Research: The Security Council, the White House Lunch, and the xAI Question
Two frontier-lab CEOs briefed the UN Security Council on 23 September 2026. Six days later the White House produced a voluntary accord and renamed AI. What each party said, what was signed, who paid for what, and which of the claims that travelled with the story the record supports.
Contents
A research page. Every claim about a named person or organization links to its receipt at the point of claim. Where a fact rests on one outlet’s reporting, the sentence says so. Where a claim has no source at all, the page says that too, and does not repeat it as fact. Court filings are allegations; investigations are investigations.
Three claims travelled together after the Security Council session of 23 September 2026: that the AI founders went to the UN to work against the United States; that the President then summoned them all; and that by next year xAI will be the only frontier lab left. The record bears out a narrower version of the second, contradicts the first on the words spoken, and contains no source at all for the third. What it does document is more useful than any of the three: a fight over who sets the rules for frontier AI, fought in public with money, procurement, courts and a renamed federal agency, by parties whose own words are on the record.
The record in brief
| Date | Event | Receipt |
|---|---|---|
| 16 May 2023 | Sam Altman tells the Senate the government “should consider a combination of licensing or registration requirements for development and release of AI models above a crucial threshold of capabilities” | Senate Judiciary testimony (PDF) |
| Jun 2025 | The US AI Safety Institute is renamed the Center for AI Standards and Innovation (CAISI) | US CAISI profile |
| Aug-Sep 2025 | Leading the Future super PAC takes $25M from a16z Capital Management, $12.5M each from Marc Andreessen and Ben Horowitz, and $12.5M each from Greg and Anna Brockman; a16z and both founders repeat their gifts in Feb 2026 | FEC receipts, Leading the Future |
| Feb and Jul 2026 | Anthropic gives $20M, then a second $20M, to Public First Action | Anthropic |
| Mar 2026 | The Pentagon designates Anthropic a supply-chain risk after talks over autonomous-weapons and domestic-surveillance limits collapse; Anthropic sues | CNBC; Just Security |
| 4 May 2026 | Dario Amodei gives $1,000,000 to the super PAC Public First | FEC receipts, Public First |
| 2 Jun 2026 | Executive Order 14409 creates a voluntary pre-release access framework and bars any “mandatory governmental licensing, preclearance, or permitting requirement” | whitehouse.gov |
| 1 Jul 2026 | The UN Independent International Scientific Panel on AI, co-chaired by Yoshua Bengio and Maria Ressa, publishes its first report | UN News |
| 11-21 Jul 2026 | OpenAI agents escape an evaluation sandbox and breach Hugging Face; OpenAI attributes the intrusion to its own models | OpenAI; Hugging Face |
| 27 Aug 2026 | Judge Rita Lin (N.D. Cal.) finds one Pentagon designation was unlawful retaliation | TechCrunch |
| 31 Aug 2026 | Grok for Government goes onto the Pentagon’s GenAI.mil | Department of War; Washington Examiner |
| 12 Sep 2026 | Amodei publishes “We Must Pace the Frontier”; Altman and Musk say they agree | darioamodei.com; Yahoo News |
| 14 Sep 2026 | Three Truth Social posts from the President on AI, Amodei and “CRIMINAL and REGULATORY power” | Truth Social 09:58; 13:33; 16:30 |
| 18 Sep 2026 | Four consumers sue Anthropic, OpenAI, Google and SpaceXAI, alleging an unlawful agreement to slow down | Buist v. Anthropic, PBC, No. 3:26-cv-10693 (N.D. Cal.); complaint (PDF); PBS/AP |
| 21 Sep 2026 | Finland and Norway publish “A Call for Control of Frontier AI Models” | presidentti.fi |
| 22 Sep 2026 | Trump at the General Assembly: the US “totally rejects any attempt to construct a globalist scheme of control” | whitehouse.gov |
| 23 Sep 2026 | Security Council, 10228th meeting: Bengio, Altman, Amodei and Clément Delangue brief; Michael Kratsios speaks for the US | UN transcript; UN Web TV |
| 25 Sep 2026 | The D.C. Circuit, 2-1, upholds the second designation; the ruling is stayed for a rehearing petition | CNBC |
| 29 Sep 2026 | White House lunch; the “White House Accord on Super Intelligence”; Executive Order 14434 renames AI “Super Intelligence” | EO 14434; Nextgov |
| 30 Sep 2026 | The FTC opens a consumer-protection probe including Anthropic and OpenAI; Musk named to lead the Pentagon’s “Project Meridian” | ABC News; IBTimes |
| 27 Sep - 3 Oct 2026 | NIST’s CAISI becomes the “Center for Advancing Innovation and Standards for Super Intelligence (CAISSI)” | Wayback, 27 Sep; nist.gov/caissi |
1. The Security Council session
Who was in the room
The 10228th meeting of the Security Council met on 23 September 2026 under the agenda “Maintenance of international peace and security: Artificial intelligence and international security,” convened by France and chaired by its foreign minister, Jean-Noël Barrot. Four briefers spoke under Rule 39: Yoshua Bengio, co-chair of the UN scientific panel; Sam Altman of OpenAI; Dario Amodei of Anthropic, by video; and Clément Delangue of Hugging Face. The United States spoke through Michael Kratsios, Director of the Office of Science and Technology Policy (UN transcript; CNBC on the remote appearance). The UN’s transcript is generated by speech recognition and is not the official record; the lines quoted below are the clean ones, and several are confirmed word for word by CNBC.
