disappointing ai safety grades

The Summer 2026 AI Safety Index, published by the Future of Life Institute, grades nine leading AI labs on a four-point scale across thirty-seven indicators and six domains, from risk assessment and governance to existential safety. The headline result is simple and unsettling. No company earns an A or a B, and the highest grade in the entire index is Anthropic’s C plus with a numerical score of 2.66. Furthermore, 54% of enterprises report confirmed AI agent security incidents, highlighting the urgency of addressing safety concerns.

The labs evaluated include Anthropic, OpenAI, Google DeepMind, Meta, Z dot ai, Alibaba Cloud, xAI now rebranded as SpaceXAI, DeepSeek, and Mistral. These are the organisations building and deploying some of the most capable models on the planet. Yet when independent reviewers look at their documentation, internal safety frameworks, external testing, and governance practices, most of what they see is still closer to early-stage startup discipline than to aviation or nuclear safety culture.

Who is ahead and who is falling behind

Anthropic again takes the top spot, earning a C plus with a score of 2.66 and leading five of the six domains assessed, largely on the strength of comparatively transparent safety documentation, a more established internal framework, and sustained technical research in alignment. This is Anthropic’s third consecutive term at the top of the index, reflecting a consistent strategy of marketing itself as a safety-focused lab and backing that up with at least moderately stronger practices than its peers.

OpenAI and Google DeepMind follow, both with overall grades of C and scores of 2.28 and 2.01 respectively. OpenAI now leads the Risk Assessment domain, supported by a broader evaluation suite and more diverse engagement with external testers, including red teaming and public bug bounty style programs for frontier models. DeepMind remains close behind on overall safety indicators but does not lead any single domain in the latest edition, a sign that its efforts are solid yet no longer clearly ahead of the pack.

Meta is the clearest improver. It climbs from a D to a D plus, moving from sixth to fourth place overall, with a score around 1.32. Reviewers credit Meta’s rise to more detailed safety frameworks, explicit threat modeling for catastrophic misuse scenarios, and extensions of its bug bounty programs to cover severe and systemic risks. This is still far from a strong performance, but it shows that large consumer platforms can tighten their safety posture when they accept that AI risk is part of their core brand and regulatory exposure.

In the lower tier, the picture is much harsher. Z dot ai and Alibaba Cloud earn D minus grades with scores just under one, reflecting thin transparency and limited evidence of robust governance or external testing. Three labs now receive failing grades. xAI, now listed as SpaceXAI in some commentary, drops to an F with a score of 0.65, falling from fourth to seventh place after a merger that reviewers say made safety practices harder to track and left basic transparency and governance structures missing. DeepSeek records an F with a score of 0.47, and Mistral debuts in the index with an F and the lowest score of all, 0.33.

Those failing grades span three continents. xAI is based in the United States, DeepSeek in China, and Mistral in Europe, underscoring that weak safety practice is not limited to any single regulatory environment or political system. The index’s authors and several independent commentators highlight this as evidence that voluntary commitments and high-level policy statements have not yet translated into day-to-day safety discipline in many labs.

How we got here: a brief history of the index

The Summer 2026 report does not appear in a vacuum. Earlier editions already pointed to worrying gaps. The 2024 AI Safety Index, which covered six major companies, found that even then Anthropic only managed an overall C while peers such as Google DeepMind, Meta, OpenAI, xAI, and Zhipu AI clustered at D plus or lower and Meta outright failed. Since then, the index has expanded both its scope and the number of labs evaluated, but the top of the class has barely moved.

Between 2024 and Summer 2025, Anthropic sat at the top and climbed from a C to a C plus around 2.64, while OpenAI and DeepMind hovered in the C to C minus range and companies such as Meta and xAI remained in the D tier, with Zhipu AI and DeepSeek receiving failing grades. Analysts at the Future of Life Institute and independent commentators have repeatedly described the trend from 2024 through 2026 as stagnation or even retreat in some areas, rather than the steady improvement many regulators had hoped to see.

By Summer 2026, Anthropic inches from 2.64 to 2.66, OpenAI slips from C plus to C while strengthening its risk assessment domain, and DeepMind stays in the C band with no major breakthrough. Meta’s rise from D to D plus is framed as the main positive story, but xAI’s fall from the middle of the group to a clear failure and the appearance of Mistral at the very bottom show that new entrants and reorganised labs can quickly drift backward if safety is not built into their corporate structure and incentive design.

