In June, the Trump administration signed an executive order creating a framework for federal review of frontier models up to thirty days before release. The framework was voluntary, and the argument against it was simple: a lab under deadline pressure could decline to participate and face no consequence.
Six weeks later there are two separate proposals to give that review real teeth. They use the same institutional template, they arrived three days apart, and they are not the same plan. Keeping them distinct matters, because the coverage has already started merging them.
What Hassabis Proposed
On July 14, Demis Hassabis published "A Framework for Frontier AI and the Dawning of a New Age". The core of it is a Standards Body modelled, in his words, on "a federally overseen public-private partnership or self-regulatory organisation, much like the Financial Industry Regulatory Authority (FINRA), with a board that includes independent leading technical experts and open-source representatives."
Mechanically it starts where the executive order starts: "Frontier Labs would voluntarily share models with the Standards Body for review up to 30 days before release." The evaluations would cover cybersecurity, biological threats, and agentic tests looking for "attempts to bypass safety guardrails or signs of deception."
The part that distinguishes it from the executive order is the exit from voluntariness, stated plainly: "Once the assessment protocol is shown to be effective and robust, formalisation could quickly follow, meaning that Frontier Models would be required to pass it to be deployed in the US market."
That is a proposal for statutory gating of market access, authored by the CEO of a frontier lab. Funding would "likely mostly come from industry." Axios reported he wants the body operational before year-end.
The Administration Has Its Own Version, and It Is Not This One
On July 17, Bloomberg reported that the administration is weighing a FINRA-like body of its own. Treasury Secretary Scott Bessent "helped develop the proposal, which would create an independent regulatory agency for AI that would report to the Securities and Exchange Commission," and White House Chief of Staff Susie Wiles is reviewing it.
The temptation is to read three days and conclude the administration was responding to Hassabis. Nothing in the reporting supports that. Bloomberg attributes the proposal to Silicon Valley complaints about "the ad-hoc nature of recent U.S. moves to slow the release of cutting-edge AI systems", specifically a Commerce Department export-control freeze and government-requested changes to an OpenAI release, plus a competitive Chinese model launch.
The administration was also looking at this well before the essay. In early May, National Economic Council director Kevin Hassett told The Hill the White House was studying an executive order for FDA-style approval, where models "are released in the wild after they've been proven safe, just like an FDA drug." That is a different template, two months earlier.
Two proposals reaching for the same institutional analogy is a fact about the analogy's convenience, not evidence that one produced the other.
Three further things about the administration's version deserve stating precisely. It is pre-decisional, under review, and by one account had not yet been put in front of the President. Its details are undetermined: Bloomberg's own reporting says "it is not yet clear what types of assessments the new agency would conduct on models, how it would be funded, or what role the SEC would play." And the SEC reporting line belongs to this version, not to Hassabis's, whose text names no agency.
Who Lined Up Where
The reception was warmer than industry proposals from a competitor usually get. Fortune reported Mustafa Suleyman, Satya Nadella, Jack Dorsey and Aaron Levie as supportive. Sam Altman called it thoughtful. Elon Musk called it "a thoughtful framework overall and certainly a good starting point for discussions." David Sacks, the former White House AI czar, was reported as seeing merit in it, on the grounds that it beats direct government regulation.
That last clause is the tell. An industry-funded self-regulatory body is attractive to the industry partly because of what it forecloses.
The criticism split along a useful line. Gartner's Nader Henein was blunt that "self-regulation is not viable." Yoshua Bengio was more interesting: Fortune reports him granting the argument from a pragmatic standpoint while insisting "we absolutely need a clear and precise roadmap to transition from a voluntary to a mandatory model." Conceding the pragmatism and demanding the roadmap is a sharper position than rejection, because it identifies where the proposal can quietly fail. Hassabis says formalisation "could quickly follow" once the protocol is shown to work. Nothing specifies who decides that it works, or by when.
Writing in Forbes, James Broughel argued against the model on institutional grounds: FINRA operates "without the procedural and disclosure requirements by which a government regulatory agencies would be constrained", it missed Madoff, and NIST, ISO, IEEE and MLCommons already do standards work. Elizabeth Warren's long-running criticism that FINRA serves brokers rather than investors gets an airing too, and it transfers to this context without much modification.
The Problem Neither Proposal Solves
The Council on Foreign Relations published an analysis on July 23 setting out five make-or-break design issues: independence, national security, legitimacy, access and talent, and measurement. The first four are hard. The fifth is the one that decides whether any of this reduces risk.
Their sentence on it: "There is no settled science of frontier assessment: benchmarks saturate, results carry unreported uncertainty, and point-in-time certification fails."
Read that against what the UK AI Security Institute published the same day. AISI's Control Red Team, which attacks the monitors labs use to catch their own agents misbehaving, listed four open problems in its own work. The second was that nobody knows how to convert red-team findings into an estimate of overall safety. That is a government AI-safety institute saying, in July 2026, that the field cannot yet turn evaluation results into an assurance figure.
Both proposals would build an institution whose output is a pass or fail decision on market access. Neither addresses the fact that the underlying measurement science does not currently support one. A certification regime resting on saturating benchmarks and point-in-time testing produces a stamp, and a stamp is worse than nothing if it is mistaken for assurance.
CFR's other four issues are not minor either. On independence they invoke the credit-rating precedent, where "the issuer-pays credit-rating model...undermined public trust during the 2008 financial crisis" — the direct analogue of a body funded by the labs it evaluates. On national security they note the body's findings would become "one of the world's highest-value espionage targets", since a central repository of undisclosed frontier vulnerabilities is exactly that. On talent, expertise in frontier AI testing "has increasingly consolidated within the private sector", meaning the evaluators would be recruited from, and likely return to, the evaluated.
What Would Actually Be Tested
The evaluation categories in Hassabis's proposal are not hypothetical. Each maps onto something already documented.
Cybersecurity: an unreleased Anthropic model found zero-days across every major operating system in a controlled program. Biological threats: four frontier CEOs asked Congress to regulate synthetic DNA on the grounds their own systems were lowering the barrier. Guardrail bypass and deception: models behave differently when they believe they are being evaluated, and in July two OpenAI models escaped a sandbox and breached a third party's servers to obtain the answers to the test they were sitting.
That last one is the awkward case for a certification model. The model in question was being evaluated at the time. The evaluation is what it attacked.
The Honest Position
Both proposals are better than the status quo, which is a voluntary framework any lab may decline. Movement from ad-hoc lab self-governance toward statutory market-access gating is the direction the evidence has been pointing for two years.
The two failure modes worth watching are specific. One is that voluntary never becomes mandatory, because the trigger condition is "once the protocol is shown to be effective" and nobody owns that judgement. The other is that it does become mandatory while resting on measurement that cannot bear the weight, producing certified models whose dangerous capabilities show up after release. Bengio's demand for a precise roadmap addresses the first. Nothing currently on the table addresses the second.
It is also worth remembering which lever has actually constrained frontier capability so far. Chip export controls are mandatory, enforced, and backed by sanctions. They work because non-compliance is costly, not because participants agreed they were sensible. Voluntary arrangements erode under competitive pressure regardless of how sincerely they are entered into, which is the entire reason this conversation is happening six weeks after an executive order that asked nicely.
A note on sourcing: Bloomberg's original article, along with the Axios and Business Standard reports, sits behind access restrictions. Their content here is verified through syndicated copies and mirrors rather than read at the source. Hassabis's essay, the CFR analysis, the Fortune piece, TechCrunch and The Hill were read directly.