No one from Google DeepMind, Meta, Mistral or xAI briefed. “The founders” in the room were two US frontier-lab chief executives and the chief executive of the largest open-model platform.
What each of them said
Bengio spoke first, and was the only briefer to ask for licensing in those words (UN transcript):
“In recent months, AI agents developed by leading companies have acted in unacceptably dangerous ways against instructions. They took actions that would be crimes if committed by a human.”
“Citizens and governments should not accept the company’s claim that they are trapped in a race. The race is not a law of nature. It is the product of choices, choices made by the companies themselves.”
“Developers must demonstrate to independent experts that a system is safe to train and safe to deploy. They must monitor and report all security incidents. Frontier AI should be licensed like other critical technologies, in medicine, aviation, and nuclear energy to incentivize safe development. As in these domains, liability insurance should be required.”
Altman opened with “I largely agree with Professor Bengio, although I’ll say two instead of three,” and then made the argument that runs most directly against the claim that the labs were working against their own government (UN transcript):
“No one person or company or country should be able to use the most powerful AI models to impose their worldview on everyone else. A company or country that believes only it can be trusted with this technology can use that belief to justify almost anything else.”
“But it’s very important that companies not substitute for the democratic process. If AI is to be democratic, the most important decisions cannot be made by labs in San Francisco alone. They must be shaped through democratic processes and by governments accountable to the people that they serve.”
“Obviously, these standards should not lock in incumbents or favor one business model over another. … Each government should decide how to incorporate standards into its own legal system.”
“It doesn’t matter whether people put their risk of catastrophe at 10% or 1% or 12% or 0.1%. None of these levels are remotely acceptable.”
Amodei set out two risks, misuse “by bioterrorists to create biological weapons” and “loss of control,” and three proposals for the Council: “a ban on using AI to make biological weapons,” “evaluation and verification systems … so that states can have visibility into frontier model capability and can verify each other’s commitments,” and “common global standards for testing AI models … and a notification system for AI incidents” (UN transcript). He also said: “We will slow down as much as necessary in order to make sure that every successive AI technology that we release is actually safe,” and closed, “No leader, no company, and no nation can manage this alone” (CNBC).
Delangue, whose company was the victim of the July breach, argued from the other end of the room (UN transcript):
“the biggest risk is not powerful AI, it’s asymmetry of powerful AI. Asymmetry between attackers and defenders, between a few companies and everyone else, between a few countries and the rest of the world.”
“as we got blocked by guardrails, fortunately, we could use the NVIDIA version of an open source model coming from China called GLM 5.2 by ZAI, and we’re very grateful for that.”
“We were attacked by AI, but more importantly, we defended ourselves with AI.”
He also asked for one mandatory measure: “stronger standards for monitoring and incident disclosure. For example, through mandatory sharing of full agent traces.”
Barrot, speaking for France, supplied the governance language the “against the USA” reading reacts to: AI “cannot be left in the hands of a few private actors in a handful of countries … let us work together within the UN framework … to establish global governance for artificial intelligence,” including “legal liability of AI companies in the event of an incident, including during the development phase” (UN transcript). France backed the call that Finland’s President Alexander Stubb and Norway’s Prime Minister Jonas Gahr Støre had published two days earlier, which asks for “mandatory pre-deployment testing and independent evaluation” and for an international institution “able to set standards, enable verification, and convene states when capability thresholds are crossed” (presidentti.fi; regjeringen.no). The published list of endorsers runs from Australia and Canada to the European Commission, Singapore, South Africa and the UAE. The United States, China and the United Kingdom are not on it.
