DeepMind CEO Demis Hassabis has renewed the debate over how frontier AI should be governed, arguing that the industry needs something more structured than voluntary safety promises and internal testing. In a proposal that borrows from an unlikely reference point—FINRA, the U.S. financial industry’s self-regulatory organization—Hassabis called for an independent “standards body” tasked with evaluating frontier models and helping define best practices for how they are released.
The core idea is straightforward: if frontier AI systems are going to be deployed widely, they should face consistent, external scrutiny before they reach the public. But the implications are anything but simple. A FINRA-style model would not just add another layer of compliance paperwork; it would reshape the incentives around safety evaluation, standardize what “good enough” looks like, and potentially create a shared language for risk—something the AI sector has struggled to establish as capabilities race ahead of governance.
What makes Hassabis’s framing notable is that it tries to bridge two worlds that often clash in AI policy discussions. On one side are calls for government regulation—rules enforced by law, backed by penalties, and designed to protect the public. On the other side are arguments for industry-led standards—flexible frameworks that can move faster than legislation and adapt to technical change. Hassabis appears to be aiming for a third path: an independent body that is neither purely governmental nor purely corporate, but still has teeth through standardized testing expectations and release practices.
To understand why this matters, it helps to look at what “frontier AI” means in practice. These are not ordinary software updates. They are large, general-purpose systems whose behavior can shift with new training runs, new fine-tuning, new tool integrations, and even changes in deployment context. Their risks are also not limited to one category. Frontier models can fail in ways that are hard to predict: they may produce persuasive misinformation, enable harmful instructions, leak sensitive information, or behave unpredictably when prompted in novel ways. And because these systems can be embedded into products used at scale, the blast radius of a mistake can be enormous.
Right now, much of the safety evaluation happens inside companies. That approach has obvious strengths—teams have access to the model, the training pipeline, and the engineering context needed to run targeted tests. But it also has a structural weakness: internal evaluation can be difficult to compare across providers, and it can be hard for outsiders to verify whether a given model was assessed using rigorous, relevant criteria. Even when companies are acting in good faith, the absence of shared standards makes it difficult to answer basic questions like: Was this model tested against the right threat scenarios? Were the results independently validated? How do we know the evaluation is robust rather than cherry-picked?
Hassabis’s proposal is essentially an attempt to solve that comparability problem. A standards body modeled after FINRA would aim to create baseline expectations for testing and release, so that the market—and regulators, researchers, and the public—can better understand what was done and what was found.
The FINRA analogy is instructive, even if it’s imperfect. FINRA is known for setting rules and overseeing compliance in parts of the financial sector, with an emphasis on standardized processes and accountability. Translating that concept to frontier AI would likely mean establishing a framework for pre-deployment assessment: defining test suites, requiring certain categories of evaluation, and publishing enough information to allow meaningful comparison. The goal wouldn’t necessarily be to “approve” every model in a binary way. It could be more nuanced—think of it as a structured gatekeeping process that determines whether a model meets minimum safety thresholds for particular kinds of release.
But the devil is in the details, and those details will determine whether such a body becomes a meaningful safeguard or a symbolic exercise.
One of the most important questions is what the standards body would actually test. Frontier AI risks are broad, and no single benchmark can capture them all. A credible system would need to combine multiple evaluation approaches: automated red-teaming, adversarial testing, robustness checks across prompt variations, assessments of misuse potential, and evaluations of how models behave under different deployment conditions. It would also need to consider the difference between capability and control. A model might score well on certain safety benchmarks while still being dangerous in edge cases—especially when paired with tools like web browsing, code execution, or automation workflows.
A standards body could help by insisting that evaluation is not limited to static metrics. It could require stress testing that reflects real-world usage patterns, including attempts to bypass safety filters, generate harmful content in disguised forms, or exploit model weaknesses through multi-step interactions. It could also push for transparency about evaluation methodology—what tests were run, what failure modes were observed, and what mitigations were applied.
Another key question is independence. Hassabis’s call for an independent body is meant to address a central legitimacy issue: if the same companies building frontier models also control the standards, the system risks becoming self-referential. Independence doesn’t automatically guarantee rigor, but it can improve trust by reducing conflicts of interest. In a FINRA-like structure, independence would ideally include governance mechanisms that prevent capture by any single provider, along with funding and oversight arrangements that keep the body accountable to broader stakeholders.
