The Summer 2026 AI Safety Index is the fourth edition of the Future of Life Institute's recurring assessment of frontier AI developers' safety practices, published July 7, 2026. It grades nine companies on 37 indicators across six domains, using evidence collected up to June 3, 2026. The edition expands the panel's scope from the previous cycle by adding Mistral, and its headline finding is not a company ranking but a direction of travel: that companies previously judged strongest on safety have weakened pause commitments and reversed prior bans on military applications.
Scorecard
| Company | Grade | Score | Winter 2025 | |
|---|---|---|---|---|
| [[companies/anthropic\ | Anthropic]] | C+ | 2.66 | C+ |
| [[companies/openai\ | OpenAI]] | C | 2.28 | C+ ▼ |
| [[companies/google-deepmind\ | Google DeepMind]] | C | 2.01 | C |
| [[companies/meta\ | Meta]] | D+ | 1.32 | D ▲ |
| [[companies/zhipu-ai\ | Z.ai]] | D- | 0.88 | D ▼ |
| [[companies/alibaba-qwen\ | Alibaba Cloud]] | D- | 0.87 | D- |
| [[companies/xai\ | xAI]] | F | 0.65 | D ▼ |
| [[companies/deepseek-company\ | DeepSeek]] | F | 0.47 | D ▼ |
| [[companies/mistral-ai\ | Mistral]] | F | 0.33 | N/A |
Grades use the US GPA scale (A–F mapping to 4.0–0). Domain grades run: Risk Assessment (6 indicators), Current Harms (9), Safety Frameworks (4), Existential Safety (4), Governance & Accountability (4), Information Sharing (10).
Anthropic leads five of six domains, which FLI attributes to "relatively strong transparency, a comparatively established safety framework, technical research, and governance." OpenAI leads Risk Assessment "on the strength of a broader evaluation suite and diverse engagement with external testing." Meta rose from 6th to 4th place; xAI fell from 4th to 7th. Three companies receive failing grades — one each from the United States (xAI), China (DeepSeek), and Europe (Mistral) — which FLI presents as evidence that "inadequate safety is a global problem, not a regional one." FLI also notes what it calls European dissonance: although the EU leads on AI safety regulation, the top European company scored last.
Findings
Retreat from pause commitments. FLI reports that Anthropic, OpenAI, Google DeepMind, and Meta "have weakened or voided pledges to pause unilaterally if redlines are approached, some citing competitor-contingent conditions." Reviewers term this a "moving goalpost" and argue it has "undermined safety frameworks across the board." The Anthropic-specific recommendation names the mechanism: "Reverse the RSP 3.0 walk-back on pause commitments and restore credibility of commitments." See Responsible Scaling Policy (RSP), AI Safety Cases and Frameworks.
Military use flagged as an emerging current harm. The panel records that from 2024 to 2026, companies including Anthropic, OpenAI, Google DeepMind, and Meta "that previously banned military applications gradually reversed course, joining xAI and Mistral in actively seeking defense partnerships." Anthropic drew panel criticism for "questionable military engagements," including a reported link to the Minab school strike that caused mass civilian deaths, despite its limits on domestic surveillance and autonomous weapons. Leading Chinese firms face U.S. allegations of military ties that Alibaba Cloud and Z.ai deny. See Autonomous Weapons, AI Industry Lobbying — The 2025-2026 Political Offensive.
Existential Safety is the weakest domain. No company exceeds C- and most score D or below. The panel acknowledges constructive attempts — Anthropic's constitutional classifiers, OpenAI's call for governance institutions, Google DeepMind's monitoring commitments, Meta's loss-of-control provisions — but judges them "entirely inadequate." It questions the dominant paradigms of interpretability and chain-of-thought monitorability on the ground that "detection is not prevention." See Mechanistic Interpretability, Monitorability Tax, Reasoning Models and Chain-of-Thought.
Frameworks without teeth. As US and EU compliance deadlines approach, Anthropic, OpenAI, Google DeepMind, Meta, and xAI published and updated fuller safety frameworks, but these "sometimes lack quantitative thresholds, genuinely independent audits, and clear decision authority." The per-company recommendations locate the deficits precisely: OpenAI is asked to "remove leadership's ability to override the Safety Advisory Group" and to evaluate internal-deployment risks "before broad internal use rather than after"; Google DeepMind is told "it remains unclear which internal body can halt deployment independently of executive leadership"; xAI's evaluations are described as having "gaping holes (no AI R&D data)," with "no procedure connect[ing] threshold breaches to deployment decisions, making thresholds effectively non-binding."