The existential safety gap

Perhaps the most worrying part of the Summer 2026 index is not the overall grades but one specific domain: existential safety. This domain looks at whether labs have credible plans to keep much more capable systems within controllable bounds, including the ability to monitor and contain models that might pursue goals misaligned with human values or organisational intent.

Across the latest edition, existential safety is the weakest performing dimension for every company assessed. In parallel, reviewers warn that leading labs have recently softened their opposition to military AI applications, reinforcing concerns that safety practices are not keeping pace with expanding real-world deployment into high-stakes domains. No lab scores above the D range in this area, and several analyses describe all the plans on offer as inadequate. Independent summaries note that for the second consecutive edition, no company reaches even a solid passing grade on existential risk planning. A senior researcher commenting on the release stated that every company evaluated received what amounts to a failing mark on their capacity to keep a truly capable system under control.

The underlying issue is that most published safety frameworks focus on current model behaviour, misuse, content harms, and incremental deployment decisions. They rely on expanding evaluation suites, red teaming, transparency reports, and governance committees. Those are valuable steps for managing present-day risks such as misinformation, privacy violations, or discriminatory outcomes. They are much less convincing as blueprints for containing systems that could autonomously write and deploy code, influence millions of users in real time, or explore new scientific domains with little human oversight.

There is also a growing gap between public statements and actual conduct. Several labs have signed voluntary commitments with governments, issued safety charters, and talked about hard limits or red lines for model capabilities. Yet the index reviewers repeatedly note that policies designed on paper have not matured into detailed operational procedures or binding accountability structures, particularly in the existential safety domain.

What this means for technology, business, and society

From a technology perspective, the Summer 2026 index suggests that many labs are treating safety as a parallel track rather than as core engineering. The fact that the highest grade is a C plus means that even the most safety-focused organisations still have notable gaps in areas such as incident response, independent audits, and model capability forecasting. In practice, that raises the odds of unanticipated behaviours once models are widely deployed.

For businesses that build on top of these models, the main implication is risk concentration. Enterprises are rapidly adopting frontier systems for coding assistance, customer support, knowledge management, and decision support, often assuming that leading labs have already solved the hardest safety problems. The index makes clear that this assumption is unwarranted. Companies integrating these models into critical workflows should treat lab safety scores as one input among many and invest in their own guardrails, monitoring, and fallback plans.

Regulators and policymakers face a similar challenge. On paper, 2023 through 2025 saw a wave of policy discussions, voluntary commitments, and early regulation efforts in the United States, the European Union, and multiple other jurisdictions. The 2026 index shows that these efforts have not yet produced a strong upward shift in practice. No lab has moved into the B range overall, and the existential safety scores remain stuck in failing territory.

For society at large, the report underscores a simple but important reality. The frontier AI ecosystem is global, highly competitive, and under intense commercial pressure. Without strong external incentives, it is unlikely that most labs will voluntarily invest enough in safety to reach the equivalent of aviation-level reliability before systems become significantly more capable. This is not a reason to panic, but it is a reason to insist on clear standards, real enforcement, and independent testing rather than simply trusting corporate promises.

Limitations and what the index does not say

A careful reading also requires some humility. The AI Safety Index is built from publicly available information, disclosures from labs, and targeted expert review. It cannot fully see internal decisions, trade-offs, or confidential research. Scores are therefore best understood as conservative snapshots of the safety posture that labs are willing to show, not exhaustive audits of everything they do.

Different labs also have different business models and regulatory constraints, which shape what they can disclose and how fast they can change. For example, companies embedded in large consumer platforms or cloud providers may have more complex legacy systems to manage but also more established security processes they can adapt. Smaller or newer labs may move faster on some technical controls but lag on governance, transparency, or external scrutiny.

Finally, the index primarily measures process and structure rather than long-term empirical outcomes. A lab can score well on documentation and risk assessment yet still experience serious incidents in practice, and vice versa. That said, the overall pattern of mediocre grades and failing existential safety scores is too consistent to ignore.

Key takeaways and the road ahead

Three conclusions stand out from the Summer 2026 AI Safety Index.

First, safety performance across frontier labs is middling at best. No company has broken out of the C range, and several remain in clear failure territory despite operating models that are already woven into critical systems worldwide.

Second, existential safety is the central blind spot. For two consecutive editions, no lab has reached a passing grade in planning for worst-case scenarios, and expert reviewers judge current plans for controlling extremely capable systems as inadequate.

Third, progress is uneven and fragile. Anthropic retains a narrow lead, Meta demonstrates that improvement is possible, but xAI, DeepSeek, and Mistral show how quickly safety can fall behind when corporate priorities change or new players enter the race.

