A new industry report finds AI labs have weakened key safety commitments as capabilities grow. Here's what that means for enterprise AI governance and vendor risk.
The AI industry's voluntary safety system is showing cracks — and it's happening while the underlying models keep getting more capable, not less.
That's the core finding of a new report from the Future of Life Institute, an independent research organization that grades the world's largest AI companies on their safety practices. According to the report, several leading labs have weakened or eliminated earlier commitments to pause development if their systems approached specific danger thresholds.
The panel of reviewers — which included researchers from UC Berkeley, the University of Montreal, and HEC Montréal — described the pattern bluntly as "moving the goalposts."
The highest overall grade any company received was a C+. Several others scored a straight C. A handful failed outright.
For a security or IT leader at a mid-sized enterprise, this might read like an industry-insider story that doesn't touch your day-to-day. It isn't. If your organization has adopted AI tools, integrated AI vendors into your workflows, or relies on AI-powered platforms from third parties — and by 2026, nearly every enterprise has in some form — this report is a direct signal about the vendor risk sitting inside your stack.
Here's what the report actually found, and what it means for how mid-sized organizations in finance, healthcare, and manufacturing should be thinking about AI governance right now.
What the Report Actually Found
A
July 2026 report from the Future of Life Institute found that leading AI companies have weakened earlier voluntary safety commitments — including pledges to pause development if systems reached specific risk thresholds — even as their models have grown more capable. The highest-scoring company received a C+ overall grade, with several others receiving a C or failing grade, based on 37 indicators across six safety categories.
How the grading worked
- Seven outside reviewers assessed nine major AI companies across 37 indicators spanning six categories, including existential safety, transparency, and governance practices
- Grades were based on public policies, published research, company disclosures, and a voluntary survey — five of the nine companies completed the survey; several major players did not respond
- The report found "existential safety" was the weakest category industry-wide, noting that while companies have invested in interpretability research and monitoring provisions, reviewers assessed those measures as inadequate against a sufficiently capable system
The core concern — moving goalposts
- The reviewers' central finding wasn't that companies abandoned safety work entirely — it's that several had walked back specific, earlier public commitments to pause development at defined risk thresholds
- The report also flagged a broader industry shift toward military and defense applications among companies that had previously restricted that kind of use — a notable change in posture reviewers say reflects a wider loosening of prior public commitments.
- Not every company or observer agrees with the report's framing — one company noted to Axios that grading systems like this can penalize open-weight/open-source approaches, arguing that transparency and independent scrutiny of open models is itself a meaningful safety check.
This is a genuinely contested debate inside the AI industry, and reasonable experts disagree on methodology and conclusions. What's not contested is the underlying fact pattern: a voluntary, self-regulated safety framework is evolving in real time, and formal government regulation hasn't yet caught up to provide a durable backstop.
Why This Is an Enterprise Risk Conversation, Not Just an AI Policy Story
You can't outsource AI risk to your vendor's good intentions
Most enterprises adopting AI tools are, implicitly, trusting that the underlying model provider has robust internal safety and security practices — this report is a reminder that those practices vary significantly between vendors and can change over time
A framework that was true of a vendor's safety posture a year ago may not describe their posture today — the same "risk assumptions go stale faster than expected" dynamic covered in the Five Eyes warning applies directly to vendor selection and vendor governance, not just patch cycles
The regulatory gap is your gap too
The report's authors frame the core problem as a voluntary system eroding before governments have put a durable regulatory alternative in place. Until that regulatory backstop exists, the burden of due diligence on AI vendor selection, data handling, and integration risk sits largely with the enterprises adopting these tools — not with a regulator who will catch problems after the fact.
This compounds, it doesn't replace, existing AI risk categories
This governance-level finding sits alongside — not instead of — the more tactical AI risks; vulnerabilities in AI tool integrations, AI-accelerated exploitation of known flaws, and AI coding assistants with auto-execution risk. A vendor with a weakening safety posture at the model level is not a separate problem from those tactical risks — it's the upstream condition that makes them more likely and harder to predict
Your AI vendor's safety commitments can change. Your visibility into your own exposure shouldn't have to.
What This Means by Industry
Financial Services
Regulatory bodies are watching AI adoption closely, and vendor governance gaps are increasingly likely to surface in future FFIEC or SEC-adjacent guidance — proactive AI vendor due diligence is both a security and compliance advantage
Healthcare
AI tools touching or adjacent to PHI carry compounded risk when the underlying vendor's safety posture is uncertain or shifting — vendor governance review should be a standing part of any AI tool adoption process, not a one-time checkbox
Manufacturing
As manufacturers adopt AI for both IT and increasingly OT-adjacent use cases, vendor-level safety posture has physical and operational stakes, not just data stakes — this is a different risk profile than a typical SaaS vendor evaluation
How to Build AI Vendor Governance Into Your Security Program
1. Inventory every AI vendor and tool actually in use.
Most organizations can name their officially sanctioned AI tools; far fewer have a complete picture of what's been adopted independently across teams.
2. Get expert-validated visibility into vendor-level AI risk, not just tool-level risk.
3. Build a recurring vendor review cadence, not a one-time approval.
Given how quickly vendor safety postures can shift, a one-time approval at onboarding isn't sufficient — treat AI vendor governance as an ongoing review, not a gate you pass through once.
4. Extend continuous monitoring to AI-vendor-originated activity.
Anomalous behavior tied to an AI tool integration can be just as important to catch as anomalous behavior anywhere else in your environment.
Explore Purple Team SOCaaS.
This report isn't a reason to abandon AI adoption — it's a reason to stop treating AI vendor trust as a given. The organizations best positioned heading into the rest of 2026 won't be the ones avoiding AI tools altogether. They'll be the ones who've built real, ongoing visibility into what their AI vendors can access, how those vendors' safety postures are evolving, and where their own exposure actually sits.
Ready to get a clear picture of your AI vendor risk? Talk to InfoSight about an AI Governance & Exposure Assessment and build the ongoing visibility your AI adoption strategy needs — regardless of what any single vendor pledges today.