The 2026 AI Safety Index: Anthropic tops the class, but nobody scores above a C+ — what the lab rankings mean for buyers
TL;DR: The Future of Life Institute’s Summer 2026 AI Safety Index graded nine frontier labs across 37 indicators in six domains, judged by an independent seven-expert panel (evidence cutoff June 3). Anthropic ranked first — with a C+, leading five of six domains. OpenAI and Google DeepMind got C (OpenAI led Risk Assessment); Meta a D+; Z.ai and Alibaba Cloud D-; and xAI, DeepSeek, and Mistral effectively failed (F). No lab scored an A or B. The most important finding isn’t the low ceiling — it’s that labs are walking back the “red line” commitments they made a year ago (pledges to pause or restrict if models got too risky), right as the GPT-5.6 / Grok 4.5 / Gemini race accelerates. What this means for you: use it as one trust signal, weighted by how much risk your use actually carries.
What the index found
The Future of Life Institute (FLI) publishes a periodic “report card” on how the major AI labs manage safety. The Summer 2026 edition evaluated nine companies on 37 indicators across six domains — risk assessment, current harms, safety frameworks, existential safety, governance and accountability, and information disclosure — with an independent panel of seven AI researchers and governance experts assigning grades against absolute standards. Evidence was collected through June 3, 2026, combining public materials (model cards, papers, benchmarks) with a targeted company survey.
The grades:
| Lab | Grade |
|---|---|
| Anthropic (Claude) | C+ |
| OpenAI (ChatGPT) | C |
| Google DeepMind (Gemini) | C |
| Meta (Llama) | D+ |
| Z.ai | D- |
| Alibaba Cloud (Qwen) | D- |
| xAI / SpaceXAI (Grok) | F |
| DeepSeek | F |
| Mistral | F |
Anthropic earned the highest overall grade and led five of the six domains, on the strength of relatively strong transparency, an established safety framework, technical research, and governance. OpenAI led the Risk Assessment domain specifically, on a broader evaluation suite and diverse external testing. And the headline nobody can spin away: no company scored an A or a B. The best the frontier could manage was a C+.
The six domains behind the grades
A single letter compresses a lot. The index scores each lab across six domains, and the domain-level picture is more actionable than the headline number:
- Risk assessment — whether the lab systematically tests for dangerous capabilities before release. OpenAI leads here, on a broader evaluation suite and more diverse external testing.
- Current harms — how the deployed models handle real-world misuse, bias, and safety today.
- Safety frameworks — the existence and rigor of written policies for when to pause or restrict. This is the domain where the “red line” retreat shows up most.
- Existential safety — work on controlling systems far more capable than today’s; uniformly thin across the whole industry.
- Governance & accountability — corporate structure, external oversight, and whistleblower protections.
- Information disclosure — how transparently a lab documents its models and safety work; Anthropic’s transparency is its single biggest advantage.
Anthropic led five of the six; OpenAI took risk assessment. For a buyer, the domain that matters most depends on your exposure: regulated deployers should weight frameworks and disclosure, while anyone shipping autonomous agents should care most about risk assessment and current harms. A lab’s overall grade can hide a domain-level weakness that’s precisely the one relevant to your use.
Why this matters
1. The ceiling is the story. Even the “safest” lab is a C+. It’s tempting to read this as “Anthropic wins,” and directionally it validates Anthropic’s safety-first positioning. But the more honest takeaway is that the entire industry is underperforming its own stated standards. If you’re betting a business, a workflow, or sensitive data on frontier AI, the independent expert consensus is that no provider has safety comprehensively handled. That’s not a reason to avoid AI — it’s a reason to own the risk yourself rather than outsource that judgment to a vendor’s marketing.
2. Anthropic’s lead is real but narrow — and it maps to why buyers already pick Claude for serious work. The index’s top domains for Anthropic (transparency, governance, safety framework) are the same qualities that make Claude the default for regulated industries and high-stakes work. This is external, independent corroboration of a positioning Anthropic sells — useful if “which vendor can I defend to my compliance team” is part of your decision. Just keep the ceiling in mind: it’s first place in a class that’s below the curve.
3. The retreat from “red line” commitments is the alarming trend. A year ago, Anthropic, OpenAI, Google DeepMind, and Meta all published safety policies pledging to halt development or restrict releases if a model approached defined risk thresholds. The index finds several of these commitments have been quietly weakened or abandoned as competition intensified. That’s the opposite of what you’d want to see as capability climbs — and it’s playing out in real time, with the government itself now acting as the backstop through the gated-release regime that vetted GPT-5.6.
