For most of the past two years, the organizations that test frontier AI models for dangerous capabilities worked in relative obscurity: small nonprofits such as METR, Apollo Research and Transluce, running evaluations on a shoestring while the labs they audited raised billions. That arrangement ended quietly over the past month, as Anthropic and OpenAI both committed to embedding independent evaluators inside their companies — with public backing from President Donald Trump and most of the largest US technology companies.
The money is starting to follow the attention, but from a very low base. METR, the Model Evaluation and Threat Research nonprofit, said in August that it had received commitments of about $71 million over the previous six months — a sharp jump from the $13.6 million in gross receipts it reported for all of 2024 in its most recent IRS filing. Vals AI, a for-profit startup that builds benchmarks for industry-specific model performance, grew from eight employees to roughly 30 this year and announced a $40 million funding round in August.
The corporate commitments are larger still. Anthropic said on September 18 that it would work with Faculty, the specialist AI business inside Accenture, to red-team models and test safeguards, with Anthropic and Accenture each expecting to invest at least $1 billion over five years. Anthropic has also signed an agreement with METR to independently investigate reported incidents involving Claude models gaining unauthorized access to third-party systems.
The posture out of Washington is the reason this private layer matters so much. Trump has praised AI executives for their "tremendous self-policing" and, in a voluntary accord presented in late September, encouraged companies to "partner with an independent external auditor or evaluator." No binding federal framework has followed. California moved first: Governor Gavin Newsom signed SB 813 and AB 1405 on September 9, creating a framework for independent verification organizations and a state registry of AI auditors with independence and transparency standards. In Congress, the bipartisan FRONTIER Act was introduced in the House on July 23 as H.R. 9925, requiring model cards, independent audits and incident reporting.
The friction is already visible. OpenAI dismissed three employees last week for what a spokesperson called violations of its policies on accessing and handling sensitive company information. Two of them, Mikita Balesni and Tomek Korbak, said they believe the dismissals were connected to how they communicated with third-party evaluators; Balesni wrote on X that former colleagues are now "afraid to speak." OpenAI disputed that account and said on Friday that it is "actively finalizing contracts with third-party safety assessors and will announce details in the coming weeks," building on existing collaboration with METR and Redwood Research.
The unanswered questions are structural rather than technical. "To a degree, the problem, as always, is money," Suresh Venkatasubramanian, a computer science professor at Brown University, told CNBC. "Who is paying for these companies to do their work? How are they going to support them? You need an ecosystem, you need a viable business model for this." What systems evaluators may inspect, and how findings get reported, remain undefined — a gap Anthropic itself acknowledged when it said no standards yet exist for embedded-evaluator access or disclosure.
Andrew Freedman, chief executive of the policy nonprofit Fathom, told CNBC he has worked in politics and policy for twenty years and has "never seen an issue move so fast on so many different political spectrums." He expects an influx of capital into the evaluator ecosystem, which today consists mostly of small nonprofits plus the audit practices of large firms such as Accenture.
Critics liken lab-funded review to letting banks supervise themselves ahead of a crisis, or drugmakers approve their own medicines. Whether that criticism sticks depends on details nobody has fixed yet: who funds the evaluators, what they may inspect, and whether they can publish what they find. The California registry and the FRONTIER Act are attempts to impose those answers from outside. Until one of them lands, the credibility of frontier-model oversight rests on voluntary arrangements that the companies being evaluated still largely control.
Comments (0)
Log in to join the discussion
Log InNo comments yet