AI-generated content. This article was researched and written by an automated AI editorial system and published without prior human review. Every factual claim is checked against cited primary sources before publication, but no journalist read this page before you did — treat it accordingly, and report anything that looks wrong. How this works ›

Some links on this page are affiliate links. We may earn a commission at no extra cost to you.
Updated: Sep 15, 2026
·
policygovernanceai-safetyprocurementmicrosoftanthropicopenaigooglecohere

Three labs have been building a private AI standards body since July — without the antitrust waiver their own proposal says it needs

TL;DR: On 13 September 2026, The Information reported that executives at Anthropic, OpenAI and Google DeepMind have been meeting in working groups since July on an industry-run body to set safety benchmarks, testing and auditing rules — talks that predate Dario Amodei’s public call for exactly that coordination by two months. Amodei’s essay, published 12 September, states that such discussions need the US government to “issue a narrow waiver for certain kinds of safety conversations” for antitrust reasons. No such waiver exists. The government-led alternative died in May when Musk, Zuckerberg and David Sacks talked Trump out of signing it; EO 14409 as signed on 2 June is explicitly voluntary with no licensing power. Cohere CEO Aidan Gomez responded: “Here comes a great idea from the cartel.” Satya Nadella did something different — he endorsed pacing and embedded evaluators, then announced that Microsoft would publish, for public consultation, the behavioural rules governing its own MAI models, the same first-party lineup whose coding model became the default engine inside GitHub Copilot in August. Markets took it seriously: SoftBank fell as much as 13% on Monday, the Kospi 3.3%. The buyer-side split is the entire story. A standards body is a membership. A code of conduct is a document. Only one of those can be read, versioned, diffed and put in a contract.

The sequence is the story

Run the dates in order and the shape becomes hard to miss.

July 2026 — working-group meetings begin among Anthropic, OpenAI and Google DeepMind, at executive level below the CEOs, on a body that would set safety benchmarks and auditing protocols for the industry. This is reported by The Information on 13 September, sourced to people familiar with the matter, and has not been publicly announced by any of the three.

28 July 20261,100-plus employees across four labs sign a public letter asking the US government to build the capability to pace frontier AI.

12 September 2026 — Amodei publishes the pacing essay. Step two asks frontier companies in democracies to coordinate on common safety standards and capability checkpoints, framed as a thing that has not happened yet and requires government enablement to happen safely.

13 September 2026 — it emerges that step two has been happening since July.

None of that is scandalous on its own. Companies talk. Trade associations exist in every industry, and the ones in aviation and pharmaceuticals are load-bearing. But the essay did not describe step two as underway, and it did name a precondition that is still missing.

The precondition

The exact sentence, from the essay:

For antitrust reasons, it’s helpful for the US government to mediate or at least enable these discussions — they don’t need to participate, but do need to issue a narrow waiver for certain kinds of safety conversations.

That is the author of the proposal conceding that competitors agreeing among themselves to constrain a product attribute is conduct that draws scrutiny regardless of motive. Safety is a defence to be argued, not an exemption that applies automatically.

The waiver was never granted, and the machinery that might have granted it was dismantled four months ago. On 21 May, Trump postponed signing an AI executive order hours before the ceremony, after direct calls from Elon Musk, Mark Zuckerberg and David Sacks — who characterised the proposed 90-day voluntary pre-release review as “a DMV for AI,” with models “lined up in a queue, waiting to get their test done.” The order that eventually landed on 2 June shrank the window to 30 days, kept participation voluntary, and wrote in explicit language disclaiming any “mandatory governmental licensing, preclearance, or permitting requirement.”

So the private body is not filling a vacuum that nature left. It is filling a vacuum that three of the industry’s own principals lobbied into existence, and it is doing so without the legal cover its most prominent advocate says the work requires. Altman’s position, per the reporting, is that the labs will have to do it themselves precisely because government support is not coming.

Gomez used the right word

Cohere’s Aidan Gomez posted on X that this was “a great idea from the cartel,” arguing that regulation of this shape suppresses smaller competitors.

The self-interest is obvious and should be stated: Cohere sells enterprise-only frontier models and, since the April merger with Aleph Alpha, positions itself as a transatlantic sovereign-AI challenger. A compliance surface built by the three largest labs is not a surface it would enjoy clearing.

It is also the correct legal category, which is the part worth keeping. “Cartel” here is not name-calling that happens to rhyme with the facts. It is the specific hazard that Amodei’s requested waiver was drafted to carve out. Gomez and Amodei agree on the diagnosis and split on the remedy: Amodei wants the conduct licensed, Gomez wants it abandoned. Neither of them thinks the question is imaginary.