There’s also the matter of enforcement. Standards bodies can set guidelines without having the power to compel compliance, which limits their impact. If the goal is to influence release decisions, the body would need a mechanism that affects outcomes—whether through contractual requirements, regulatory alignment, or market incentives. For example, if major deployments require certification or adherence to specific testing protocols, then companies would have strong reasons to participate seriously. Without that kind of leverage, standards risk becoming optional best practices, which the industry has already demonstrated it can ignore when timelines tighten.
Hassabis’s proposal implicitly recognizes that the AI sector is moving faster than traditional governance cycles. Frontier models can be updated frequently, and the pace of iteration can outstrip the ability of regulators to craft detailed rules. A standards body could provide a faster-moving framework that evolves with technology. But speed introduces its own risk: if standards update too slowly, they become irrelevant; if they update too quickly without consensus, they become unstable and hard to follow.
That tension suggests a standards body would need a careful cadence—regular updates to test suites and release practices, with clear versioning so that companies and evaluators can track changes over time. It would also need to manage the relationship between research and deployment. Many safety techniques are still experimental, and some evaluation methods may be incomplete. A credible standards body would have to decide how to incorporate emerging best practices without pretending that early-stage methods are definitive.
There is also a deeper philosophical challenge: what does it mean to “release” a frontier model? In finance, products and services have relatively clear boundaries. In AI, release can mean many things: open weights, closed API access, integration into consumer apps, or deployment through enterprise tooling. Each release mode changes the risk profile. A model released as open weights might be harder to control, while a model accessed via API might be subject to usage policies and monitoring. A standards body would need to define release categories and tailor expectations accordingly.
This is where Hassabis’s “best practices” emphasis becomes important. Rather than treating all releases identically, a standards body could create tiered requirements. For instance, higher-risk release modes might require more extensive evaluation, stronger mitigations, and additional monitoring obligations. Lower-risk modes might still require baseline testing but with fewer burdens. The goal would be proportionality—matching oversight intensity to plausible harm.
Monitoring after release is another area where a FINRA-style approach could be adapted. Financial oversight doesn’t end at onboarding; it includes ongoing compliance expectations. For AI, post-deployment monitoring could include tracking misuse indicators, auditing outputs for harmful patterns, and responding to newly discovered vulnerabilities. A standards body could require that companies not only test before release but also maintain a feedback loop that updates mitigations when new failure modes emerge.
That said, post-release monitoring raises its own concerns. Continuous surveillance of model behavior can be technically challenging and may create privacy issues depending on what data is collected. It can also create incentives to minimize reporting of failures. A standards body would need to define what monitoring entails, what data can be used, and how results should be reported in a way that supports learning rather than hiding problems.
One unique take on Hassabis’s proposal is that it could shift the conversation from “safety as a claim” to “safety as a process.” Today, many safety discussions revolve around statements like “we tested for X” or “we believe the model is safe enough.” Those claims are difficult to verify externally. A standards body could make safety more procedural: it would specify what steps must be taken, what evidence must be produced, and how results should be interpreted. That doesn’t eliminate uncertainty, but it reduces the gap between what companies say and what outsiders can evaluate.
In other words, the standards body could function as an institutional memory for the field. Over time, it could accumulate knowledge about which tests correlate with real-world harms, which mitigations reduce risk, and which evaluation methods are misleading. That would be valuable because AI safety is not just about preventing known failure modes—it’s about anticipating unknown ones. A shared process can help the industry learn faster than isolated teams.
Still, there are legitimate criticisms. Some worry that a standards body could become a bottleneck that slows innovation or creates a de facto approval regime that favors incumbents. Others fear that certification could be treated as a shield: once a model passes a checklist, companies might feel less pressure to go beyond it. There’s also the risk that standards could be gamed—companies might optimize for what gets measured rather than what matters.
These risks argue for designing standards that are hard to game and that emphasize adversarial evaluation. The standards body would need to ensure that test suites include unpredictable scenarios and that evaluation is not limited to static prompts. It would also need to incorporate independent red-teaming and possibly involve external experts who can challenge assumptions. If the body is truly independent, it could serve
