What Is AI Safety Policy and Governance? A 2026 Guide

Superblocks Team
+2

Multiple authors

September 29, 2026

Copied
0:00

AI safety policy and governance combines technical safety research, national regulation, and international coordination to govern how AI systems are built, tested, and deployed.

The two terms overlap but aren't identical. Safety reduces the risk of harm; governance is the structure that enforces it.

Even the language has shifted fast. The global summit series that began at Bletchley Park in 2023 as the "AI Safety Summit" is now the "AI Impact Summit," and that renaming tells its own story. Here's the current state of play and what it means for your organization.

What is AI safety policy and governance? The 30-second answer

AI safety policy and governance is the combined set of technical practices, national laws, and international agreements that manage the risks AI systems pose.

That spans immediate harms like bias and data leakage to longer-term concerns about systems acting beyond human control.

Bottom line: no single global framework exists. What exists is a patchwork of national regulation, voluntary industry commitments, and periodic international summits, and any organization deploying AI has to navigate all three.

Key components

AI safety policy and governance breaks down into four distinct layers that don't always move in sync:

  • International summits: Periodic government-led meetings (Bletchley Park, Seoul, Paris, New Delhi) that set nonbinding priorities well short of enforceable law.
  • National regulation: Binding rules that vary sharply by country, from the EU's risk-tiered AI Act to the US's voluntary-plus-state-patchwork approach.
  • Safety research and reporting: Independent assessments like the International AI Safety Report and the Future of Life Institute's AI Safety Index that grade progress without regulatory power.
  • Corporate governance: The internal policies, risk management, and audit practices organizations build to comply with whatever rules apply to them. Our guide to writing an AI governance policy covers that layer specifically.

How does AI safety policy and governance work?

At the international level, it works through periodic summits that set direction without binding force, while national governments separately decide what to legislate.

The summit series shows this clearly:

  1. Bletchley Park, UK (November 2023): The first summit, focused on catastrophic risk from frontier models.
  2. Seoul, South Korea (May 2024): Companies adopted voluntary commitments to a frontier safety framework.
  3. Paris, France (February 2025): Renamed the "AI Action Summit," shifting emphasis toward implementation and economic opportunity.
  4. New Delhi, India (February 2026): Renamed again to the "AI Impact Summit," the first hosted in the Global South, emphasizing measurable outcomes over safety framing.

The naming pattern itself is the story. Each summit has used progressively less "safety" language and more emphasis on action and impact.

Meanwhile, national regulation has diverged sharply. The EU's AI Act imposes risk-tiered obligations with fines up to €35 million or 7% of global turnover.

The US relies on the voluntary NIST AI RMF layered under a growing patchwork of state laws.

A December 2025 executive order signaled federal intent to consolidate oversight and directly challenge those state rules. China takes a centrally administered approach with mandatory algorithm filing and content review.

Where the frontier labs stand

The summits and national laws don't cover the whole picture. The two most prominent AI labs have each published detailed policy positions, and both go further than most government proposals on the table.

Anthropic's Advanced AI Framework

Anthropic's proposal calls for mandatory testing, published safety frameworks, independent evaluation, and government authority to block or deter the deployment of models that pose catastrophic risk. 

The rules would apply only to frontier-scale models, defined as those trained on more than 10²⁵ floating-point operations by developers earning over $500 million in AI revenue or spending over $1 billion on AI R&D. It names four risk categories: biological, cyber, loss of control, and automated R&D accelerating the other three.

On the state preemption question already reshaping US policy, Anthropic takes a clear position: Congress shouldn't preempt state law unless it replaces it with a federal law at least as strong. See Anthropic's Policy on the AI Exponential for the full framework.

OpenAI's push for mandatory federal rules

OpenAI's Chief Global Affairs Officer, Chris Lehane, published a similar call to action on September 9, 2026, urging Congress toward mandatory, capability-based national AI safety regulation. 

Until that happens, OpenAI is backing state legislation instead of waiting, including four new California bills covering independent safety assessments, AI-auditor standards, youth protections, and biological threat safeguards.