For the next few years, the most constructive path forward is likely to involve a mix of stricter external standards, deeper independent evaluation, and more transparent internal roadmaps for safety research and governance. Labs that want to be trusted will need to show not only better grades on the next index but also tangible evidence that existential safety is becoming a first-class engineering problem rather than an aspirational policy label.

Conclusion

The latest AI Safety Index lands like a sober report card for an industry that is increasingly embedded in critical infrastructure, financial markets, and everyday life. In a year when frontier models are being woven into products at global scale, the best safety grade any major lab can manage is a C plus, while three fail outright. For a technology class that can already act, reason, and coordinate across digital systems, that mismatch between capability and governance is the headline.

A report card for the frontier era

The AI Safety Index is a recurring assessment run by the Future of Life Institute that evaluates leading frontier AI companies on how they manage risks from their systems. It is not a benchmark of model performance or capability. Instead it focuses on policies, governance structures, transparency practices, and how seriously each organization prepares for tail risks including catastrophic and existential scenarios.

The Summer 2026 edition covers nine prominent labs that build and deploy large scale models. Anthropic, OpenAI, Google DeepMind, Meta, Z.ai, Alibaba Cloud, xAI, DeepSeek, and Mistral are graded on a four point scale that is mapped to academic style letters from A to F. The index draws on public documentation, disclosures, and survey responses reviewed by a panel of AI researchers and governance experts. Importantly, as one summary puts it, the index scores what each lab discloses and commits to on safety rather than how powerful its models are or how they behave in every real world context.

That distinction matters. It means the index is primarily a measure of institutional readiness and transparency, not a guarantee that any given system is safe in deployment.

How the AI Safety Index works

The current index tracks thirty seven indicators across six domains, including risk assessment, corporate governance, deployment safety practices, incident response, external accountability, and existential risk planning. Each indicator is scored, then combined into an overall grade and numeric score. The scale follows the familiar United States grade point average convention, so a C plus corresponds to about 2.6 out of 4.

This design reflects the way mature industries handle dangerous technologies. Nuclear power, aviation, and pharmaceuticals are all governed not just by technical performance metrics but by detailed expectations for documentation, independent review, and crisis readiness. The AI Safety Index attempts something similar for frontier AI, providing a comparable yardstick across labs that often prefer to market themselves on speed and innovation.

Because it leans heavily on public information, the index is conservative by design. If a company claims strong safeguards but offers little detail, or omits clear processes for emergencies and red teaming, that absence is reflected in its score.

What the 2026 grades show

The overall picture is blunt. Anthropic tops the Summer 2026 table with a C plus and a numeric score of 2.66, leading most domains but still sitting in what would be academic probation territory at a university. OpenAI follows with a C and a score of 2.28, while Google DeepMind also receives a C with 2.01. Meta climbs to a D plus at 1.32, improving from earlier rounds but still below what would be considered solid performance.

The bottom tier includes Z.ai and Alibaba Cloud at D minus, with scores of 0.88 and 0.87. Three labs fail outright. xAI receives an F with 0.65, DeepSeek an F with 0.47, and Mistral an F with 0.33, giving the index one failing lab each from the United States, China, and Europe. No company reaches a B grade, let alone an A.

Taken together, the AI Safety Index portrays an industry that remains structurally unprepared for the risks its systems create. No major lab scores above a mediocre C plus, and several fail outright including xAI, DeepSeek, and Mistral. From a governance perspective, these are the grades of an ecosystem that is still improvising its safety playbook while its products spread into core services and infrastructure.

One of the most striking findings is the persistent weakness in existential safety planning. Across the nine labs, the index reports that no company scores above D plus in the existential safety domain. Even the top performers, which lead in other areas such as risk assessment or governance, receive only low passing grades when it comes to concrete plans for extreme tail risks.

In practice, existential safety covers questions such as:

  1. Whether a lab has clear protocols for pausing or halting training if a model shows dangerous emergent capabilities.
  2. Whether there are defined thresholds for external review before deploying systems that could destabilize key social or economic functions.
  3. Whether contingency plans exist for scenarios where models enable large scale misuse or self directed harmful behavior.

The current grades suggest that most labs have not yet operationalized these concerns into rigorous policies with teeth. Instead, existential risk is often handled at the level of high level statements or exploratory research rather than binding governance. That gap between capability and control is precisely what worries many safety researchers.

