[{"data":1,"prerenderedAt":31},["ShallowReactive",2],{"nr-en-no-ai-firm-controls-systems-guidelight":3},{"slug":4,"title":5,"dek":6,"date":7,"time":8,"publishedAt":9,"updated":10,"updatedAt":10,"dateFmt":11,"updatedFmt":10,"kind":12,"tier":13,"author":14,"authorName":15,"topics":16,"tracker":23,"trackerLabel":24,"headlineStat":25,"image":26,"ogImage":27,"imageAlt":5,"csv":10,"minutes":28,"words":29,"html":30},"no-ai-firm-controls-systems-guidelight","Control Gaps at AI Giants: Guidelight Assessment Reveals Security Shortfalls","A first systematic evaluation by non-profit Guidelight shows that none of the major AI firms fully implement basic internal control mechanisms. Even the best performers score only a C+.","2026-08-19","12:16","2026-08-19T12:16:00+02:00","","August 19, 2026","analyse","standard","ideal-syka","Ideal Syka",[17,18,19,20,21,22],"AI Safety","Control Mechanisms","Guidelight","OpenAI","Anthropic","Regulation","\u002Ftools\u002Fki-aufsichtsmonitor","AI Oversight & Standards","None of 5 evaluated AI firms meet security standards fully","\u002Fnewsroom\u002Fimg\u002Fno-ai-firm-controls-systems-guidelight.webp","\u002Fog-nr\u002Fno-ai-firm-controls-systems-guidelight.en.png",2,429,"\u003Cp>No major AI provider truly has its own systems under control. That&#39;s the central finding from Guidelight&#39;s first assessment, an independent non-profit founded by former OpenAI safety leads Page Hedley and Steven Adler. The analysis reveals systematic gaps in the control mechanisms companies should be deploying internally—and this applies to industry leaders.\u003C\u002Fp>\n\u003Ch2>Key Facts\u003C\u002Fh2>\n\u003Cul>\n\u003Cli>\u003Cstrong>Five companies evaluated\u003C\u002Fstrong>: Anthropic and OpenAI lead with \u003Cstrong>C+\u003C\u002Fstrong>, Google follows with \u003Cstrong>D+\u003C\u002Fstrong>, xAI receives \u003Cstrong>D−\u003C\u002Fstrong>, Meta scores lowest with \u003Cstrong>F\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>No company meets\u003C\u002Fstrong> Guidelight&#39;s proposed security standards in full\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Six baseline practices assessed\u003C\u002Fstrong>: Activity logging, approval mechanisms for risky actions, circuit breakers, and containment plans\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Data source\u003C\u002Fstrong>: Only public disclosures such as system cards, security reports, and blog posts\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch2>What Guidelight Examined\u003C\u002Fh2>\n\u003Cp>The assessment focused on six fundamental safety practices every company should implement internally: logging AI activities, approval mechanisms for risky actions, \u003Cstrong>circuit breakers\u003C\u002Fstrong>, and plans to contain misaligned models. Guidelight relied exclusively on publicly available information—a deliberate constraint that highlights the gap between public messaging and actual practice.\u003C\u002Fp>\n\u003Cp>According to Guidelight, companies perform best at \u003Cstrong>detecting misbehavior\u003C\u002Fstrong>. They fall significantly short on \u003Cstrong>prevention and containment\u003C\u002Fstrong>—precisely where it matters most to stop problems before they start or shut them down quickly.\u003C\u002Fp>\n\u003Ch2>Rankings and Standouts\u003C\u002Fh2>\n\u003Cdiv class=\"tbl-scroll\">\u003Ctable>\n\u003Cthead>\n\u003Ctr>\n\u003Cth>Company\u003C\u002Fth>\n\u003Cth>Score\u003C\u002Fth>\n\u003Cth>Highlight\u003C\u002Fth>\n\u003C\u002Ftr>\n\u003C\u002Fthead>\n\u003Ctbody>\u003Ctr>\n\u003Ctd>\u003Cstrong>Anthropic\u003C\u002Fstrong>\u003C\u002Ftd>\n\u003Ctd>C+\u003C\u002Ftd>\n\u003Ctd>Co-leader\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>\u003Cstrong>OpenAI\u003C\u002Fstrong>\u003C\u002Ftd>\n\u003Ctd>C+\u003C\u002Ftd>\n\u003Ctd>Co-leader\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>\u003Cstrong>Google\u003C\u002Fstrong>\u003C\u002Ftd>\n\u003Ctd>D+\u003C\u002Ftd>\n\u003Ctd>Detailed roadmap provided\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>\u003Cstrong>xAI\u003C\u002Fstrong>\u003C\u002Ftd>\n\u003Ctd>D−\u003C\u002Ftd>\n\u003Ctd>Significantly weaker\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>\u003Cstrong>Meta\u003C\u002Fstrong>\u003C\u002Ftd>\n\u003Ctd>F\u003C\u002Ftd>\n\u003Ctd>Lowest score\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\n\u003Cp>Google stands out by publishing a detailed roadmap—signaling at least public commitment to improvement. Anthropic and OpenAI, the established safety leaders, fall far short of their own standards. Meta and xAI show minimal effort.\u003C\u002Fp>\n\u003Ch2>What This Means\u003C\u002Fh2>\n\u003Cp>The assessment raises an uncomfortable question: if the companies building AI systems don&#39;t fully control their own models, how can external regulators or users trust them? The fact that Guidelight had to rely solely on public disclosures also suggests companies offer little transparency into their internal controls.\u003C\u002Fp>\n\u003Cp>For German organizations deploying or developing AI systems, this is an important signal: responsibility for safe AI use doesn&#39;t rest with vendors alone. Organizations should build their own control mechanisms regardless of how mature the major providers&#39; systems are. At the same time, the assessment shows room for regulatory pressure: if even market leaders fail to meet basic standards, binding regulation may be needed to enforce minimum requirements.\u003C\u002Fp>\n\u003Ch2>Sources\u003C\u002Fh2>\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fthe-decoder.de\u002Fkeine-grosse-ki-firma-hat-ihre-eigene-ki-wirklich-unter-kontrolle\u002F\">The Decoder (DE)\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cem>Editorially owned by \u003Ca href=\"\u002Fen\u002Fautor\u002Fideal-syka\">Ideal Syka\u003C\u002Fa>. Sources and method: \u003Ca href=\"\u002Fen\u002Fredaktion\">Newsroom &amp; method\u003C\u002Fa>. Tips and corrections: \u003Ca href=\"mailto:ai@i6eal.de\">ai@i6eal.de\u003C\u002Fa>.\u003C\u002Fem>\u003C\u002Fp>\n",1787142623112]