For anyone buying AI tools, that agreement is the useful part. It means the “is this just competitors coordinating?” question does not need to be adjudicated by outsiders. Both sides have already conceded it is live.

Microsoft declined the club and shipped an artifact

The most interesting move of the weekend came from the vendor not named in the reporting.

Nadella’s 13 September post welcomed “deliberate pacing,” endorsed the embedded-evaluator idea, and compared independent evaluation to audits in finance and testing in pharmaceuticals. It also contained a line that reads as a direct response to a three-company standards body: alignment governance “cannot be controlled by a handful of entities,” and must be broadly representative across academia, countries and ecosystems.

Then it did the thing that separates this from the rest of the cycle. Nadella announced that Microsoft would publish, on 14 September and for public consultation, a Code of Conduct for its own first-party MAI models — the family introduced under Mustafa Suleyman at Build in June, covering reasoning, coding, image generation, transcription and voice. Suleyman called the underlying position “straightforward common sense,” adding that any technology failing to serve humanity “is a failure, and should be rejected.” Nadella’s governing quote:

Any pursuit of superintelligence has to be grounded in the core principle that if the AI we build is not helping humanity and under human control, it’s not worth pursuing.

Set the rhetoric aside. The structural fact is that this is the first time Microsoft has published behavioural standards for its own models, and the timing matters more than the prose. Microsoft’s first-party coding model, Project Polaris, became the default engine for paid GitHub Copilot subscribers in August — roughly 20 million seats migrated automatically, with the GPT-4 Turbo fallback window closing in November. That is one of the largest deployments of a first-party model anywhere, and until this week the behavioural rules governing it were not public.

The version table is the point

Here is the detail that makes the comparison concrete rather than rhetorical.

Microsoft already publishes a document called a Code of Conduct. The Code of Conduct for Microsoft AI Services is at version 4.0, dated 1 May 2026, and carries a document history table recording every revision since February 2025 with a summary of what changed in each. It binds customers: disclosure requirements for AI-generated output, watermarking and content-credential obligations for video, human-oversight requirements for autonomous systems, and a long prohibition list running from facial recognition for US local police to CBRN content.

That document is enforceable against you. It is also, for exactly that reason, the model of what a governance artifact looks like when someone means it: a URL, a version number, a date, a changelog, and consequences named in the text.

The new MAI code points the obligation the other way. Whether it arrives with the same apparatus — a version, a date, a revision history, a statement of what happens when a model violates it — is the only question worth asking about it, and it is answerable by reading the published file rather than by trusting a description of it. That includes this one.

Now put a standards body next to that. As of 14 September there is no charter, no membership list, no name, no publication rule, no date, and no statement of what a failed benchmark does to a vendor. The FLI 2026 AI Safety Index had to grade nine labs largely on public statements because there was nothing firmer to grade, and found commitments being quietly walked back. OpenAI’s Frontier Governance Framework is a published document and a genuinely better artifact than a forum membership — but it is also a document OpenAI revises unilaterally.

The pattern this desk keeps running into

The through-line across the last month of agent and governance coverage is monotonous and keeps being right: the control expressed as an instruction fails, and the control expressed as structure holds.

A criminal operator’s own 28-country exclusion list was ignored by the hundreds of agents it was written for, because an exclusion list in a prompt is a suggestion. Meta’s Rule of Two turned out to be policy rather than cryptography — a real improvement, and not a guarantee. Frontier capability is increasingly reached through clearance tiers rather than purchase orders, which is structure, and it binds.

Governance splits along the same seam. A membership is an instruction to yourself. A published, versioned document with a changelog is closer to structure, because departures from it are visible to people outside the organisation without the organisation’s cooperation. That is the same property that made the evaluator publication right the only durable item in Saturday’s news cycle.

Markets priced it

Monday was not kind to the assumption that safety talk is costless. SoftBank Group — OpenAI’s largest outside backer — fell as much as 13% intraday and closed down about 10.7%. The Nikkei 225 slid 0.8% to 63,492.99 and South Korea’s Kospi dropped 3.3% to 6,684.37, with chipmakers and memory suppliers leading the decline.

One session proves very little about whether a standards body materialises. It does establish that this particular form of announcement has a price, which is a useful thing to know about how often it will be repeated.

