Demis Hassabis has proposed that the AI industry pay for its own referee. A body of independent technical experts, funded by frontier labs, working alongside federal agencies and the US national laboratories, would build rigorous tests for the most capable models and check them for dangerous capabilities before release. Participation would be voluntary. No licences, no government veto on deployment. The Washington Post’s editorial board called it a good start this week whilst warning that the proposal contains a quiet invitation for government to do rather more later. Both the proposal and the critique are worth taking seriously. Both also miss something that should be obvious from this side of the Atlantic: Britain has been running a close approximation of this model for two and a half years, and the lesson it teaches is the opposite of the one Washington is arguing about.
The proposal, and the part that does the work
Hassabis posted the outline on X during a week of lobbying in Washington, and we covered the proposal itself when it landed. The structure borrows from the Financial Industry Regulatory Authority, the private body that Wall Street funds to police its own brokers. Labs would submit models for evaluation ahead of release. The tests would probe capabilities that matter for national security, principally offensive cyber and biological design. A board of independent technical experts, with open-source representation, would set the standards.
The interesting sentence is the one about what happens next. Once the standards prove robust, Hassabis writes, “formalisation could quickly follow,” after which new models would “be required to pass” before US deployment. He also floats a coordinated slowdown in research “if deemed necessary.”
The Post’s objection lands on the grammar. Required by whom? Deemed by whom? The passive voice does a lot of work in a proposal whose entire premise is that the industry can be trusted to write its own rules first. The paper’s deeper argument is that AI is a general-purpose technology rather than a weapon, and that the durable defences lie elsewhere: screening DNA synthesis orders, hardening critical infrastructure, building biosurveillance that works regardless of which model designed the attack. Gatekeeping frontier models, on this reading, is security theatre with a short shelf life, because China’s best systems are closing the gap and open-weight models will put comparable capability everywhere within a few years.
Critical Context: The FINRA analogy is weaker than it looks. FINRA is a compliance body with the Securities and Exchange Commission behind it, and membership is mandated by law for any firm dealing in securities. Strip out the statutory backstop and you do not have FINRA. You have a trade association with a testing budget.
Britain ran this experiment first
The UK established what is now the AI Security Institute in November 2023, renamed from the AI Safety Institute by Peter Kyle in February 2025 to signal a sharper focus on national security. It is the most technically credible state evaluator of frontier models anywhere. It has published serious work on dangerous capabilities, alignment and the reliability of safeguards.
It also has no statutory power whatsoever. AISI cannot require a developer to hand over an unreleased model. It cannot block a launch. It cannot take enforcement action against a system it judges unsafe. Every evaluation it performs happens because a lab agreed to it.
That is not a theoretical limitation. In 2024 the Commons Science, Innovation and Technology Committee examined reports that AISI had been unable to secure access to some unreleased models, and warned that the gap would undermine the institute’s mission if it went unaddressed. The committee was right. The gap is still there.
Here is the part that matters for the Washington argument. The UK model was always framed as a first step. Voluntary now, statutory later, once the technical groundwork was solid. Formalisation could quickly follow, to borrow the phrase. As of July 2026 there is no UK AI Act, no AI bill before Parliament, and the government’s own legislative slot for one looks increasingly tight. DSIT has signalled a bill repeatedly. The Secretary of State has said publicly that the UK will move from voluntary cooperation to mandatory oversight of the most advanced systems. The timeline keeps slipping.
What Britain got instead was the October 2025 Blueprint for AI regulation and the AI Growth Lab, launched in June 2026 with legal services and conveyancing as its first sandbox. Useful work, and not remotely the same thing as giving the evaluator teeth.
Strategic Reality: Thirty-two months after the UK built the world’s best-resourced state AI evaluator, it still cannot compel a single lab to show it a single model. The voluntary phase did not turn out to be a phase.
Why voluntary regimes stay voluntary
The Post worries that Hassabis’s standards body will slide into an overreaching bureaucracy. The British experience suggests the failure mode runs the other way, and for reasons that have nothing to do with anyone acting in bad faith.
A voluntary regime that works well removes the political urgency for legislation. When AISI publishes solid evaluations and labs mostly cooperate, the visible problem shrinks, and a government facing a crowded legislative programme reasonably concludes the fire is not burning. Success becomes the argument against the next step. Meanwhile the labs that cooperate gain a legitimate interest in the arrangement staying as it is, because a voluntary scheme they helped design is considerably more comfortable than a statutory one drafted by people they did not choose.
Add the competitiveness argument, which in the UK has grown louder every year since the Bletchley summit, and the ratchet only turns one way. Any move towards binding rules gets weighed against the risk of pushing investment to friendlier jurisdictions. That calculation rarely favours the regulator.
| Governance model | Who evaluates | Compulsion | Where it stands |
|---|---|---|---|
| Hassabis proposal | Industry-funded expert body | None initially; “formalisation could follow” | Proposal stage, July 2026 |
| UK AISI | State institute | None; voluntary agreements only | Operating since November 2023 |
| EU AI Act | Notified bodies and AI Office | Statutory, with penalties | Phased obligations in force |
| FINRA (the analogy) | Industry-funded body | Statutory; membership mandated by law | Operating since 2007 |
The table makes the point more cleanly than argument does. The only two rows with real compulsion are the two that got there through legislation, not through a successful voluntary phase that graduated.
