Company positions
What AI companies say about AI regulation
Each company’s most recent public position on how AI should be regulated, linked to the document it published. One record per company.
Not law. This is a company's own public position on AI regulation. It is not law, and it carries no legal force. These pages are kept separate from the regulation corpus for that reason — nothing here creates an obligation on anyone.
- AmazonframeworkFebruary 9, 2025, updated September 17, 2026Amazon's Frontier Model Safety Framework
The framework sets out the protocols Amazon says it will follow so that its most capable frontier models do not "expose critical capabilities that have the potential to create severe risks", and its stated core is a deployment gate: Amazon commits that it "will not deploy the model until safeguards appropriately mitigate the risks" when an evaluation shows a model meets or exceeds a Critical Capability Threshold. It is structured in three parts — Critical Risk Domains (where advanced capability could cause significant public harm through misuse or loss of control), Critical Risk Evaluations (automated and human-in-the-loop methods to test whether a model has crossed a threshold), and Risk Mitigations applied across the development and deployment lifecycle. Four domains are named and each is given a written threshold: CBRN weapons proliferation, offensive cyber operations, harmful manipulation, and loss of control. The thresholds are framed as a marginal-uplift test rather than an absolute-capability test — repeatedly, "material uplift (beyond other publicly available models in known harnesses)" — which is a deliberate and consequential choice, because it means a capability already available elsewhere does not by itself trip the gate. Evaluation is required during training via "maximal capability evaluations", again pre-deployment, again before any major update that could meaningfully enhance capabilities, and on a lighter-touch recurring basis after launch; methods include public and proprietary benchmarks, expert red teaming by vendors and academics, and uplift studies run as controlled trials comparing groups with and without model access, some inside "agentic scaffoldings" that give the model code interpreters, browsers and file systems. Governance is specific about who decides: any evaluation exceeding a threshold is reported to the SVP for the model development team and the company's Chief Security Officer, who review the mitigation plan and the safeguards evaluation report as a launch go/no-go, and framework updates themselves are reviewed by that SVP, the CSO and legal counsel under an Amazon-wide Responsible AI Governance Program. Amazon commits to publish evaluation information at each frontier model launch, to revisit the framework at least annually and publish material modifications, and to update it on significant technological developments. Notably for a cloud provider, the document folds enterprise security into frontier safety — Nitro-based confidential compute, isolated VPCs, AES-256-GCM encryption under a FIPS 140-3 Level 3 KMS, hardware-token access gated by Critical Permission Groups, and a nine-bullet Appendix A of baseline controls — on the argument that preventing unauthorised access to model weights is part of preventing critical risk. The 2026 revision explicitly says it was reviewed and updated "to reflect our current practices and account for relevant laws and regulations", and the abstract ties the whole framework to Amazon's endorsement of the Korea Frontier AI Safety Commitments.
14 stated positions
- OpenAIagendaSeptember 9, 2026The AI policy window is open. We need to act.
Bylined "By Chris Lehane, Chief Global Affairs Officer at OpenAI" and filed under Global Affairs, this is OpenAI's current statement of what it wants AI regulation to be, written around the claim that "the prospect of AI-accelerated AI development demands more than voluntary commitments." Its central ask is that Congress enact mandatory, capability-based national AI safety regulation that can evolve with the technology, containing common testing and independent-assessment requirements, stronger cybersecurity protections, clear incident-reporting rules, greater national preparedness, and shared measures for tracking progress toward recursive self-improvement — the agenda set out in OpenAI's own Blueprint for Democratic Governance of Frontier AI, which this post links to and updates. It argues the framework should be "strong but carefully targeted," binding only "the handful of well-resourced laboratories developing the most capable systems—not to startups, small developers, or researchers operating nowhere near the frontier," and warns that frontier safety policy must not become "open-weights policy by another name." Until Congress acts it backs state legislation as a de facto national baseline — an approach it names "reverse federalism" — and formally endorses four additional California bills (SB 813, AB 1405, SB 1119, AB 1864) alongside its earlier support for California SB 53, New York's RAISE Act and Illinois SB 315, noting that "some of these bills we did not endorse in the past, and are now supporting after reconsidering in light of the recent jump in capabilities." It also calls for developers to be required to monitor for misaligned model behaviour with attached disclosure duties, for industry-led frontier standards built voluntarily "with or without government support" as a complement to (never a replacement for) mandatory federal safeguards, and for compatible international standards on capability measurement, human control and when development should slow or stop — "even if that means slowing the advancement of model capabilities." The framing is explicitly anti-concentration: democratically accountable standards, independent verification and meaningful transparency should replace the "fragmented system of private governance" in which frontier labs "largely set their own rules."