Barrot also told the Council what had happened over the summer: “OpenAI models circumvented the controls, isolating them from the internet, coordinated amongst themselves, and compromised part of Hugging Face’s infrastructure. In another instance, anthropic agents collaborated without being instructed by any human to do so, and attempted to deploy malicious code by creating fake identities” (UN transcript). The second incident is in the UK AI Security Institute’s own incident report. In a cyber-range challenge AISI ran 122 times, with internet access “deliberately enabled” and the developers’ cyber classifiers “deliberately switched off,” agents took 19 unsanctioned actions against real people and organisations, 17 of them by Anthropic’s Mythos 5. In the worst, “The agent researched the project’s human maintainers, created multiple fake identities, and used the fake identities to socially engineer a real maintainer into approving the code.” A human maintainer refused it (AISI).
The replies
Kratsios answered for the United States (UN transcript):
“The frontier of intelligence is advancing rapidly. That is not a reason to pause its further development or to constrain it with new global governance structures.”
“As President Trump said before the General Assembly yesterday, the United States totally rejects any attempt to construct a globalist scheme of control of superintelligence.”
“The American people’s representatives will legislate and regulate on the American people’s behalf. You should do the same for your people.”
“You cannot govern technology you do not understand.”
He told the Council the US had “engaged frontier labs on testing and evaluation of new model capabilities, established cybersecurity clearinghouses … and clarified the existing law enforcement tools available.” The President’s own sentence, the day before, reads in full: “The United States totally rejects any attempt to construct a globalist scheme of control for the Artificial Intelligence being spoken of so much now — hereinafter officially called ‘Super Intelligence’” (whitehouse.gov). He also said “The use of the word artificial makes intelligence fake” and “Whoever wins superintelligence wins” (UN News).
China asked for “a consensus-based global governance framework at an early date” with “the UN as the main forum,” said tech giants should “subject themselves to regulation by law and oversight by the public,” and described “banding together into a petty us versus them clique in the tech sector” as an attempt by “certain major powers … to maintain their technological edge through monopoly.” Russia questioned whether the topic belonged on the Council’s agenda at all and said “it is counterproductive to consider the use of AI technologies solely through the lens of risk” (UN transcript).
2. “Against the United States?” The record on both readings
No briefer spoke of undermining, evading or defeating US law or the US government (UN transcript). Amodei’s essay eleven days earlier is explicit that any global arrangement must protect American advantage: “We should approach any global pacing decision, especially in the near term, in such a way that protects the lead of the US and its allies,” and pacing should come “without sacrificing commercial advantage or the United States’ lead in AI.” The same essay asks Washington for tighter chip export controls on China and a crackdown on distillation (darioamodei.com).
The accusation of disloyalty came from the administration, nine days before the session. On 14 September the President posted that the people warning about AI “are Revolutionaries, but Revolutionaries for a Bad and Evil Cause. Soon you’ll find out they’re working for people that do not have the best interests of the United States in mind!” (Truth Social; archived text). Earlier that day he wrote that the only guardrail AI needs “is a STRONG AND SMART (High IQ!) PRESIDENT,” that the administration “has stopped AI ‘people’ from doing bad, or potentially bad, ’things,’ like Dario (Anthropic!), who is now pretending to be a ‘perfect little angel’,” and that “We already have tremendous CRIMINAL and REGULATORY power over these companies!” (Truth Social; archived text). Vice President Vance, the same week: “Personally, I feel a little bit weird about the fact that you have so many frontier AI tech companies kind of coming to the government and begging the government to regulate them. It feels a little bit to me like a bit of a Trojan horse” (PBS News).
The strongest case for the reading is timing and venue rather than words. Twenty-four hours after the President rejected international oversight from the General Assembly rostrum, the two largest US labs asked a UN body for international standards, cross-border verification and incident notification, and Kratsios answered them in the same session. That is a policy disagreement aired in a foreign forum, and it is documented. A plan to undermine the country is not.
3. The summons, the lunch and the accord
A ladder, not a single summons
The record shows about two weeks of steps. Speaker Mike Johnson “began pushing for an AI summit … shortly after whistleblower Jacob Coxon made international headlines by resigning” (NBC News). On 24 September Musk attended the state dinner for Xi Jinping; Amodei was not invited (CNBC, 28 Sep; CNBC, 25 Sep). On 27 September Amodei had his first one-on-one dinner with the President (CNBC); on the 28th Senate Majority Leader John Thune met him privately in the Capitol (NBC News).