The piece also commits OpenAI to building voluntary frontier safety standards with other labs, with or without government involvement, and cites accelerating AI-driven research as the reason the window for action is closing. See OpenAI's policy statement in full.

That's worth sitting with alongside the December 2025 executive order covered above. While the federal government moves to curb state AI laws, the two labs building frontier systems are pushing in opposite directions, either defending continued state action or opposing preemption without an equally strong federal replacement.

AI safety vs. AI governance: what's the difference?

The two terms get used interchangeably, but they describe different work done by different people.

Here's how they differ:

Factor AI safety AI governance
Focus Technical risk reduction: alignment, reliability, evaluation Policy structures: law, oversight, accountability
Who does it Researchers, red teams, safety engineers Regulators, boards, compliance and risk teams
Output Safer models and safety benchmarks Enforceable rules and audit requirements
Enforcement None on its own Backed by law, contracts, or regulatory penalty
Timescale Ongoing research problem Codified in policy at a point in time

The takeaway is that safety without governance is research with no teeth, and governance without safety is a rulebook nobody built the science to satisfy. The two only work together.

What I liked and didn't like about the current state of AI safety policy and governance

Pros

Independent scrutiny is real and growing. The Future of Life Institute's 2026 AI Safety Index grades nine leading AI companies across 37 indicators.

The International AI Safety Report now represents the largest global collaboration of its kind, creating public accountability that didn't exist three years ago.

Some binding regulation has real teeth. The EU AI Act's fine structure, up to 7% of global turnover, is large enough to change corporate behavior instead of getting filed away as a routine cost of doing business.

Cons

The summit series is visibly deprioritizing safety. Going from "AI Safety Summit" to "AI Action Summit" to "AI Impact Summit" in three years reflects a real change in political appetite, away from catastrophic risk and toward economic opportunity.

No binding global framework exists, and the fragmentation is worsening. The EU, US, and China are pulling in different directions, and a December 2025 US executive order actively challenging state-level AI laws makes the domestic picture less settled than before.

Should your organization care about AI safety policy and governance? My take

Yes, whatever your own view on AI safety, because real regulatory exposure already exists and keeps expanding, with new obligations landing faster than annual compliance cycles typically account for.

This matters most if you:

  • Operate in or sell into the EU, where the AI Act's extraterritorial reach applies regardless of where you're headquartered.
  • Are in a US state with a broad AI governance statute already in effect.
  • Deploy AI systems with autonomous or high-impact decision-making capability.

You can track this more passively if you:

  • Use AI only through a single vendor's hosted product with no custom deployment.
  • Operate exclusively in jurisdictions without AI-specific regulation yet, though that list is shrinking.

How to track AI safety policy and governance in 5 steps

Staying current works best as an ongoing practice, not a one-time compliance review.

  1. Map your regulatory exposure. Identify every jurisdiction where you operate, sell, or process data, since AI regulation follows where your users are, not where your offices sit.
  2. Monitor national developments alongside summits. Summit declarations are nonbinding; national and state legislatures pass the actual laws on a different timeline.
  3. Build internal governance ahead of enforcement. Waiting for a law to take effect before building compliance capacity leaves no runway to comply. Our AI risk management guide covers building that capacity.
  4. Document decisions as you make them. Regulatory bodies increasingly expect evidence, not just policy documents. Our AI audit trail guide covers what to log.
  5. Revisit your framework at least annually. The pace of regulatory change over the past three years means a policy written in 2024 is almost certainly out of date now.

Pro tip: track state-level legislation as closely as national and international developments. In the US specifically, state law is currently moving faster and with more binding force than federal policy.

Best practices for AI safety policy and governance

A few habits separate organizations that stay ahead of this from ones caught unprepared by a new law:

  • Assume regulation, don't wait for certainty: Building governance capability before it's legally mandatory costs less than retrofitting it under a compliance deadline.
  • Ground policy in principles that outlast any single law: Our AI governance principles guide covers the principles that tend to hold up regardless of which specific law changes next.
  • Treat safety and governance as connected, not separate teams' problems: A safety finding with no governance path to act on it, or a governance policy with no technical safety backing, both fail in practice.

