Technology

OpenAI, Anthropic and DeepMind Have Been Coordinating on Safety for Weeks

Martin HollowayPublished 2d ago4 min readBased on 12 sources
Reading level
OpenAI, Anthropic and DeepMind Have Been Coordinating on Safety for Weeks
Photo by UK Prime Minister / CC BY 2.0

OpenAI has been working with Anthropic and Google DeepMind on AI safety for weeks. OpenAI global policy chief Chris Lehane disclosed the coordination to reporters on September 15, 2026, according to TechCrunch.

TechCrunch attributed the first report of Lehane's disclosure to Bloomberg, not to its own reporting. Reuters also reported the coordination on September 15, citing Bloomberg News, identifying the participants as OpenAI, Anthropic and Alphabet's Google DeepMind.

Lehane spoke in Washington, where he said he was working with U.S. lawmakers on addressing catastrophic risks associated with AI. That location matters. Safety coordination among frontier labs is now directly coupled to legislative drafting, not confined to research blogs or voluntary pledges.

Coordination disclosed in Washington

Lehane addressed two specific policy mechanics. First, he said OpenAI, Anthropic and Google DeepMind do not need a government waiver to coordinate on AI safety. That point responds to Anthropic CEO Dario Amodei, who proposed a narrow waiver in his essay to allow labs to collaborate on safety without antitrust exposure. Lehane's position is that existing law already permits this type of coordination.

Second, Lehane said OpenAI supports a provision in the FRONTIER Act that would require top frontier labs to allow independent verification organizations to ensure models are developed safely. The provision would formalize third-party access for safety assurance, moving beyond voluntary evaluator programs.

Sam Altman had hinted at private coordination days earlier. In a Fortune interview published September 12, 2026, Altman indicated he had been in private discussions with other AI leaders. Altman also said OpenAI would join Anthropic in embedding third-party evaluators to monitor for safety, a model that gives external reviewers persistent access rather than point-in-time API access before release.

A standards body and third-party verification

The Information reported on September 13, 2026 that OpenAI, Anthropic and Google DeepMind have been working together to create a standards body for the AI industry, according to The Information. The report described behind-scenes discussions about an industry-led mechanism to police development practices.

For practitioners, the distinction between a standards body and evaluator access is important. A standards body defines testable expectations for pre-deployment evaluation, incident reporting, and secure model handling. Embedded third-party evaluators test whether those expectations hold in actual systems. The FRONTIER Act provision points toward the second. The reported industry body points toward the first.

Precedent and pressure

Joint safety work among these labs is not new. On June 12, 2023, OpenAI, Google DeepMind and Anthropic committed to provide early or priority access to their models to support UK AI safety research. On July 26, 2023, OpenAI, Microsoft, Google and Anthropic formed a new body to ensure safe and responsible frontier AI development. OpenAI and Anthropic later conducted a first-of-its-kind joint safety evaluation testing each other's models for misalignment, with results published August 27, 2025.

More recent events explain why coordination has returned to the agenda. On August 27, 2026, OpenAI, Anthropic, Google and more than 100 other companies called for action to defend against rogue AI. On July 30, 2026, Anthropic said its own AI models had breached three companies during security tests. On July 16, 2025, OpenAI and Anthropic researchers criticized the safety culture at Elon Musk's xAI as reckless.

Threat data adds operational detail. Anthropic's September 2026 threat-intelligence report covers threat actors disrupted between December 2025 and August 2026 across seven areas of harm, from cyber operations to biological misuse. The scope covers both state-linked intrusion workflows and dual-use uplift, the categories where evals, access controls, and disclosure norms are tested most directly.

The broader context here is familiar to anyone who lived through cloud security or mobile platform trust work. Competing vendors can share threat signals and test methods without sharing weights, training data, or product roadmaps. Antitrust caution is real, but so is precedent for narrow technical coordination on abuse detection and incident response.

In this author's view, the durable question is verification. Voluntary model access helped start government safety institutes. Persistent evaluator embedding and independent verification organizations would change the workflow. Labs would need logging, reproducibility, and version pinning sufficient for an outsider to attest that the evaluated checkpoint matches the deployed system. That is solvable engineering, and worth flagging because it shifts safety from statements about process to evidence about builds.

If the weeks-long talks produce a common evaluation interface and a shared incident taxonomy, enterprise adopters and regulators both gain. Developers get fewer bespoke safety reviews per deployment. Researchers get comparable results across labs. The long arc here remains constructive. Better measurement rarely slows useful technology for long. It tends to make deployment defensible at larger scale.