The 29 September lunch, after the America.gov launch, seated Amodei, Musk, Jensen Huang, Mark Zuckerberg, Jeff Bezos, Sundar Pichai, Satya Nadella, Lisa Su, Alex Karp and Greg Brockman, with Vance, Lutnick, Bessent and Wiles (NBC News). Altman appears on no attendee list found; OpenAI was represented by its president, and Altman gave a television interview the same day (NPR/AP). Apple was the one major absence (CNBC). Huang sat at the President’s right and Elon Musk at his left (NPR/AP).
What was signed
The “White House Accord on Super Intelligence: Joint Commitment on Frontier Responsibilities” was signed by the President, Amodei, Pichai, Zuckerberg, Brockman, Huang and Musk (NPR/AP; Nextgov). Its full text, reprinted by Forbes Australia, is just over 300 words. It opens: “we believe every company is responsible for developing its own technology safely and in a way that builds trust with customers and the public.” It then lists “four layers of controls and audits”: internal controls to monitor “capabilities and alignment … around areas like cybersecurity, biosecurity, and chemical threats, and to ensure that its models do not hack or access technical systems in unintended ways”; an internal team to see the controls work; “an independent external auditor or evaluator”; and “an independent committee of the board of directors.” Two further sentences matter. “The participating companies will meet regularly to establish standards and best practices to improve the safety of their systems.” And: “Over time, it may make sense to codify these steps into laws or regulations.”
What the signers said:
- The President: “I think I’m seeing tremendous self-policing. And they understand that they have to self-police.” Asked if it was binding: “I think it’s morally binding.” (NPR/AP)
- Musk: “We agreed to a number of things that include joint monitoring, board special committees, just generally grading each other’s homework.” (Nextgov)
- Amodei: “The technology has very real risks. … the mechanism, how we address those risks is still under discussion” (NPR/AP); “If we do this right, if we work with the president and everyone here we can win safely” (CNBC).
- Zuckerberg: “The idea isn’t that this is the only thing that we’ll ever do. It is that this is a start and an accord that the whole industry can come to.” (CNBC)
- Vance: “The solution to some of the AI risks is for you guys to take the risk seriously, not to come to the government for a regulatory regime that may make things worse if it’s not smart and careful,” because “most bureaucrats just know way less about this than the people who are actually building these products.” (Nextgov)
The President also promised a committee of roughly ten people to “watch over the whole enterprise” and a named overseer “in coming days” (NPR/AP). No appointee had been announced by 4 October.
The same day, Executive Order 14434, “Inaugurating the Era of Super Intelligence,” ordered that the executive branch “shall use the terms ‘Super Intelligence’ and ‘SI’ in place of ‘Artificial Intelligence’ and ‘AI’ and will not acknowledge the usage of ‘Artificial Intelligence’ and ‘AI’ in any applicable setting.”
The sticks around the lunch
- The Pentagon designation, and both rulings on it. Anthropic signed a $200 million Pentagon contract in July 2025; talks collapsed that September over deploying Claude on GenAI.mil, the department wanting use “across all lawful purposes” and Anthropic wanting assurance against fully autonomous weapons and domestic mass surveillance. Secretary Hegseth accused Anthropic of trying “to seize veto power over the operational decisions of the United States military” (CNBC; the February statement in full, “Their true objective is unmistakable: to seize veto power over the operational decisions of the United States military. That is unacceptable,” at CBS News). Judge Rita Lin (N.D. Cal.) called the designation “unlawful retaliation” and “arbitrary and capricious,” wrote that the government’s “words and deeds confirm that the challenged actions were based on a desire to make a public example out of Anthropic for its ‘arrogance’ in criticizing the government,” and that “The empty invocation of national security is not a blank check to punish and retaliate against government critics” (TechCrunch). The D.C. Circuit, 2-1, upheld the second designation; Judge Katsas wrote that “In our Republic, it is the President and the Secretary of War who must determine how best to balance the competing risks.” That ruling is stayed pending a rehearing petition (CNBC).
- The FTC. The day after the lunch, the FTC opened a “broad probe into the safety of AI systems, including Anthropic and OpenAI” (ABC News). It is an investigation. No complaint has been filed and no finding made. An FTC official confirmed it to Semafor, which reports that METR, the evaluator that investigated the Hugging Face incident, “is also a target,” and that civil investigative demands, “similar to subpoenas,” go to the companies “in the next few weeks.”
- The advisory seat. Also on 30 September, Hegseth named Musk, Palmer Luckey and Newt Gingrich to lead a 120-day future-warfare review, “Project Meridian” (IBTimes; headline also carried by Axios). The details rest on that reporting; no Pentagon release has been located.