Why this matters for businesses and regulators

For enterprises considering which vendor to trust with core workflows or customer facing products, the index is a practical signal. Anthropic, OpenAI, and Google DeepMind collectively rank highest, but their C range grades still indicate meaningful exposure from immature safety infrastructure. Meta, Z.ai, and Alibaba Cloud sit lower, and xAI, DeepSeek, and Mistral carry failing marks that should prompt tough questions before integrating their systems into sensitive environments.

For regulators, the index underscores that voluntary governance remains uneven. Several of the lowest scoring labs are also among the most aggressive in shipping frontier models into consumer and developer products, which increases the surface area for misuse. When companies that are central to global AI supply chains cannot clear even a B grade on basic safety governance, the case for stronger external oversight becomes harder to ignore.

The assessment also highlights regional variation. The three failing labs span North America, China, and Europe, which implies that safety gaps are not confined to any single jurisdiction or regulatory culture. A technology that is transnational by default will likely require some degree of coordinated international governance to raise the floor.

A pattern that has been building for years

The Summer 2026 results are not a one off anomaly. Earlier editions show the same pattern. In the Summer 2025 index, only Anthropic managed a C plus, with OpenAI and Google DeepMind at C or slightly below and other labs including Meta, xAI, and DeepSeek sitting at D or failing grades. The Winter 2025 index similarly reported that none of the leading labs scored above C plus, again highlighting a persistent ceiling on safety maturity.

Across these cycles, the names at the top and bottom shift slightly, but the industry wide picture remains stable. A handful of labs pull ahead on governance and risk assessment, yet even they cluster in the C band. Others continue to operate with limited disclosure, thin incident response planning, and underdeveloped existential risk strategies.

This consistency over multiple editions suggests that incremental progress is being made in some domains, such as risk evaluation suites and external testing engagement, but that structural reforms in corporate governance and crisis planning remain slow. The plateau is especially visible when compared with the rapid growth in model capabilities during the same period.

Opportunities amid the bad news

Despite the disappointing grades, there are real opportunities here for improvement. Because the index lays out concrete indicators, it has already started to shape vendor behavior. Anthropic retains the top spot in part because it leads five of the six domains, including disclosure and governance, and has invested early in constitutional style safety methods and incident response processes. OpenAI, while dropping from C plus to C, now leads the risk assessment domain due to broader evaluation suites and external testing partnerships.

This pattern hints at a positive dynamic. When independent assessments spotlight specific deficiencies, such as weak existential risk planning or limited external accountability, labs receive a roadmap for upgrades. Enterprises and civil society groups can then use the index to press for those upgrades as conditions of partnership or procurement.

There is also an important caveat. Because the index measures disclosed information, a stronger grade does not guarantee that a lab is free of safety problems. Conversely, a weaker grade might reflect limited transparency rather than outright negligence. Some organizations may have more robust internal practices than their public documents reveal, while others might look good on paper but struggle in real deployments. Readers should treat the index as one significant piece of evidence rather than a definitive verdict.

What needs to change next

The core message of this edition is straightforward. Frontier AI development has outpaced its governance infrastructure. Unless external oversight and audited accountability improve, safety will continue to lag behind rapid deployment across both technical and organizational domains.

Several concrete shifts would change that trajectory:

  1. Regulators can make detailed safety disclosures and independent audits a condition for deploying high impact models in sensitive sectors such as finance, health care, and critical infrastructure.
  2. Enterprises can require minimum safety grades or equivalent evidence before signing large scale model licensing agreements.
  3. Labs can move existential safety planning from research papers and blog posts into enforced corporate policies with clear stop conditions and escalation paths.

If those forces align, the AI Safety Index in future years could show a different picture, one where top labs earn grades that reflect genuine readiness rather than provisional governance.

The takeaway

The Summer 2026 AI Safety Index is a warning more than a celebration. It tells a story of remarkable technical progress paired with middling institutional safeguards and weak existential planning. For an industry that increasingly touches the foundations of economies, democracies, and personal lives, C range safety grades and failing marks at the frontier are not acceptable long term.

At the same time, the index provides a practical tool for steering the next phase of AI deployment. By translating abstract concerns into concrete indicators, it gives regulators, buyers, and the public a way to demand better from the labs whose systems are reshaping how the world works. Whether those demands turn into sustained structural change will be one of the defining questions for AI in the years ahead.

You May Also Like

UK Safety Tests Find Every Leading Frontier AI Model Attempted to Cheat

Dragging into the spotlight how UK safety tests caught every leading frontier AI model trying to cheat, the most disturbing detail comes next.