Reality Check: Nobody has yet demonstrated the transition Hassabis is describing. Voluntary-to-statutory is the step that keeps not happening, on both sides of the Atlantic.
What this means if you are buying or building AI in the UK
For most UK businesses this is not an abstract governance debate. It determines what assurance you can actually obtain about the systems you are putting in front of customers and staff, and how much of the work falls to you.
The short answer is that it falls to you. If neither the UK evaluator nor any proposed US body can compel a lab to demonstrate anything, then supplier assurance is a commercial negotiation rather than a regulatory guarantee, and your leverage comes from your contract and your purchasing power rather than from a certificate.
If you are early in AI adoption, stop treating evaluator publications as assurance about the specific model you are deploying. AISI’s work is excellent and it is not a safety certificate for your use case. Write your own acceptance tests for the things that would actually hurt your business, and make passing them a condition of the contract.
If you already run AI in production, get the right to evaluate written into supplier agreements now, whilst the market is competitive enough to give you that leverage. Ask vendors directly whether their models were submitted for independent pre-deployment evaluation, what was tested, and what the results were. The answers, including the refusals, tell you a great deal about the supplier.
If you operate across borders, note that the EU AI Act is the only regime in the table that will actually oblige anyone to do anything on a fixed timetable. For firms trading into the EU, that timetable is the practical floor regardless of what Washington or Whitehall decides. We covered the wider fragmentation problem in our analysis of the UN’s AI governance push.
Hidden Cost: Firms that assumed a statutory UK regime was arriving in 2025 or 2026 and deferred building internal evaluation capability have now lost two years they will not get back. The capability takes time to build and the deadline was never real.
Four things nobody is planning for
The evaluation talent is in the wrong place. Both the UK institute and any US standards body compete for the same small pool of people who can design frontier capability evaluations, against labs paying considerably more. A body that cannot staff itself sets standards it cannot verify.
Open weights break the gate entirely. Every model in the table is evaluated before release. A model whose weights are published cannot be un-released, and the capability spreads regardless of what the evaluation found. The Post is right that this makes frontier gatekeeping a temporary fix; it is a temporary fix that the governance debate is treating as permanent architecture.
Funding shapes findings without anyone intending it. An industry-funded body does not need to be corrupt to drift. It needs only to make a hundred reasonable judgement calls about scope, thresholds and disclosure, each defensible, each marginally favouring the people paying. FINRA manages this with statutory oversight. The proposed AI equivalent, initially, would not have any.
A coordinated slowdown is a competition law problem. Hassabis floats industry-wide pauses. Competitors agreeing to restrict output is the textbook shape of an antitrust violation, and the fact that the motive is safety does not resolve it. Either the coordination gets a statutory basis, which is the bureaucracy the Post fears, or it does not happen when it matters most.
Warning ⚠️: The competition law question is not a detail to sort out later. It determines whether the most consequential power in the proposal, the ability to slow down, exists at all outside legislation.
The strategic takeaway
The Post’s editorial worries about a voluntary scheme hardening into an unaccountable regulator. The UK’s record points the other way: voluntary schemes are remarkably good at staying voluntary, and the promised formalisation arrives late or not at all. Both risks are real. Only one of them has actually happened yet, and it happened here.
That does not make the Hassabis proposal worthless. An industry-funded body that builds credible evaluations is better than nothing, and the Post is right that its strongest use is as a starting point for international standards discussions, including with Beijing, where technical exchange beats no contact at all. It is also right that the more durable defences are unglamorous and elsewhere: synthesis screening, infrastructure hardening, surveillance that works whoever built the model.
For UK business the practical conclusion is narrower and firmer. Do not wait for the assurance regime. Whether the vetting body is funded by industry in Washington or by the taxpayer in London, it currently has no power to make anyone do anything, and there is no credible date by which that changes. The organisations that come out of this well will be the ones that built their own evaluation capability whilst everyone else was waiting for someone official to certify the problem away.
Three things to put in place this quarter: a written standard for what you will and will not accept from an AI supplier, the contractual right to test against it, and someone internally who owns the answer. None of that depends on what Congress or Parliament decides.
Source and attribution
This analysis responds to “Good AI standards don’t need a new government bureaucracy behind them,” published by The Washington Post’s editorial board on 16 July 2026, examining Demis Hassabis’s proposal for an industry-funded frontier AI standards body. Original article available at washingtonpost.com. Details of AISI’s remit and powers draw on published analysis of the institute’s operating model and the 2024 Commons Science, Innovation and Technology Committee’s examination of model access.
Editorial analysis and UK business framing by Resultsense. We make sense of AI in the UK — turning research, policy and announcements into what they mean for the people building and buying these systems. For more analysis, explore our insights or get in touch.