No major AI provider truly has its own systems under control. That's the central finding from Guidelight's first assessment, an independent non-profit founded by former OpenAI safety leads Page Hedley and Steven Adler. The analysis reveals systematic gaps in the control mechanisms companies should be deploying internally—and this applies to industry leaders.
Key Facts
- Five companies evaluated: Anthropic and OpenAI lead with C+, Google follows with D+, xAI receives D−, Meta scores lowest with F
- No company meets Guidelight's proposed security standards in full
- Six baseline practices assessed: Activity logging, approval mechanisms for risky actions, circuit breakers, and containment plans
- Data source: Only public disclosures such as system cards, security reports, and blog posts
What Guidelight Examined
The assessment focused on six fundamental safety practices every company should implement internally: logging AI activities, approval mechanisms for risky actions, circuit breakers, and plans to contain misaligned models. Guidelight relied exclusively on publicly available information—a deliberate constraint that highlights the gap between public messaging and actual practice.
According to Guidelight, companies perform best at detecting misbehavior. They fall significantly short on prevention and containment—precisely where it matters most to stop problems before they start or shut them down quickly.
Rankings and Standouts
| Company | Score | Highlight |
|---|---|---|
| Anthropic | C+ | Co-leader |
| OpenAI | C+ | Co-leader |
| D+ | Detailed roadmap provided | |
| xAI | D− | Significantly weaker |
| Meta | F | Lowest score |
Google stands out by publishing a detailed roadmap—signaling at least public commitment to improvement. Anthropic and OpenAI, the established safety leaders, fall far short of their own standards. Meta and xAI show minimal effort.
What This Means
The assessment raises an uncomfortable question: if the companies building AI systems don't fully control their own models, how can external regulators or users trust them? The fact that Guidelight had to rely solely on public disclosures also suggests companies offer little transparency into their internal controls.
For German organizations deploying or developing AI systems, this is an important signal: responsibility for safe AI use doesn't rest with vendors alone. Organizations should build their own control mechanisms regardless of how mature the major providers' systems are. At the same time, the assessment shows room for regulatory pressure: if even market leaders fail to meet basic standards, binding regulation may be needed to enforce minimum requirements.
Sources
Editorially owned by Ideal Syka. Sources and method: Newsroom & method. Tips and corrections: ai@i6eal.de.