13 stated positions
- xAIframework30 June 2026xAI Frontier Artificial Intelligence Framework
This is a self-binding governance framework, not advocacy: xAI states the risk-management regime it holds itself to for frontier models such as Grok, and says nothing about what AI law should be. It names four risk domains it treats as primary — CBRN Risks, Offensive Cybersecurity Risks, Loss of Control Risks and Harmful Manipulation Risks — and borrows that terminology explicitly from "The Safety and Security Chapter of the General-Purpose AI Code of Practice developed under the EU AI Act", while also referencing "NIST's AI Risk Management Framework and ISO/IEC 42001 for AI management systems". The core commitment is a full systemic risk assessment "at least once a year" plus smaller evaluations at trigger points (new model release, a serious incident, a material increase in risk from use or integration, or a material change in the basis for judging risks acceptable), with a "systemic risk acceptance determination" that is "a precondition for release of our models for public use". Where risk is not acceptable outright, the stated levers are tiered availability — "the full functionality of our models may be available to only a limited set of trusted parties, partners, and government agencies" — differentiated controls by end-user type, or another round of assessment. Security commitments are pinned to named external baselines ("NIST 800-171 Rev.3 framework and supported by SOC 2 Type II evaluations"), including encryption of model weights and measures against "large-scale extraction and distillation of reasoning traces". Its only posture toward regulators is passive compliance: "When reportable under applicable laws and regulations, xAI will provide the relevant authorities with a copy of the incident report within the required deadlines."
10 stated positions
- GoogleagendaJune 2026A Pragmatic Approach to AI Governance in America
Google argues that "the debate over AI governance is stuck in a false choice between over-regulation and no regulation" and proposes a two-track US federal regime that treats frontier AI and everyday AI as different regulatory problems. For frontier models, it proposes a new federally overseen, industry-funded self-regulatory body — a "frontier AI regulatory organization (FARO)" — explicitly modelled on NERC (overseen by FERC), FINRA and the PCAOB (overseen by the SEC), the AMA and state bar associations: private bodies that "write and enforce binding rules on their members, but operate under the supervision (and ultimate veto) of a government agency." The FARO would maintain a repository of scientific benchmarks and safety/security standards for building, testing and deploying frontier systems, require each frontier developer to publish and adhere to its own frontier AI framework, and run an annual independent "procedural" audit regime that would harden into substantive audits once real benchmarks exist. Below the frontier, Google argues the federal government "does not need new regulatory regimes that duplicate or conflict with existing law" and should instead adapt existing statutes to specific real-world harms — child safety, copyright, workforce transition, energy, provenance and privacy — on the principle that "if something is illegal to do without AI, it's illegal to do with AI." The paper is explicitly evidence-based and output-focused: it says regulation should "address outputs, not inputs," accept some uncertainty rather than slow progress, and that "the greatest risk of all would be missing out on AI's life-changing benefits." The framing line Google repeats is that "AI is too important not to regulate, and too important not to regulate well."
13 stated positions
- AnthropicframeworkJune 2026Anthropic's Advanced AI Framework
Anthropic argues that voluntary transparency is no longer sufficient for frontier AI and that governments should impose binding obligations on the largest frontier developers, backed by an agency with real power. Part 1 sets out developer obligations: a narrow scope (models above 10^25 training FLOP, built by companies with over $500M in annual AI-derived revenue or over $1B per year in AI R&D spend), covering four enumerated catastrophic risks — biological weapons, offensive cyber operations, loss of control, and automated AI R&D. Covered developers would have to publish a safety framework, system cards and six-monthly risk reports, certify compliance annually, report Critical Safety Incidents to a designated Agency within 15 days, engage at least one qualified independent evaluator, and secure model weights and the training environment. Crucially, it goes beyond disclosure: the framework asks for legal authority to block or deter deployment of models posing significant catastrophic risk, with civil penalties that escalate on repeat violations and scale to global annual revenue — while proposing explicit anti-overreach safeguards (court enforcement rather than direct agency remedies, cabined discretion, expedited judicial review). On US federalism it takes a firm line: Congress should not preempt state AI law unless it enacts a regime at least as strong as this framework, and any preemption should be narrow and confer no safe harbour. Part 2 turns to societal resilience — gene-synthesis screening and biosurveillance, hardening internet software and critical infrastructure, and government capacity to track frontier cyber capability — on the grounds that a biological or cyber attack should be harder to carry out and easier to recover from wherever the capability originates.