Rhetoric versus revealed behavior. Across Google DeepMind, OpenAI, and xAI, the index finds that "leadership's reassuring public messaging diverges from commercial conduct and legislative stance, making stated commitments an unreliable proxy for actual safety practice."
Meta's specific finding concerns governance rather than capability: its whistleblowing policy quality scores are described as reasonable but "undermined by active enforcement of a non-disparagement agreement and other suppression of dissent."
For the three Chinese-market companies and Mistral, the recurring recommendation is to publish a safety framework and governance structure at all; FLI states that for Z.ai, Alibaba Cloud, and DeepSeek the "rating largely reflects the Chinese regulatory environment rather than independent safety leadership," and that deferring entirely to government guidance "amounts to 'complete passivity' as an existential-safety strategy." Mistral's leadership is described as consistently downplaying, "and at times dismiss[ing]," frontier risk.
Reviewer commentary is attributed. Stuart Russell states that companies "have backed away from earlier commitments to release new systems only with safety measures appropriate for their capability levels; now, they're planning to release them even if it's demonstrably unsafe to do so." David Krueger calls the lack of progress toward credible safety plans "scandalous," adding that recent CEO gestures toward coordinating a pause are welcome but that companies "are still not telling people how urgent the risk is and how unprepared they are."
Methodology
Nine companies, 37 indicators, six domains. Evidence was collected to June 3, 2026 from publicly available materials — model cards, research papers, benchmark results — supplemented by a targeted company survey addressing transparency gaps such as whistleblower protections and external model evaluations. An independent panel of seven researchers and governance experts assigned domain-level grades against absolute performance standards with discretionary weights, provided written justifications and recommendations, and had individual grades kept confidential; final scores are averaged expert assessments.
The panel comprised David Krueger (University of Montreal; Mila; founding Research Director at the UK AI Security Institute), Sharon Li (University of Wisconsin-Madison), Tegan Maharaj (HEC Montréal; Mila), Sneha Revanur (Encode), Stuart Russell (UC Berkeley), Robert Trager (Oxford Martin AI Governance Initiative; Centre for the Governance of AI), and Yi Zeng (Renmin University; founding dean of the Beijing Institute of AI Safety and Governance).
A Chinese Regulatory Context annex accompanies the scorecard, added because "it is not obvious whether companies are more likely to abide by their own voluntary commitments (which are common in the U.S.) or draft laws and government standards that have not yet come into force (which are common in China)." It distinguishes five instrument types by binding force: national binding instruments (most determinative; enforced by CAC, MIIT, MPS, SAMR and sectoral regulators, with fines up to 50 million RMB or 5 percent of turnover, service suspension, delisting, or license revocation); local binding instruments (predominantly promotional, subordinate to national law, with mainly incentive-based consequences); voluntary technical standards (GB/T standards from TC260, non-binding in form but functioning as de facto compliance benchmarks because regulators reference them); draft regulations (anticipatory only); and strategic policy guidance (a "behavioral steering tool" with no direct liability). See China — Interim Measures for the Management of Generative AI Services, Cyberspace Administration of China (CAC).
Provenance
Published July 7, 2026 at futureoflife.org, with a full report PDF and a two-page summary. Pulled and verified July 26, 2026 against futureoflife.org, the issuing organization's own domain; independently corroborated by contemporaneous coverage in TIME, Axios, France 24, Barron's, the Financial Times, and Inside AI Policy. Predecessor editions: Winter 2025 (December 2025), Summer 2025 (July 2025), and the inaugural 2024 index (November 2024, six companies).
The June 3, 2026 evidence cutoff predates several later developments, including the July 2026 OpenAI–Hugging Face incident and subsequent model releases; grades should be read against that date rather than as current.
Relationships
- supersedes: the Winter 2025 edition of the same index for current grades.
- supports: AI Safety Cases and Frameworks — external assessment of published frontier-safety frameworks.
- contradicts: developer claims that published safety frameworks carry binding thresholds, which the panel finds often lack quantitative thresholds, independent audits, and clear decision authority.
- related: Responsible Scaling Policy (RSP) — the RSP 3.0 pause-commitment walk-back is a named finding.
- related: Autonomous Weapons, AI Existential Risk, Monitorability Tax.
- related: Future of Life Institute (FLI), Stuart Russell.
- related: Anthropic, OpenAI, Google DeepMind, Meta AI, xAI, DeepSeek, Mistral AI, Alibaba / Qwen Team, Zhipu AI.