Designing a FINRA for Frontier AI
A recent idea for governing frontier artificial intelligence (AI) has moved quickly. In April, I proposed that the federal government regulate AI through a federally supervised self-regulatory organization akin to the Financial Industry Regulatory Authority (FINRA). In June, Anthropic, OpenAI, and Google each published a framework for federal AI governance; Google adopted the FINRA structure and branded it a “FARO.” In July, Google DeepMind Chief Executive Officer Demis Hassabis published a personal essay calling for an industry-funded, FINRA-style standards body with federal supervision, and told Axios he wanted it operational before year-end. Days later, Bloomberg reported that Treasury Secretary Scott Bessent had helped develop a proposal—now under review by White House Chief of Staff Susie Wiles—for an independent frontier AI regulator modeled on FINRA and reporting to the Securities and Exchange Commission (SEC).
Such a formal regime would replace the recent, ad hoc approach to AI regulation. When Anthropic released Fable 5, the Commerce Department imposed export controls and forced the company to disable it; then the White House applied similar pressure on OpenAI. Both restrictions have since been lifted, through informal negotiations. Neither the developers nor, it now appears, the government thinks this improvised approach is working.
A supervised self-regulatory organization (SRO), like FINRA, is a private industry body that writes and enforces rules for that industry, under the supervision of a government agency. FINRA is composed of broker-dealers, and it writes and enforces rules for the securities industry under the supervision of the SEC. Congress has used this model for other domains where technical complexity and speed of innovation outpace federal bureaucratic capacity, such as futures trading, grid reliability, and even horse racing. The key features are mandatory membership, industry funding, and a supervising agency with authority to direct or veto the SRO’s actions. SRO rules bind members with the force of law, and the SRO enforces them directly, subject to appeal to the supervisor and then to federal court.
With an SRO for AI now under active consideration inside the executive branch, the essential question is how to build one. The proposals to date have said little about the institutional details that will determine whether such an entity effectively regulates AI. The primary critiques of the SRO model—that it will be captured by industry or produce stifling regulation—are best addressed through careful design of the SRO’s governance and its relationship with the supervising agency. Every regulatory scheme faces these hazards, but the SRO’s structure is distinctive in offering mechanisms that check each.
Membership
All frontier AI developers would be bound by the SRO’s rules, creating an incentive to participate in writing them. Not every regulated entity will share in governance, however. Foreign AI firms would have to comply with SRO requirements without holding voting rights or board seats, and companies deploying open-weight models would answer to the supervisor’s rules without participating in the SRO at all.
Defining “frontier developer” is a perennial threshold problem. Approaches range from a model-focused compute floor (as in the European Union’s AI Act) to compound financial triggers at the firm level (Anthropic’s white paper). Each has trade-offs, but the criteria should capture startups developing new models so that their interests are represented; any participation costs pale beside frontier-scale compute.
The threshold should be usable now but designed to change. For now, membership should extend to any entity maintaining an AI model trained on 1026 or more floating point operations (FLOPs), a threshold only a handful of models on the market today clear. FLOPs measure training scale rather than capability, an imprecision to be corrected as models and testing evolve. Responsibility for updating the threshold and eventually replacing it with a capability-based test belongs with the supervisor, not the SRO, though the SRO could provide expert advice. Case-by-case designation should also be available to account for entrants plainly structured to evade the rules. Because membership determines both who bears compliance costs and who votes on the rules, incumbents would have an interest in setting the boundary to their own advantage.
The Supervisor
Now that the president can remove the leadership of independent agencies at will, any supervising agency will be subject to political control. Formal independence is no longer a reason to prefer one agency over another as supervisor; the choice instead turns on expertise and institutional fit. Under the SRO model, independence comes not from the supervisor but from the SRO’s nonprofit board, which is beyond presidential removal power.
Which agency fits depends on what the supervisor must do. Its primary functions would be to approve or remand SRO rules; confirm the board; hold backstop enforcement authority and hear appeals; approve the budget; examine and sanction the SRO itself; own the membership threshold; and set the rules for open-weight models.
Every supervisor candidate has drawbacks. The Bessent plan reportedly names the SEC, which has unmatched experience overseeing SROs but lacks the technical expertise and clearance infrastructure to evaluate models for cyber or biological threats. The Federal Trade Commission and the Federal Communications Commission carry political baggage and entrenched cultures ill-suited to AI regulation. A new independent agency offers the cleanest slate, but it is the hardest legislative lift and could take years to stand up. Multiagency committees, such as the Financial Stability Oversight Council, have proved cumbersome. Among the departments, Energy lacks a regulatory culture and would refract every question through an energy lens, Treasury lacks technical adjacency, and Commerce leans pro-industry.
As OpenAI’s policy paper asserts, the Center for AI Standards and Innovation (CAISI) has the core expertise to build around. It already sits in the Commerce Department, which has no dominant institutional culture. The department traditionally promotes industry interests, but without true independent agencies, the supervisor’s posture will always track the party in power regardless of where it is housed.