My verdict on AI safety policy and governance

The honest picture is a widening gap between the seriousness of AI's real risks and the political appetite to regulate them globally. The summit series itself is the clearest evidence, with three renamings in three years, each one moving further from the word "safety."

Real, binding, expensive regulation exists today in the EU and in a growing number of US states, regardless of what international summits are named this year or how the political conversation around them has drifted.

Where Superblocks fits

Global policy debates set the tone, but the compliance burden lands on individual organizations building and deploying AI systems, without the internal governance to show their work if a regulator asks.

Superblocks is the governed enterprise vibe coding platform, built on a SOC 2 and HIPAA-aligned foundation. Role-based access applies on every plan, and Enterprise adds the audit logs and full MCP visibility regulators now look for.

For building the internal governance program this global picture demands, our guides to responsible AI governance and writing an AI governance policy cover that work in depth.

See how governed AI-built apps hold up under scrutiny with the Superblocks Quickstart Guide, which walks through building an internal app with the audit trail already in place.

Or book a demo to see how Superblocks fits into your existing compliance and governance requirements.

Frequently asked questions

What is AI safety policy and governance?

AI safety policy and governance covers the technical practices, national laws, and international agreements that manage AI risk together. Safety means reducing technical risk, like alignment and evaluation; governance means the legal structures that enforce it.

Is there a global AI safety law?

No, there's no single binding global AI safety law. Regulation is set nationally. The EU's AI Act imposes risk-tiered rules with major fines, the US relies on a voluntary framework plus a growing state patchwork, and China administers AI centrally through mandatory filing and review.

Why have the AI summits moved away from "safety" language?

The international summit series has renamed itself twice since 2023, from the AI Safety Summit to the AI Action Summit to the AI Impact Summit, reflecting a documented change in political priority toward economic opportunity and measurable outcomes over catastrophic risk framing.

What tool helps document AI governance for compliance?

For AI-built internal apps, Superblocks provides role-based access on every plan, with audit logs and MCP visibility on Enterprise, giving regulators the access trail they look for. Dedicated compliance and GRC platforms remain right for organization-wide tracking.

Does my company need to comply with the EU AI Act if we're not based in Europe?

Yes, potentially. The EU AI Act applies based on where your AI system's outputs are used, not your company's location, so organizations serving EU users or markets can fall under its requirements no matter where they're based.

One senior analyst replaced 15 spreadsheets with one app

At Virgin Voyages, non-technical teams now build their own AI apps, with IT governance fully intact. The result: 15+ production apps, seven departments onboard, and zero dedicated frontend engineers.

A 3-5 day process, now done in 12 hours

At Matthews, a marketing manager with zero coding background built an app that auto-generates offering memorandums, cutting turnaround from days to hours. See how the brokerage is putting AI builders on every team, with full governance intact.

Stay tuned for updates

Get the latest Superblocks news and internal tooling market insights.

You've successfully signed up

Request early access

Step 1 of 2

Request early access

Step 2 of 2

You’ve been added to the waitlist!

Book a demo to skip the waitlist

Thank you for your interest!

A member of our team will be in touch soon to schedule a demo.

8

production apps built

30

days to build them

10

semi-technical builders

0

traditional developers

8+

high-impact solutions shipped

2 days

training to get builders productive

0

SQL experience required

See full story →

See the full Virgin Voyages customer story, including the apps they built and how their teams use them.

Large cruise ship sailing in a harbor with a road lined with palm trees and cars in the foreground.
Why not Replit, Lovable, or Base44?

"Those tools are great for proof of concept. But they don't connect well to existing enterprise data sources, and they don't have the governance guardrails that IT requires for production use."

Superblocks Team
+2

Multiple authors

Sep 29, 2026