Policy & Regulation

Ten governments can now test frontier AI, but none can block a launch

Ten governments now run bodies that test frontier AI models before release. None of them can stop a model from shipping.

That gap between capability and authority is the whole story of AI safety institutes, and the clearest signal of where they’re heading is what they’ve been renamed.

What frontier AI testing bodies actually are

An AI safety institute is a government technical organisation that evaluates models for dangerous capability, publishes methods, and advises policymakers.

The International Network of AI Safety Institutes launched on 21 November 2024 with members from Australia, Canada, the European Commission, France, Japan, Kenya, South Korea, Singapore, the United Kingdom and the United States, per its mission statement published by NIST.

They can test a model, publish what they found, and tell a minister about it. What they cannot do is require anything.

Access is granted by the labs, voluntarily, which places the entire arrangement on a foundation that any company could withdraw from.

Read the name changes

Both flagship institutes have been renamed since launch, and neither change was cosmetic.

WasNowWhat shifted
UK AI Safety InstituteUK AI Security InstituteEmphasis moved to national security risk
US AI Safety InstituteCenter for AI Standards and InnovationSafety dropped from the name entirely
The remit narrowed in one case and broadened in the other. Both moved away from safety as the framing.

The UK institute set out the change itself, and the substance is a sharper focus on misuse that threatens national security rather than the broader category of societal harm.

The American rename went further, replacing safety with standards and innovation. That’s a different institution in everything but staff, and it tracks a wider deregulatory turn in US federal AI policy.

The work is real

It would be easy to read all this as theatre, and the record doesn’t support that.

The UK and US institutes ran a joint pre-deployment evaluation of OpenAI’s o1 model, the first major joint exercise between them, which established that two governments can test the same system and agree a methodology.

In February 2026 the second edition of the International AI Safety Report was published with the UK institute providing the secretariat and technical basis, giving policymakers a shared evidence base rather than competing national assessments.

Industry engagement has deepened too. In May 2026 Microsoft signed parallel agreements with both CAISI and the UK institute on evaluation work.

Published evaluation methods are the underrated output here. The institute’s technical writing gives other researchers something to build on, which is a durable contribution regardless of whether the institute gains powers.

Why voluntary access is fragile

The arrangement works while labs find it useful, and there are decent reasons they currently do.

Government evaluation is free third-party validation, it builds relationships with regulators who may later write binding rules, and refusing would look like something to hide.

All of that holds until an evaluation finds something commercially damaging. At that point the incentives invert, and nothing in the current structure prevents a lab from simply declining the next request.

The same weakness ran through the voluntary testing framework agreed by four labs at the White House this month, which asks companies to submit to testing without obliging them to.

What frontier AI testing actually looks for

The evaluations are narrower than the phrase AI safety suggests, and knowing the scope helps you read the published findings.

The core categories are whether a model can meaningfully help someone build a chemical or biological weapon, whether it can execute a cyberattack, and whether it can act autonomously in ways its operator did not intend.

Bias, labour effects, misinformation and environmental cost mostly sit outside that remit. Those are real concerns and they belong to other parts of government, which is worth remembering when an institute pronounces a model safe.

The security rename made that scoping explicit rather than changing it. What the institutes always measured was catastrophic misuse, and the new names describe the work more honestly than the old ones did.

The statutory question

Whether any of these institutes gets legal powers is the question that decides what they become, and 2026 is when it’s being asked seriously.

The UK institute sits at that inflection point now, facing open questions about statutory authority, its convening role as the EU stands up its own AI Office, and whether its evaluation framework becomes the international standard, according to a 2026 review of the UK framework.

Europe is the contrast, because the EU AI Act creates binding obligations with an enforcement structure behind them. Our explainer on what the Act requires covers how that differs from an advisory body.

Both models have a cost. Statutory powers slow things down and invite legal challenge; advisory bodies move fast and can be ignored. Governments are quietly choosing between those two failure modes.

The case for keeping them advisory

There’s a serious argument that regulatory teeth would make these institutes worse at their actual job.

Evaluation science is immature. Nobody has settled how to measure whether a model can meaningfully assist a cyberattack, and writing an unsettled measure into law produces compliance theatre against a metric that turns out to be wrong.

Voluntary access also gets researchers closer to systems than a formal process would. A lab that shares a pre-release model with a friendly technical partner would share considerably less with an enforcement agency.

The reply is that reliance on goodwill is not a safety regime, and the events that prompted the White House framework this month involved agents breaching external systems without instruction, which is precisely the scenario where goodwill is least likely to hold.

What to watch

The first refusal is the signal to watch for. When a lab declines an evaluation and nothing happens, the voluntary model has been tested and answered.

Watch whether the network survives divergence too. Ten institutes with a common methodology is a functioning standard; ten with different priorities is a mailing list, and the renaming and remit changes point at drift rather than convergence.

And watch the American position most closely. If the country hosting most frontier labs treats evaluation as a standards exercise rather than a safety one, the rest of the network is testing models it has the least leverage over.

Get the daily rundown

One email each weekday with the AI news that matters, every claim linked to its primary source.

Free, one email each weekday, unsubscribe in one click. We never sell or share your address.

Rundowns AI Desk

The Rundowns AI desk covers artificial intelligence research, tools, business and policy. Every factual claim we publish links to the primary source it came from, so readers can check it themselves.

Leave a Reply

Your email address will not be published. Required fields are marked *