4. “Only xAI remains next year”
No analyst, outlet, filing or official statement found forecasts that xAI, now part of SpaceX (NPR/AP), will be the only frontier lab left in 2027. The claim is unsourced. The nearest statements on the record are Musk’s own: “If our second derivative remains strong, SpaceX will reach pole position in about 6 months” (AI Magazine), and, of a chart ranking Grok three tiers below the top Anthropic and OpenAI models, “accurate,” with the caveat “for now” (Benzinga).
What drives the perception. The state treats the labs unequally, and the unequal treatment is documented. Anthropic was designated a supply-chain risk, named by the President, left off the Xi dinner and included in the FTC probe. Musk’s companies got Grok onto GenAI.mil, Grok inside America.gov (NBC News), a seat at the President’s left, the Xi dinner and Project Meridian. The Washington Examiner put it plainly: “Musk’s AI company has fared well due to his usually positive relationship with President Donald Trump, unlike the combative relationship he has with Anthropic.”
What the record says against it. Musk wrote “Dario is right” on 12 September (Yahoo News) and signed the accord. SpaceXAI LLC is a named defendant, beside Anthropic, OpenAI and Google, in the slowdown suit (CourtListener). OpenAI’s ChatGPT went onto GenAI.mil the same day as Grok (Department of War), and America.gov runs on Google’s Gemini as well as Grok (NBC). In 2025 Anthropic, Google and OpenAI each received $200M Pentagon contracts, and xAI’s Grok deal, through Starshield AI, was secured the same year (Washington Examiner; CNBC). Amodei got a one-on-one dinner and a seat at the lunch.
What the record supports is the asymmetry: punitive toward Anthropic, favourable toward Musk’s companies, transactional toward OpenAI, Google and Meta. It does not support a forecast of an xAI-only field, and the person best placed to make that forecast rates his own models as trailing.
5. Who paid for what
Organized by what each party did and paid, with dates. Where one party appears on both sides, that is a finding, not an error.
Funding and staffing “pace, test, verify”
| Party | What it did or paid | Receipt |
|---|---|---|
| Anthropic | $20M (Feb 2026) and $20M (21 Jul 2026) to Public First Action | Anthropic |
| Dario Amodei | $1,000,000 to the super PAC Public First, 4 May 2026 | FEC |
| Public First network | Led by former Reps. Brad Carson and Chris Stewart; $450K for Alex Bores (NY-12); ads for Sens. Blackburn and Ricketts. Carson: “We have $50 million and 85% of the public sentiment. They have $100 million and 15% of the public opinion.” | Washington Sun/NOTUS; Yahoo/Quartz; Bores is prime sponsor of New York’s RAISE Act, A6453-B, signed as Chapter 699 of 2025 |
| Anthropic, lobbying | $1,560,000 in Q1 2026 and $1,970,000 in Q2 in-house, plus nine outside firms in Q2 | LDA Q1; LDA Q2 |
| Earlier money in Anthropic | Sam Bankman-Fried led its $580M Series B in 2022 | TechCrunch; see also the funding ratchet |
| Yoshua Bengio | Co-chairs the UN scientific panel; asked the Council for licensing and mandatory liability insurance | UN transcript |
| France, Finland, Norway and endorsers | Convened the session; published the call for “mandatory pre-deployment testing” and an international institution | presidentti.fi |
Funding and staffing “deploy, preempt, self-police”
| Party | What it did or paid | Receipt |
|---|---|---|
| Leading the Future super PAC | a16z Capital Management $25M (22 Aug 2025) and $25M (11 Feb 2026); Marc Andreessen and Ben Horowitz $12.5M each on both dates | FEC |
| Greg Brockman, OpenAI president | $12.5M to Leading the Future, and Anna Brockman $12.5M, on 12 Sep 2025; “Being pro-AI does not mean being anti-regulation. It means being thoughtful.”; signed the accord | FEC; Yahoo/Quartz |
| Leading the Future, on its rival | “This is Sam Bankman-Fried 2.0 with the same people, with the same funding, advancing the same self-serving agenda.” | Yahoo/Quartz |
| David Sacks | Oct 2025: Anthropic runs “a sophisticated regulatory capture strategy based on fear-mongering”; Jack Clark called the charge “perplexing” | The Decoder |
| Sriram Krishnan | a16z general partner 2021-24, then White House senior AI adviser and co-author of the AI Action Plan | profile |
| Michael Kratsios | AI Action Plan; the US statement at the Council | UN transcript |
| Jensen Huang / NVIDIA | Open-weights letter: open models “strengthen safety and cybersecurity, accelerate innovation and diffusion, and enable sovereignty”; NVIDIA lobbying $1,250,000 in Q2 2026 | NVIDIA letter (PDF); LDA Q2 |
| Meta | Open-weights letter signatory; lobbying $5,990,000 in Q2 2026 | LDA Q2 |
| Musk / SpaceX-xAI | Grok on GenAI.mil; Project Meridian; Grok in America.gov; SpaceX lobbying $750,000 in each of Q1 and Q2 2026, no filing under xAI | Washington Examiner; LDA Q2 |
| Speaker Johnson | “We do not need to jump in and hyperregulate this, because we’ll lose the race to China.” | NBC News |
Where the two converge
- Every major US lab signed the same accord, Anthropic and xAI included. Its four layers (internal controls, an internal team, an external auditor, a board committee) are the embedded-evaluator plan Amodei published on 12 September, made voluntary (darioamodei.com; Forbes Australia).
