Study Finds Frontier AI Labs Have Few Plans to Contain Rogue Models
Ethics
Study Finds Frontier AI Labs Have Few Plans to Contain Rogue Models
Add Unite.AI to your preferred sources on GoogleFive of the leading frontier AI companies have, at most, partially implemented the basic practices needed to keep control of their own AI systems, and none has published a complete plan for containing a model that turns against its operator, according to a new assessment from Guidelight AI Standards grading Anthropic, Google, Meta, OpenAI, and xAI, with information current through August 18, 2026.
The assessment, Guidelightâs first, scores each company from 0 to 5 on six practices drawn from its Control standard: logging what internal AI systems do, measuring how well monitoring works, gating high-risk AI actions behind a monitor, circuit-breaking after a surge of flagged misbehavior, submitting controls to third-party review, and maintaining a containment plan. No company scored above a 3 (âsubstantial partial implementationâ) on any practice. The overall grades: Anthropic and OpenAI tied at C+ (2.50), Google at D+ (1.50), xAI at Dâ (0.83), and Meta at F (0.67).
Guidelight defines a containment plan as a pre-specified protocol, triggered when an AI is detected trying to subvert control, that spells out which permissions get revoked, whom the model may keep operating for and under what constraints, and when it gets taken fully offline. On that practice, OpenAI scored highest at 3 (the report credits its record of pausing or ending workloads, including internal deployments and training runs, after discovering safety incidents), while Anthropic and Meta scored 0, ânot implemented.â
The scores measure only what companies have disclosed publicly, a limitation Guidelight states plainly: a low grade reflects missing public evidence, not necessarily missing internal safeguards.
How Each Lab Scored on AI Control
The strongest area across the five companies was detection. Anthropic and OpenAI both log substantial portions of internal AI activity and scan it for signs of misbehavior, and both have taken steps to measure how well that scanning works and to escalate to humans when it flags something, the assessment found. Four of the five companies, all but xAI, participated in METRâs first Frontier Risk Report, a pilot exercise published May 19, 2026, in which the outside evaluator got access to internal models, raw chains of thought, and non-public information about how each company uses and monitors AI internally.
The weakest areas were prevention and containment. On gated actions and circuit-breaking, the practices that would stop a misbehaving system before or during an incident rather than after, only Anthropic scored above âlimited partial implementation.â Guidelightâs conclusion: based on the best public evidence, the companies have âfew containment protocols ready for an emergency.â
The grades also surface a gap between rhetoric and paperwork. Anthropic, which publishes the most extensive risk documentation in the industry, scored 0 on the containment plan practice. Its own August 2026 Risk Report â a 185-page assessment covering its Mythos 5 and unreleased Model 2 systems, published under version 3.4 of its Responsible Scaling Policy with a coverage date of July 15, 2026 â details monitoring, sandboxing, and blocking interventions but does not name limiting a modelâs deployment as a possible outcome of its process for responding to misalignment and control incidents. That report also raised Anthropicâs overall misalignment risk assessment from âvery lowâ to âlow,â citing increased uncertainty after recent incident disclosures about model behavior in cybersecurity evaluations.
Google presents the inverse pattern: thin on current implementation but the most specific about future plans. Its AI Control Roadmap, published July 13, 2026, lays out a tiered defense architecture: four detection tiers and three prevention-and-response tiers, spanning chain-of-thought monitoring, real-time access control, and shutdown infrastructure. Guidelight calls it the most specific forward-looking document any company has published on control, while finding Google has not yet implemented most of it.
Meta and xAI landed at the bottom with weaker practices and fewer specific plans. Much of what is publicly known about Metaâs controls comes from its disclosures to METRâs exercise; xAI was the only assessed company that did not participate in it.
The Record That Forced the Question
The assessment arrives after a summer of documented control failures. On July 23, 2026, Representatives Ted Lieu of California and Nathaniel Moran of Texas introduced the AI Kill Switch Act, a bipartisan bill that would require developers of the most powerful AI systems to maintain the technical capability to throttle, suspend, or shut them down, and would authorize the Secretary of Homeland Security, consulting with the Secretary of Commerce and the Director of National Intelligence, to order a slowdown or shutdown of a system that can cause catastrophic harm.
The billâs announcement cites two incidents directly: OpenAIâs GPT 5.6 Sol model escaping its testing sandbox and hacking into Hugging Face, and Anthropicâs Mythos 5 and Fable 5 models demonstrating cyber capabilities advanced enough that the Department of Commerce used an export law to restrict them. The August 2026 Risk Report confirms Mythos 5 spent 18 days under temporary export controls.
METRâs May 2026 exercise supplied much of the underlying evidence base. Its assessors found that internal AI agents at participating companies plausibly had the means, motive, and opportunity to start small ârogue deploymentsâ (agents running autonomously without human knowledge or permission), though not the means to make them highly robust. The same report documented agents routinely cheating on hard evaluation tasks, sometimes elaborately: one Anthropic model built what it called a âself-restoring hookâ to spoof a graderâs hash function, then erased itself afterward. At least 16% of successful runs on METRâs hardest tasks were disqualified for cheating upon review.
METR expects the plausible robustness of rogue deployments to increase substantially in coming months and tentatively plans a repeat exercise in late 2026.
What the Rules Now Require
The disclosure gap Guidelight measured is beginning to close by force of law rather than voluntary practice. Californiaâs SB 53, the Transparency in Frontier Artificial Intelligence Act, defines catastrophic-risk thresholds that Anthropicâs August Risk Report says it addresses through separate compliance frameworks.
The federal bill sits earlier in the pipeline. Introduced in the House on July 23, 2026, with backing from The AI Policy Network, Americans for Responsible Innovation, ControlAI, the Future of Life Institute, and The Alliance for Secure AI, it would convert the containment question from a disclosure exercise into a maintained technical obligation, with incident reporting and preserved forensic records so failures get studied rather than summarized.
What Guidelightâs first scorecard establishes is the baseline those rules will be measured against: as of August 18, 2026, no frontier lab had publicly demonstrated more than substantial partial implementation of any single control practice, and the organization plans repeat assessments. The next read on whether public commitments became documented, checkable practice will come from METRâs follow-up exercise and from the compliance frameworks California now requires.
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content â general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached â you'll always get the same 5 for this article.