CAISI may need to be split. Interagency coordination and frontier pre-deployment model evaluation would form the core of the new supervisor, which can stay in the Commerce Department but be separated from the National Institute of Standards and Technology (NIST), a nonregulatory standards body. CAISI’s other functions—standards development, international coordination, and foreign-adversary capability assessment—would remain within NIST.
The Board
Composition of the SRO’s governing board may be the most consequential design choice. The board would write and enforce rules against catastrophic AI risk; whether those rules are captured or neutral, stifle innovation, or enable harm would depend on who sits on it. After Trump v. Slaughter, it is also the most robust mechanism for insulating frontier AI governance from partisan whiplash; only the SRO board should be able to remove its members, who should hold staggered terms exceeding four years.
Seats allocated to industry should be elected by member developers rather than assigned one per firm. Elected governors reduce the ability of any single firm to push rules that asymmetrically benefit it; per-firm seats also make the board ineffectually large once independent governors are added. A transitional period that entails giving each founding developer their own seat may be politically necessary, but the statute should trigger elected representation once membership crosses a defined threshold.
The majority of board members should be independent governors. The FINRA board currently seats 12 public governors against 10 industry governors. Independent governors are a primary defense against industry capture, cross-ownership voting blocs, and meddling by a politically motivated supervisor. They should outnumber industry governors by two or three seats. FINRA defines independence as having no material business relationship with an industry member; an industry governor, by contrast, must have a recent or current association with one.
Board-member qualifications should reflect the role. The board would approve rules and adjudicate enforcement disputes but originate neither. Technical staff would draft the rules, and enforcement staff would perform the testing and audits. AI fluency is essential, but governors need not be the Turing Award winners Hassabis envisions. Governors need judgment, political savvy, and adversarial-oversight skills—closer to the profile of an activist investor than an eminent academic. Independent governors must command respect across industry regardless of background.
The most reliable way to ensure independent governors whom industry respects is to require approval from both sides. A majority-independent nominating committee would send candidates to the full board, and a candidate would take a seat only with majority support from both the industry governors and the sitting independent governors. The supervisor could veto candidates-elect but need not affirmatively confirm them. Because the first slate of independent directors cannot be chosen this way, the statute would either have to name them directly or establish a selection committee of industry, supervisor, civil-society, and political representatives.
Rulemaking
A key SRO advantage is that industry can write rules faster and more expertly than a government agency, leveraging insider knowledge. But the SRO must be incentivized to use that advantage. Without pressure, its optimal strategy is to write one set of rules satisfying statutory requirements and then stop. The best incentive is the credible threat that if the SRO does not act, the supervisor will—and industry would rather draft the rules itself.
Two existing models inform the mechanism. The Federal Energy Regulatory Commission can order its supervised reliability organization to propose a standard “address[ing] a specific matter,” but it cannot impose consequences for an inadequate response. The SEC, by contrast, can “abrogate, add to, and delete from” the rules of any SRO it supervises. For the AI SRO, the supervisor should combine both: It should be able to request a rule proposal from the SRO on a specified topic with a statutory deadline, and implement its own rule if the SRO fails to respond adequately.
The supervisor must approve all new SRO rules, whether the SRO proposes them on its own initiative or upon request. The private nondelegation doctrine prohibits SRO rules from taking effect without government approval. Some courts have indicated the doctrine also requires the supervisor to have the power to edit SRO rules, though the SEC rarely exercises it. That raises the risk of a politicized supervisor that seeks to usurp the SRO’s drafting initiative. The statute should include subject-matter limits on supervisor edits tied to the SRO’s enumerated scope, require public comment on supervisor requests, demand a reasoned basis for all supervisor rulemaking actions, and provide for judicial review of disputes.
Enforcement
Enforcement is the least developed component of supervised AI SRO proposals to date. There is rough consensus that the body should set standards that frontier models must meet before deployment, but the proposals do not describe who checks compliance or what happens when a developer contests or violates a determination. The SRO’s rules would need a credible enforcement mechanism to be effective.
As in finance, AI enforcement would primarily be an examination function. Enforcement staff—separate from the technical staff who design tests—would audit developer practices across the full model life cycle, including data selection, training, and post-deployment monitoring. Models, including models only for internal developer use, would have to pass a battery of safety evaluations to be deployed. Where staff surfaces a potential violation, and the member contests the finding, the dispute would enter a settlement-oriented process designed for remediation rather than punishment, with formal adjudication reserved for rare, intractable conflicts. An adjudicated decision could be appealed to the SRO board, then to the supervisor, then to a federal court.
The SRO has several incentives to enforce. Members want their rivals scrutinized—each developer faces different compliance costs for different rules, so some frontier firm will always benefit from enforcement of a particular standard. The SRO should also bear a statutory obligation to enforce, with the supervisor empowered to sanction dereliction. And concurrent supervisor authority to enforce directly against members gives the SRO reason to act before ceding the initiative. Exclusive SRO enforcement would, as with rulemaking, raise nondelegation problems. But budget and capacity constraints would produce a natural division of labor. The SRO would handle examination and lighter sanctions such as extra testing for a borderline model or stricter monitoring for a repeat offender, while the supervisor would reserve its resources for major violations warranting post-deployment suspension or substantial fines.