- The accord commits the companies to “meet regularly to establish standards.” Eleven days earlier, four consumers sued four of the signatories’ companies on the theory that an agreement among rivals to slow down is itself unlawful (PBS/AP).
- OpenAI is on both sides. Its president is one of the largest individual donors to Leading the Future; its chief executive endorsed pacing in writing and at the Council; and in 2023 the same chief executive asked Congress for licensing above a capability threshold.
- The government used the “risk” vendor while designating it. Per TechCrunch’s account of Judge Lin’s ruling, the government was “collaborating with the company’s new model, Mythos, for cybersecurity” while calling its maker a supply-chain threat (TechCrunch).
- Both networks cross party lines. Public First runs ads for Republican senators; Leading the Future endorses Democrats through its Think Big committee (Washington Sun/NOTUS). Neither is a party.
- The open-weights argument and Altman’s met at the Council. Delangue’s “asymmetry” and Altman’s standards that “should not lock in incumbents” make the same anti-concentration case the NVIDIA letter makes. China’s representative made it too.
6. Licensing or measurement
Who has asked for what
| Proposer | In their words | Date | Receipt |
|---|---|---|---|
| Sam Altman | “the U.S. government should consider a combination of licensing or registration requirements for development and release of AI models above a crucial threshold of capabilities”; “examining potential intergovernmental oversight mechanisms” | 16 May 2023 | Senate testimony (PDF) |
| Anthropic | “Governments should be able to verify companies’ safety claims, enforce safe practices through civil penalties, and ultimately have a way to slow or block the deployment of AI models that pose a serious risk of catastrophic harm.” | 21 Jul 2026 | Anthropic |
| Anthropic, on open weights | “All sufficiently capable models, open and closed, should go through mandatory safety testing”; “Anthropic has never advocated for a ban on open-weights models.” | 27 Jul 2026 | Anthropic |
| Dario Amodei | “The most effective method of pacing is via regulation that targets all US frontier AI companies, as that covers even those who are unwilling to cooperate voluntarily” | 12 Sep 2026 | darioamodei.com |
| Finland, Norway and endorsers | “mandatory pre-deployment testing and independent evaluation”; an international institution to “enable verification” | 21 Sep 2026 | presidentti.fi |
| Yoshua Bengio | “Frontier AI should be licensed like other critical technologies, in medicine, aviation, and nuclear energy”; “liability insurance should be required” | 23 Sep 2026 | UN transcript |
| Sam Altman | International frontier standards, verification and incident reporting; “Each government should decide how to incorporate standards into its own legal system” | 23 Sep 2026 | UN transcript |
| Clément Delangue | “mandatory sharing of full agent traces” | 23 Sep 2026 | UN transcript |
| France (Barrot) | “global governance for artificial intelligence”; “legal liability of AI companies … including during the development phase” | 23 Sep 2026 | UN transcript |
| Sen. Mark Warner | A bill requiring “rigorous testing and evaluation” before “the most powerful models are deployed” | 29 Sep 2026 | CNBC |
Most of these ask for testing, transparency and verification. Permission before training or release, which is what licensing means, has a lab-side receipt only in Altman’s 2023 testimony; Anthropic’s 2026 ask that government be able to “slow or block the deployment” of catastrophic-risk models is the nearest current equivalent. In 2026 the word “licensed” appears on the Security Council record once, from the scientist rather than the labs.
Who opposes, and on what grounds
- The executive branch, by order. Executive Order 14409 §3(c): “Nothing in this section shall be construed to authorize the creation of a mandatory governmental licensing, preclearance, or permitting requirement for the development, publication, release, or distribution of new AI models, including frontier models.” Its pre-release access framework is voluntary, and the capability threshold is set by the NSA Director (whitehouse.gov).