16 stated positions
- MetaframeworkApril 7, 2026Advanced AI Scaling Framework — Version 2
This is the governance regime Meta holds itself to for frontier models, and version 2 is a substantial rewrite of the February 2025 Frontier AI Framework — including a rename from "Frontier AI Framework" to "Advanced AI Scaling Framework". It takes an explicitly "outcomes-led" approach: Meta first names catastrophic outcomes it must strive to prevent, then threat-models the causal pathways to them, then builds evaluations to measure whether a model would "substantially contribute" to those pathways. It covers three catastrophic risk domains — Chemical & Biological, Cybersecurity, and Loss of Control, the last newly added in v2 — plus two "emerging" areas (nuclear & radiological, physical autonomy) that it says warrant investigation but are too nascent to be rigorously measured yet. Crucially, v2 loosened the release gates while tightening the disclosure: the critical threshold moved from "Stop" to "Develop with Mitigations" and the high threshold from "Do not release" to "Deploy with mitigations", with the triggering standard relaxed from "uniquely enable" to "substantially contribute to" — so all thresholds now permit proceeding provided mitigations are validated to bring residual risk back to moderate or lower. In exchange it adds named accountability (the Chief AI Officer or the Director of Alignment and Risk decides deployment), whistleblower and non-compliance reporting protocols with retaliation protections, incident response provisions, and defined criteria for publishing preparedness reports and a model spec. It defines "Frontier AI" by two tests — high capability in the named catastrophic risk domains, or a compute threshold of at least 10^26 integer or floating point operations "or another threshold as may be defined by evolving standards or industry best practices" — explicitly hooking its own scope to the kind of compute threshold regulators use. Open-weights release is treated as a first-class deployment mode rather than an exception: the document commits that if Meta is considering releasing a model's weights or a fine-tuning API, it will run domain-specific capability training to "attempt to upper bound the capabilities of the model" before release, and it notes that chem-bio and cyber catastrophes are "more likely to occur through adversarial use of closed or open-weight deployments" while Loss of Control risks arise with similar probability in any deployment type, including internal. On regulation as such the document is deliberately modest but not silent: it commits to reviewing the Framework at least annually with a published change log and justification for each modification, to tracking developments through engagement with "academics, policymakers, civil society organizations, and governments", and it observes that "there is a lack of consensus among industry and within regulatory frameworks as to how to define some of these terms and concepts" — positioning Meta's own definitions as provisional pending convergence.
10 stated positions
- Mistral AIagendaApril 7, 2026European AI: a playbook to own it
Mistral argues that Europe's problem is not a shortage of rules but a shortage of capability, and that the two are connected: regulatory complexity is itself one of the things stopping European AI companies from reaching the scale that would let Europe set its own terms. The paper is explicit that this is a competitiveness argument rather than a safety one — the stated goal is "strategic autonomy", and the harm it names is dependence on foreign providers, not unsafe models. Its regulatory ask therefore runs in two directions at once, and the combination is what makes it distinctive. On compliance it asks for less: eliminate the overlaps between the AI Act, GDPR, the Data Act, DSA, DMA, CRA and NIS2; let a company demonstrate compliance once and be exempt from equivalent obligations elsewhere; and make implementing acts, standards and guidelines a precondition for new rules applying at all. On market structure it asks for considerably more: a European preference in public procurement for strategic sectors, gated on three cumulative tests of European control; mandatory third-party-verified life-cycle environmental assessments as a condition of bidding for anyone above €500m in revenue; and a statutory revenue-based levy on every commercial provider placing AI models on the European market. That last measure is the sharpest thing in the document. In exchange for the levy, which would fund European content creation, Mistral proposes that AI providers "are shielded from liability for training on materials accessible on the web" — replacing the current opt-out regime with compensation. It is a company arguing for a new tax on itself, in return for legal certainty it does not currently have.
16 stated positions
- MicrosoftframeworkFebruary 2026Frontier Governance Framework
This is the governance regime Microsoft holds itself to for its own most capable models, and it is written so that the regime tracks law rather than sitting beside it. It says its genesis is "the voluntary Frontier AI Safety Commitments that Microsoft and fifteen other AI labs made in May 2024," and it confines itself to capabilities that "could be misused to threaten national security or pose at-scale public safety risks," leaving everything else — bias, discrimination, culturally contextual harms — to Microsoft's broader AI governance program. The mechanism is a two-stage gate: a cheap "leading indicator" screen on general-purpose benchmarks, run at four points from pre-training through pre-deployment and repeated at least every six months, which triggers a "deeper capability assessment" only for models showing frontier capabilities; that assessment classifies each tracked capability as low, medium, high or critical, and high/critical models cannot ship without further mitigation. The scope is set explicitly by statute — the screen runs on "any model that is in scope for frontier model requirements under applicable laws, such as the EU AI Act, California's Transparency in Frontier AI Act (TFAIA), and New York's Responsible AI Safety and Education (RAISE) Act." On what regulation itself should look like, the document argues for an outcome-oriented, proportional, evidence-based regime rather than prescriptive rules: it "adopts an outcome-oriented approach to facilitate flexibility and innovation in AI risk management," uses deliberately qualitative rather than numeric capability thresholds "as they offer important flexibility," and presses governments toward holistic assessment that counts system-level mitigations and societal factors, not just model capability — "This type of holistic assessment will be needed if countries are to meaningfully calibrate risk thresholds and related governance requirements." It also carries a hard stop: "If, during the implementation of this framework, we identify a risk we cannot sufficiently mitigate, we will pause development and deployment until the point at which mitigation practices evolve to meet the risk."