Staffing and Budget
The SRO’s staff must be expert and independent. Hiring high-quality AI engineers is expensive—roughly $1 million in annual compensation as a benchmark. Full-time staff reporting to the board would develop institutional loyalty to the SRO rather than to any single developer, with secondments from member companies to the technical committees that draft rules to keep expertise up to date.
To empower safety teams within the companies, developers would designate “safety officers” who would collectively form a cross-firm standing committee. It would be modeled on the Reliability and Security Technical Committee of the North American Electric Reliability Corporation (an SRO), which includes industry technical experts and maintains a direct line to flag emerging risks to the SRO board. Safety officers who sign off on covered evaluations could be required to hold an SRO-issued license, giving them personal accountability and a portable credential. The SRO could thus serve as a professional home for safety personnel employed by developers, providing the kind of external community and recognition that actuaries and attorneys enjoy through professional bodies.
The SRO’s budget should draw on industry’s deep pockets rather than unstable congressional appropriations. The SRO would set its own budget subject to supervisor approval. Funds would come from an assessment on compute providers, who would pass the cost through to all consumers. This ensures the entire ecosystem—including foreign and open-weight deployments on U.S. infrastructure—contributes to safety, and dilutes any single developer’s funding leverage. The statute should set upper and lower bounds for the assessment as a percentage of compute spending to prevent both underfunding and unchecked growth.
Foreign Models
The Google white paper and Hassabis agree that SRO rules must cover foreign models, but foreign software providers pose regulatory challenges no scheme can fully resolve. Sophisticated blocking techniques will not stop a determined user from accessing a foreign model, but that should not prevent approaches that reach most cases. In practice, regulation will cover enterprise use more effectively than individual use, and enterprise use accounts for most of the volume and much of the risk.
A tempting solution is to include foreign firms as SRO members, but it would be untenable. Foreign nationals cannot obtain security clearances for sensitive cyber or biological testing that would be essential to SRO examinations. Congress would not permit a Chinese firm to vote on rules for U.S.-deployed AI models or to test Mythos’s hacking capabilities—and it shouldn’t. Foreign firms should have no hand in writing rules for the U.S. market that U.S. courts will enforce. This is the default for regulation across domains and jurisdictions, including for other SROs; foreign companies list on U.S. stock exchanges under rules written without their participation.
Regulating closed-weight foreign models is relatively straightforward, albeit limited to enterprise channels. The authorizing legislation can prohibit cloud hosts, API resellers, and deployers from providing access to a foreign model unless the SRO has certified the deployer’s U.S. version as compliant with its rules.
Open-weight foreign models should operate under the same principle: They would be permitted only if they meet domestic requirements. Because open-weight developers have no incentive to comply, domestic deployers must bear the cost of compliance and safety testing. The supervisor could maintain a registry of cleared open-weight models, tested at public expense, to reduce duplicative compliance. Models that fail could be retested with proposed remediations at the submitter’s cost. Only registered models could be deployed, with the deployer attesting under penalty that it has not fine-tuned the model to weaken safeguards or increase dangerous capabilities.
These are near-term measures. In the long run, Google’s white paper identifies the durable solution as a reciprocity regime in which each country tests its own firms’ models and recognizes other countries’ deployment approvals.
Limitations and Next Steps
The necessity of the SRO structure is contestable. In theory, Congress could grant a direct regulator each of the same advantages: Authorize hiring outside the General Schedule, fund it through industry assessments, exempt it from ordinary notice-and-comment timelines, and seat industry experts on its technical committees. But in practice, Congress does not write statutes allowing civil servants to earn $1 million, and it does not fashion bespoke carve-outs to the Administrative Procedure Act for select agencies. When it wants a regulatory body with industry expertise that can move fast, it uses an SRO—in finance, in energy, and beyond. Congress has never given a direct regulator these features, but it has assembled them repeatedly in SROs.
To fully implement a supervised SRO, legislation is essential. A statute would build CAISI into a full supervising agency, mandate membership, create an antitrust exception for safety coordination, and make SRO rules binding. But scaffolding can go up now. The president could invoke the Defense Production Act to sponsor a voluntary agreement among AI developers to form a proto-SRO exempt from antitrust liability. The SRO could then develop testing guidelines and submit them to CAISI for approval, and the executive branch could condition federal procurement on compliance with CAISI-approved SRO standards. Developers that participate would gain first-mover advantage in setting norms likely to persist through formal recognition.
The SRO model has weaknesses, but so does every regulatory design. It is well-suited to a fast-moving, technically complex industry marked by information asymmetry and catastrophic risks that demand ex ante intervention, and it can recover a measure of institutional independence that direct regulation no longer provides. The details outlined here are a starting point. The alternative to working through them now is not coherent regulation or freedom from regulation—it is the episodic, reactive government action of the past two months. Existing SROs provide a template and hard-won lessons; the task is to adapt before a crisis forces something worse.