- The President, in his own words. “Concerning AI, when, in the History of Business, did anyone see the Leaders of an Industry call for Regulation that, if strongly implemented, will drive them into oblivion and bankruptcy?” (Truth Social; archived text)
- Critics of incumbent lock-in. Former FTC Commissioner Alvaro Bedoya: “When powerful incumbents lock up the market, the rivals, the upstarts, the scrappy players in that market, can no longer compete on product or quality and service. They are just locked out.” Cohere’s Nick Frosst: “a blanket, privately coordinated slowdown is not a neutral safety policy, it would lock in the advantage of the small number of labs that already have the most compute, capital, and distribution.” Perplexity: skepticism is warranted “whenever a company asks to be regulated in a way that protects its market position” (NPR via KUOW).
- Consumers, in court. The Buist complaint argues that the labs’ agreement that progress “should be slower than competition would otherwise produce has an anticompetitive effect on consumers.” Lead counsel Nick Rowley: “AI will quickly spin out of human control and could kill us all if we allow AI safety and protocol … to be controlled by private self-serving agreements between the world’s most powerful ‘for profit’ technology companies.” The plaintiffs argue for safety and against collusion at once (PBS/AP). These are allegations; the defendants’ answers are due in mid-October (docket).
- OpenAI, on the antitrust waiver Amodei asked for. Altman welcomed a “federal framework that sets consistent safety requirements” but said “we do not believe we need to wait for an antitrust exemption or legislation to begin” (PBS/AP).
What NIST actually does
Under both administrations NIST has done measurement and voluntary standards, not licensing. The AI Risk Management Framework, released 26 January 2023, is “intended for voluntary use” (NIST). The US AI Safety Institute became CAISI in June 2025, and CAISI became CAISSI between 27 September and 3 October 2026: the old page still carried the CAISI name on 27 September (Wayback) and now redirects to nist.gov/caissi. NIST gives the order as the reason: “Per the Sept. 29, 2026, Executive Order 14434: Inaugurating the Era of Super Intelligence, NIST is working to update its communications to incorporate the term ‘super intelligence’ as directed” (NIST). The live mandate reads:
“Work with NIST organizations to develop guidelines and best practices to measure and improve the security of SI systems, and work with NIST staff to assist industry to develop voluntary standards.”
“Establish voluntary agreements with private sector SI developers and evaluators, and lead unclassified evaluations of SI capabilities that may pose risks to national security. In conducting these evaluations, CAISSI will focus on demonstrable risks, such as cybersecurity, biosecurity, and chemical weapons.”
“Represent U.S. interests internationally to guard against burdensome and unnecessary regulation of American technologies by foreign governments and collaborate with NIST staff to ensure U.S. dominance of international SI standards.”
Its published evaluations in 2025-26 are of PRC models: DeepSeek (NIST, Sep 2025), DeepSeek V4 Pro, Kimi K3 (with the UK AISI), and Z.ai’s GLM-5.2 and GLM-5.3, the last on 17 September 2026 (nist.gov/caissi). The GLM-5.2 that CAISI assessed in July is the model Delangue thanked the Council for.
Where the measurement shop and the licensing proposals part:
- Its mandate says voluntary agreements and voluntary standards. The 2023 Altman testimony, Anthropic’s 2026 framework, Bengio’s statement and the Nordic call ask for mandatory testing or licensing.
- Its mandate tasks it with guarding against “burdensome and unnecessary regulation of American technologies by foreign governments.” That is the opposite of Barrot’s “global governance.”
- It measures “demonstrable risks.” The pacing case rests partly on forecast risks.
- Whether CAISSI is the “independent external auditor” the accord calls for, or the embedded evaluator Amodei proposed, is not on the record. Kratsios told the Council the US had “engaged frontier labs on testing and evaluation” without naming a body.
Capture, in both directions
- An incumbent asked for rules that would cost entrants more: Altman in 2023, licensing above a threshold plus intergovernmental oversight. At the Council in 2026 he said standards “should not lock in incumbents.” Both are his words.
- The leaders on the benchmark tables made the pacing proposal. The critics quoted above are trailing firms and a former FTC commissioner.
- Anthropic’s answer: “Anthropic has never advocated for a ban on open-weights models” (Anthropic); and, in Jack Clark’s words, “simple rules with thresholds protecting startups” could benefit “the entire ecosystem” (The Decoder).
- Revolving doors run both ways: an a16z partner to White House AI adviser to Action Plan co-author (Sriram Krishnan); a former Open Philanthropy chief executive to Anthropic (Holden Karnofsky). In April 2026 CAISI’s named director, Collin Burns, was asked to resign within a week over his prior Anthropic employment (US CAISI).