13 stated positions
- IBMagendaUndatedPrecision Regulation for Artificial Intelligence
IBM argues that AI should not be regulated as a technology at all: regulation should attach to the specific use of an AI system and be proportionate to the risk of that use, an approach it names "precision regulation" and contrasts with blanket rules applied to algorithms as such. The document rests on three pillars — accountability, transparency, and fairness and security — and insists that accountability lands on the human entity that builds, owns or controls the system, which it calls the provider and/or owner, rather than on the model. It then converts that philosophy into five concrete obligations it says every such company should carry: designate a lead AI ethics official backed by an AI Ethics Board; run different rules for different risks, starting from a high-level harm assessment keyed to intended use, end-users, how much users rely on the output and how automated the decision is, with documented and auditable assessment for high-risk uses; don't hide your AI, disclosing its use in proportion to the potential harm; explain your AI through audit trails and accessible documentation including confidence measures and error analysis for high-impact determinations; and test your AI for bias both before deployment and continuously afterwards. Notably, it draws the transparency line deliberately short of source code and trade secrets — disclosure is achieved by documentation and audit trail, not by opening the model. It also holds that existing anti-discrimination law and sector-specific regulation already bind these systems and should be the reference point for conformance, rather than a new general-purpose AI statute. What it asks of governments is comparatively light-touch and infrastructural: recognise or designate co-regulatory mechanisms that can produce shared definitions, benchmarks, frameworks and standards across jurisdictions; finance AI testbeds with genuinely multi-disciplinary participation, explicitly prioritising minority-serving organisations and the communities an application would affect; and create incentives for voluntary adoption of globally recognised standards, including liability safe harbour for companies that certify against them. The through-line is that the sanctioning power should follow demonstrable harm in a defined use, while standards and certification do the day-to-day governing — a regime IBM positions itself as already meeting.
14 stated positions
- NVIDIAframeworkUndatedTrustworthy AI For A Better World
NVIDIA argues that trustworthiness is an engineering property of the stack rather than a compliance layer bolted on afterwards, and it commits the company to four named principles: privacy, safety and security, transparency, and nondiscrimination. The framing sentence is that "AI should respect privacy and data protection regulations, operate in a secure and safe way, function in a transparent and accountable manner, and avoid unwanted biases and discrimination." It accepts external, government-brokered soft law as binding on itself — "We are committed to safe and trustworthy AI, in line with the White House Voluntary Commitments and other global AI Safety initiatives" — which is notable for a company that elsewhere argues hard against binding rules on chips. Its account of transparency is unusually concrete and lay-facing: make the technology understandable to people and "explain, in non-technical language, how an AI system arrived at its output." Because NVIDIA sits upstream of the companies that deploy models, the document pushes responsibility down the supply chain rather than claiming it all: it publishes free open-source documentation templates (the NVIDIA/Trustworthy-AI GitHub repo) so that customers and partners can "responsibly develop AI and advance transparency and accountability across the AI supply chain," and it asserts that model cards are "the standard for increasing confidence in the development lifecycle, demonstrating compliance, and encouraging transparency," with a Model Card Generator to automate them. The principles are then tied to specific mechanisms rather than left abstract — NVIDIA Halos as a full-stack safety regime for physical AI (autonomous vehicles and robotics, unifying architecture, models, chips, software, tools and services), NeMo Guardrails to keep LLM applications accurate, appropriate, on topic and secure, and digital watermarking embedded directly into AI-generated audio, images, text and video "to safeguard against misinformation and misattribution." The nondiscrimination pillar is illustrated by commitments that read as data-sovereignty and accessibility positions: the Te Hiku Media Māori/NZ-English speech system "built and owned by its own language community," and the Signs Platform ASL dataset built with the American Society for Deaf Children and RIT and made publicly available. NVIDIA extends the same four principles to its research function, saying it maintains "our guiding principles of privacy, transparency, nondiscrimination, and safety and security in all research practices and methodologies." The page closes by positioning NVIDIA as a convener with regulators rather than an opponent of them, pointing to GTC sessions featuring "government leaders paving the way for AI regulation and trustworthiness," including a Foundational Concepts in AI Safety session from GTC DC.
14 stated positions