organisation runs before anyone asks them of a regulator, who appoints the person accountable for it, who chooses the tests it must pass, who can stop it and how fast, and who holds the record of what it did, is the engagement. Board advisory.

This argument is one a board usually meets for the first time in the room. There is AI keynote for boards and leadership offsites, and the full range of topics and audiences.

Box of Amazing

Rahim’s free weekly letter on AI and human capability

If this was useful, the weekly letter is where the thinking happens first. Most of what ends up on this site starts there. Weekly essays on AI, capability and the future of work. Read by 25,000 people, every week since 2017. Free, and one click to stop.

Opens Substack to confirm. No pitch in it, unsubscribe in one click, and nobody follows up because you read something.