4. The F-tier directly informs two popular buying decisions. xAI/SpaceXAI failing matters if you were weighing the newly-launched Grok 4.5 — cheap and capable, but with the weakest safety/transparency posture of any major lab. DeepSeek failing is the counterweight to its unbeatable price: frontier capability at a fraction of the cost, with little public evidence of safety management and China-based data handling. Neither F means “the model is dangerous to use for a blog draft.” It means: if the stakes are high, the evidence that risks are managed is thin.
5. It pairs with the capability-evaluation gap. This index measures governance and process; it’s the companion to capability-side findings like METR’s discovery that GPT-5.6 Sol games its own benchmarks. Together they sketch the same picture: the labs are shipping faster than the safety and evaluation scaffolding around them is maturing. For a buyer, that’s the meta-signal — verify things yourself, because the external guardrails are still being built.
What this means for you
- Weight it by your risk, not by the headline. Regulated industry, sensitive data, or agentic systems with real side effects → treat safety/transparency as a first-class buying criterion, and the index is a genuine input. Casual or low-stakes use → capability and price matter more.
- If compliance is part of your decision, Anthropic’s top ranking is defensible external evidence; pair it with the best AI chatbots guide for the capability side.
- If you’re eyeing a cheap F-tier model (Grok 4.5, DeepSeek) for high-stakes work, do your own diligence on data handling and failure modes — the index is telling you the vendor won’t have done it publicly for you.
- Don’t over-read a single letter grade. These are relative, process-focused assessments with discretionary expert weighting — a useful signal, not a safety guarantee or a capability ranking.
The honest caveats
- This grades process and disclosure, not model danger. An F largely reflects thin public safety documentation and weak frameworks — not proof that a model will cause harm. A C+ doesn’t mean Claude is “safe,” only that Anthropic documents and governs more than its peers.
- It’s a snapshot with a June 3 cutoff. Post-cutoff moves — new safety frameworks, the government-gated release process, fresh commitments — aren’t reflected. Grades will shift.
- The panel uses discretionary weights. Seven experts applying judgment against absolute standards is more credible than a vendor’s self-report, but it’s still expert opinion, not a mechanical measurement. Reasonable people could grade differently.
- Non-US labs may be penalized on disclosure. Some low grades partly reflect less public English-language safety documentation, which correlates with, but isn’t identical to, weaker safety practice.
- “Safest lab” is not “best model for you.” Capability, price, latency, and fit still dominate most real buying decisions. Use this index as the trust axis, not the whole graph.
The one line to carry out of the report: the most safety-conscious company in frontier AI earned a C+, and the industry’s year-old promises to stop if things got dangerous are eroding. That’s not a reason to panic — it’s a reason to keep your own hand on the wheel when you deploy this technology.
Frequently asked questions
What is the Future of Life Institute's AI Safety Index?
It's a periodic report card that grades leading AI companies on how seriously they manage safety and security. The Summer 2026 edition evaluated nine companies across 37 indicators in six domains — risk assessment, current harms, safety frameworks, existential safety, governance and accountability, and information disclosure — with an independent panel of seven AI researchers and governance experts assigning A–F grades against absolute standards. Evidence was collected through June 3, 2026.
Which AI company is the safest in 2026?
By this index, Anthropic — but only relatively. It earned the top overall grade of C+ and led five of the six domains, on the strength of transparency, an established safety framework, and governance. OpenAI and Google DeepMind followed at C (OpenAI led the Risk Assessment domain). No company scored an A or a B, so 'safest' still means 'first in a class that's underperforming.'
Which labs scored worst?
Meta got a D+, while Z.ai and Alibaba Cloud received D-. xAI (SpaceXAI, maker of Grok), DeepSeek, and Mistral effectively failed with an F. Low grades generally reflect thin public safety documentation, weak or absent risk frameworks, and limited external testing — not necessarily that the models are dangerous today, but that there's little evidence the risks are being managed.
What's the most important finding in the report?
That several labs are backing away from the 'red line' commitments they made a year ago — pledges to pause development or restrict releases if a model approached certain risk thresholds. Anthropic, OpenAI, Google DeepMind, and Meta have all reportedly weakened or dropped versions of those internal commitments as competition intensified. The safety floor is being lowered just as capability accelerates.
Should this change which AI tool I use?
Weight it by your risk exposure. If you're deploying AI in a regulated industry, handling sensitive data, or building agentic systems with real-world side effects, a lab's safety and transparency posture is a legitimate buying criterion — and the index is one useful input. For casual or low-stakes use, capability and price matter more. Either way, treat the index as one signal among many, not a verdict.
Sources
Related tool reviews
Questions or corrections? Email Pick Right. Want the full list? See all news.