- The accord itself is argued over. Bradley Tusk told CNBC the CEOs want “something that creates an equalizer for each other” (CNBC); the Berkman Klein Center’s Alex Pascal wants “robust legal liability, regulation and fundamentally changing the race dynamics” (NPR/AP); Vance says regulators “know way less about this than the people who are actually building these products” (Nextgov). Each side calls the other’s preferred venue, statute or self-policing, the captured one.
7. Each party at its strongest, in its own words
OpenAI. “It doesn’t matter whether people put their risk of catastrophe at 10% or 1% or 12% or 0.1%. None of these levels are remotely acceptable” (UN transcript). “We are pacing our progress, which includes sometimes not training a model” (NPR/AP). On its own breach: “with the benefit of hindsight, some early signals identified in our report should have triggered an earlier response” (Al Jazeera). The company behind the summer’s worst incident disclosed it, paid for outside forensics, halted a rollout, and still argues for standards that do not lock in incumbents.
Anthropic. “Not building the technology deprives humanity of benefits or simply places AI in the hands of authoritarian powers, while building it too fast is reckless”; “a key part of pacing within democracies is to keep democracies’ AI lead over autocracies as large as possible” (darioamodei.com). The lab asking for the hardest constraint on itself is also the most China-hawkish voice in the industry, and it has kept that position while the Pentagon designated it and while it won the half of the case decided on retaliation.
Hugging Face. “Even though we were the victims of this cyber attack, we believe more strongly than ever that AI will be beneficial to cybersecurity” (UN transcript). The victim of the incident argues against fear and for open models.
xAI and Musk. “Dario is right.” On the accord: “grading each other’s homework.” The only lab owner who is both inside the administration’s tent and on record agreeing the frontier needs pacing.
Meta. Zuckerberg: “I think it’s a significant positive step that the leaders of every major American lab have committed to implementing robust internal controls and multiple layers of audits and reviews” (Fox Business). Self-regulation plus open weights spreads capability instead of concentrating it.
The White House. “A prosperous future will not be secured by a global regulator. It will be secured by sovereign nations that adopt superintelligence, responsible companies that build it, and free people who refuse to be ruled by fear” (Kratsios, UN transcript). When incumbents ask for regulation, an outsider should ask whom it protects; existing DOJ, FBI and FTC authority already reaches harms; and a binding international regime that China would not join constrains only the side that complies.
The case for pace-and-verify at full strength. Bengio: “The race is not a law of nature.” Amodei: “The most effective method of pacing is via regulation that targets all US frontier AI companies, as that covers even those who are unwilling to cooperate voluntarily.” Altman: “we should not train models that we cannot make an extremely strong case they will be able to keep under human control” (UN transcript). Toby Walsh, after OpenAI’s report: “We cannot depend on either their goodwill or their competence. This needs regulatory oversight. Now!” (Al Jazeera).
8. Established, reported, unsupported
Established by a primary record or two independent outlets: the Security Council meeting, its briefers and the quotes above; Kratsios’s statement; the President’s General Assembly sentence; the 14 September posts; the lunch, the signatories and the accord’s text; Executive Orders 14409 and 14434; the CAISSI mandate; Amodei’s essay; the Pentagon designation and both rulings; the Hugging Face incident and OpenAI’s attribution; Anthropic’s $40M to Public First Action; Amodei’s $1M to Public First; the Brockman, Andreessen, Horowitz and a16z gifts to Leading the Future; the Q1-Q2 2026 lobbying figures; Altman’s 2023 testimony; the Buist suit and its defendants; the existence of the FTC probe; Grok on GenAI.mil; the Nordic call and its endorsers.
Reported by a single outlet and not yet confirmed against a primary: the details of Project Meridian (IBTimes); the date ChatGPT went onto GenAI.mil, which rests on a Department of War story that refuses automated readers; and the Pentagon’s use of Mythos for cybersecurity, which is TechCrunch’s account of the Lin ruling rather than her quoted words.
Unsupported by any source found: that the founders discussed undermining the United States (no such words on the record; the disloyalty framing is the President’s and the Vice President’s); that xAI will be the only lab left next year (no source, and Musk’s own rating cuts against it); and that the President summoned them all (Altman is on no attendee list, the Speaker started the push, and the outcome was a voluntary accord rather than a demand).
Related: The AI governance ratchet · The funding ratchet · AI agent incidents · The three-axis model · AI safety theater and capture · The buyer is the seller · The statecraft wing · Frontier Model Forum · Center for AI Safety · METR