What to do with this

  1. Ask every model vendor for a URL and a version number. The question is: what published document states the behavioural rules your models are held to, and when was it last revised? Claude, ChatGPT, Gemini, Cohere and Microsoft will give five different quality answers, and the differences are informative at zero cost.
  2. Treat forum membership as marketing, not assurance. A body with no charter cannot be breached. If a vendor cites participation in an industry standards effort in a security questionnaire, the follow-up is: what document, what version, what happens on failure.
  3. Push on portability instead of conformance. Nadella put enterprise control of learning loops and model weights alongside the code of conduct. Of those two, portability is the one that survives a vendor changing its mind. Standards can be redefined by whoever writes them; an exit cannot be redefined by anyone but you.
  4. Keep a non-member vendor evaluated, not necessarily deployed. If the three largest labs converge on a shared compliance surface, the vendors outside it — Cohere, Mistral, Meta, the Chinese open-weight labs — become a distinct tier with different pricing and different constraints. Knowing what that tier can and cannot do for your workload is cheap now and expensive later. The agent tooling roundup and the Claude vs ChatGPT comparison both track where those substitutions are clean.
  5. Do not switch vendors over this. Nothing shipped. No model changed. No price moved. A weekend of essays and an unannounced working group are not a migration trigger, and anyone selling them as one is overreading.

The honest read

An industry body that sets real testing standards would be a genuine improvement on the present situation, which is nine labs grading their own homework and a government that declined the job in May. It is entirely possible this is what it looks like when something useful gets built.

But it is being built by three companies, in private, since July, without the antitrust cover its own advocate says it needs, and with the first outside vendor to comment calling it a cartel. None of that makes it illegitimate. All of it makes it something a buyer cannot yet rely on.

The reliable objects this week are smaller and duller: an evaluator publication right that can be tested when it is first tested, and a behavioural document with a version number that can be read today. Developers and engineering leads evaluating stacks over the next quarter should weight accordingly — and re-check the MAI code against its own published text rather than against anyone’s summary, including this one.

Update, later on 14 September 2026: the same argument has a commercial twin this week. The case above is that a membership is not a control and a versioned document is. The pricing equivalent arrived the same day: Anthropic’s Claude Code weekly limits fell 17% against a base the company has never published, while Financial Times reporting put its inference gross margins above 80% and its listing near a $2tn target. A published per-token rate card is a document; a percentage of an undisclosed weekly allowance is a membership. See Anthropic’s 80% inference margin and the Claude Code limit cut.

Update, 15 September 2026 — OpenAI says it does not need the waiver

The open question in this article was whether the working groups reported by The Information would pause for the narrow antitrust waiver Amodei’s essay says such conversations require. They will not, and both answers arrived within two days.

On 14 September, David Sacks — until recently the administration’s AI czar, and one of the three people who talked Trump out of signing the standards-body executive order in May — told the labs to keep building and stop seeking an antitrust waiver or an approval regime, on the grounds that they do not need legal cover to build safe products.

On 15 September, OpenAI confirmed to Bloomberg that it has been working with Anthropic and Google on safety for several weeks, and stated that it does not need an antitrust waiver to coordinate on safety. The Washington Post reported the same discussions on 14 September alongside the administration’s opposition to any slowdown.

So the waiver this article flagged as missing is now missing by choice rather than by delay. The three participants have concluded that safety coordination does not raise the question Amodei’s own essay conceded it raises, and the one official who might have granted the waiver has said it is unnecessary.

For a buyer, this sharpens the article’s conclusion rather than changing it. The gap between a membership and a document just got wider: the body is proceeding without the legal predicate its own chief proponent named, which means its output is even less likely to arrive as anything you can point a contract at. Meanwhile OpenAI’s separate endorsement of the FRONTIER Act’s Independent Verification Organization provision the same day is the more consequential move, because a statute is the one form of this that would bind participants and non-participants alike — see the pacing essay’s updated file. Keep buying against documents, not memberships. Nothing about that has changed; there is simply now one more document worth naming in a questionnaire.

Frequently asked questions

What exactly is the AI standards body that Anthropic, OpenAI and Google are discussing?

According to The Information's 13 September report, citing people familiar with the matter, executives below CEO level at Anthropic, OpenAI and Google DeepMind have been meeting in working groups since July 2026 to discuss an industry-led body that would set safety benchmarks and other shared rules, including protocols for model testing and auditing. It has no published charter, no announced membership criteria, no name, no governance structure and no stated date. Sam Altman has told an OpenAI employee meeting that he supports a testing and auditing body and believes the major labs will have to build it themselves without US government support. That is the entire public record as of 14 September 2026. Everything else about it — whether it would publish, who could join, what happens to a vendor that fails a benchmark — is currently unknown, and a buyer should treat unknown as the operative word rather than as a detail to be filled in later.

Why does the antitrust waiver matter if this is all voluntary?

Because Amodei's own essay says it matters. Step two of 'We Must Pace the Frontier' proposes that frontier companies in democratic countries coordinate on common safety standards and on limits to the rate of unchecked AI progress, and then states directly: 'For antitrust reasons, it's helpful for the US government to mediate or at least enable these discussions — they don't need to participate, but do need to issue a narrow waiver for certain kinds of safety conversations.' That sentence is an acknowledgement by the proposal's author that competitors agreeing among themselves to limit a product attribute is the sort of conduct that attracts antitrust scrutiny, whether or not the motive is safety. The waiver does not exist. The Trump administration's draft order for a government-led standards body stalled amid internal opposition, notably from David Sacks, and Executive Order 14409 as actually signed on 2 June 2026 is explicitly voluntary and explicitly disclaims any mandatory licensing or preclearance regime. So the discussions reported by The Information began roughly two months before the waiver was publicly requested, and are continuing without it.

Is Cohere's 'cartel' comment just a smaller vendor protecting its position?

Partly, and that does not make it wrong. Aidan Gomez's post on X — 'Here comes a great idea from the cartel' — came with the argument that regulation of this kind suppresses smaller competitors, which is obviously in the interest of a company positioned as an enterprise and sovereign-AI challenger rather than a frontier-scale incumbent. Self-interest is visible on both sides of this argument: the three labs proposing the body are also the three with the most to gain from a compliance surface that is expensive to clear. What makes the objection worth recording is that 'cartel' is not merely an insult here; it names the exact legal category that Amodei's requested waiver was designed to carve out. The disagreement between Gomez and Amodei is not about whether competitor coordination on product limits raises the question. Both of them concede that it does. They disagree on whether the answer should be a waiver or a refusal.

What is Microsoft's MAI Code of Conduct, and how is it different from the code of conduct Microsoft already has?

Microsoft already publishes a Code of Conduct for Microsoft AI Services, currently at version 4.0 dated 1 May 2026, with a document history table recording four revisions since February 2025. That document binds customers: it sets out what buyers may and may not build with Microsoft AI services, from disclosure obligations for synthetic media through to prohibitions on facial recognition for US local police and on CBRN content. The document Nadella announced on 13 September, slated for publication on 14 September for public consultation, is a different object pointed the other way: behavioural rules for Microsoft's own first-party MAI models, the in-house family introduced under Mustafa Suleyman at Build in June 2026 spanning reasoning, coding, image generation, transcription and voice. Microsoft has never previously published the behavioural standards its own models are held to. Confirm the published text and its version before relying on any characterisation of its contents, including this one — as of writing, the announcement is verifiable and the document's provisions are not.

What should an organisation actually change in its AI procurement because of this?

One question and one clause. The question: for each model vendor in your stack, ask what published, versioned document states the behavioural rules their models are held to, and when it was last revised. A vendor that can answer with a URL and a version number is offering something you can diff, cite in a contract and re-check next quarter. A vendor that answers with membership in a forum, a signed statement of principles, or participation in an industry body is offering something that cannot be breached because it does not say anything. The clause: press on portability rather than conformance. Nadella's framing on 13 September put enterprise control of learning loops and model weights alongside the Code of Conduct as parallel commitments, and of the two, weight and data portability is the one that survives a vendor changing its mind about standards. Conformance claims are revocable by the standard-setter. An exit is not.

Did markets treat the pacing story as real, or as public relations?

As real, at least for one session. On Monday 14 September, Asian AI-linked equities sold off on the weekend's pacing messaging: SoftBank Group, OpenAI's largest outside backer, fell as much as 13% intraday and closed down roughly 10.7%; Japan's Nikkei 225 slid 0.8% to 63,492.99; South Korea's Kospi lost 3.3% to 6,684.37, with chipmakers and memory suppliers among the worst hit. A single session is weak evidence of anything durable, and the move is better read as investors repricing the growth path than as a judgement on whether a standards body will exist. But it does answer one question cleanly. The common dismissal of safety announcements is that they cost the announcer nothing. This one cost SoftBank about a tenth of its market value in a day, which is a real constraint on how often the labs can repeat the exercise.

Sources

Related tool reviews

Questions or corrections? Email Pick Right. Want the full list? See all news.