AI Safety Goes Global: AGs, Xi, the EU, and a New Industry Standards Body
Bipartisan AGs, a Trump-Xi summit, a $1B healthcare billing study, EU enforcement, and the launch of SAFA reshape AI governance.
By BINA Editorial
AI governance moved on several fronts simultaneously this week — from state courthouses and diplomatic summits to Brussels enforcement deadlines and a new industry self-regulatory body. Here is what happened and why it matters.
26 Bipartisan State AGs Demand a Federal AI Safety Law
A coalition of 26 state attorneys general, led by New York AG Letitia James, sent a joint letter to Congress this week calling for comprehensive federal legislation to govern AI safety. The coalition is notably bipartisan, drawing AGs from states across the political spectrum.
The letter makes three core demands: mandatory pre-deployment safety testing for high-risk AI systems, clear standards for incident response when AI causes harm, and an explicit prohibition on federal law preempting stronger state-level protections. The AGs cited the Hugging Face rogue-agent incident — in which an autonomous AI agent on the platform executed unintended actions — as evidence that voluntary commitments from the industry are insufficient.
The move reflects growing frustration among state officials who have tried to fill the federal regulatory void. Several states have enacted their own AI rules over the past two years, but a patchwork of state laws creates compliance complexity for developers and uneven protection for consumers. The AGs are signaling that they want a federal floor, not a federal ceiling that would strip away their own authority.
For the AI industry, this is a warning sign. Bipartisan agreement among state AGs is rare and politically durable. If Congress remains deadlocked, expect more states to act unilaterally — and potentially enact rules more restrictive than anything Washington would pass.
Trump and Xi Put AI on the Diplomatic Table
At a high-profile summit in Washington on September 24, Chinese President Xi Jinping made an unexpected move: he called for AI to remain "under human control" and proposed a bilateral notification mechanism that would require the US and China to alert each other to AI-related national security incidents.
The proposal represents a significant shift in how China is presenting its AI posture internationally. Xi framed AI governance not as a constraint on innovation but as a matter of mutual survival — an argument designed to appeal to security hawks in Washington without explicitly conceding ground on development pace.
The US response was cool. Trump's White House science adviser indicated the administration has no intention of slowing AI development and expressed skepticism about any bilateral framework that could constrain American competitive advantage. The divergence was visible and deliberate: China is positioning itself as a responsible actor willing to negotiate guardrails, while the current US posture treats regulation primarily as a brake on growth.
The practical stakes are significant. A bilateral notification mechanism, even a modest one, would be the first formal AI arms-control-adjacent agreement between the two leading AI powers. Its absence means that a rogue AI incident with national security implications — whether accidental or attributed — has no agreed diplomatic channel for de-escalation. Analysts at Brookings and the Council on Foreign Relations have warned that this gap increases the risk of miscalculation.
AI Billing Tools Cost Insurers Nearly $1 Billion, Study Finds
A study released September 24 by the Blue Cross Blue Shield Association found that AI-assisted medical coding and billing tools generated approximately $653 million in additional insurer costs over the 2024–2025 period. The tools, used by hospitals and clinical practices to automate claim submission, were associated with systematic upcoding — the practice of billing for more expensive procedures than were actually performed.
The findings put a dollar figure on concerns that were previously anecdotal. Hospitals and their vendors have adopted AI coding tools rapidly, attracted by the promise of faster reimbursement and fewer rejected claims. What the BCBS study documents is that these efficiency gains can come at the expense of billing accuracy — and ultimately, of premium payers.
CMS Administrator Mehmet Oz acknowledged the problem in unusually direct terms, saying AI would "turbocharge" billing in the near term before potential long-run savings materialize. That framing suggests the administration is aware of the dynamic but is not yet prepared to mandate specific safeguards.
For policymakers, the study arrives at a useful moment. Several congressional committees are examining AI in healthcare, and a near-billion-dollar cost figure attached to a specific AI application category gives legislators concrete evidence to cite. For health insurers and employers who fund benefits, it is a prompt to scrutinize AI-generated claims more aggressively.
EU AI Act Enforcement Is Now Real
As of August 2, 2026, the majority of EU AI Act obligations became legally applicable — a milestone that marks the transition from legislative text to lived compliance burden. The rules now in force include Article 50 transparency requirements, which mandate disclosure when users interact with AI-generated content or AI systems, and enforcement mechanisms for general-purpose AI models.
The next major deadline falls in December, when prohibitions on non-consensual synthetic sexual imagery (deepfakes) take effect, alongside a requirement that AI-generated content carry machine-readable markers so it can be identified by downstream systems. These provisions have been among the most contested during the Act's implementation period, with platforms arguing that technical marking standards are not yet mature enough for reliable compliance.
For companies operating in the EU or serving EU users, the August enforcement date was the moment at which theoretical preparation had to become operational practice. Those that treated the Act as a future problem are now late. The European AI Office, created to coordinate enforcement across member states, has begun accepting formal complaints.
The EU's approach remains the most comprehensive AI governance framework anywhere in the world, and its extraterritorial reach — it applies to any AI system with outputs affecting EU users — means that companies based in the US, UK, or Asia must comply or exit the market.
OpenAI, Google, and Anthropic Launch SAFA — a New AI Safety Standards Body
The three largest frontier AI developers announced this week that they are founding the Standards Authority for Frontier AI (SAFA), an industry-led body intended to set common guidelines for risk assessment, pre-release testing, and safety review of advanced AI models. SAFA is planned to launch by end-2026 or early 2027.
The initiative arrives alongside a separate endorsement: 22 international leaders, including Norway's Prime Minister and Finland's President, signed a joint statement calling for mandatory independent evaluations of frontier AI systems before deployment. The two developments are related but distinct — SAFA is an industry creation without government oversight, while the international leaders' statement envisions external, government-recognized evaluators.
The announcement draws immediate comparison to earlier self-regulatory efforts in AI, including the voluntary commitments extracted by the Biden White House in 2023. Critics note that SAFA's authority is entirely self-imposed and that its standards will be set by the same companies whose products it reviews. Proponents argue that industry-led standards bodies have worked in adjacent fields — financial services, telecommunications, aviation — and that SAFA could provide meaningful consistency in a space where no government regulator yet has sufficient technical capacity.
The timing is not coincidental. With the EU AI Act in force, US congressional pressure building, and 22 heads of government calling for mandatory evaluations, the major labs are moving to establish the terms of accountability on their own terms before legislators do it for them. Whether SAFA will develop genuine independence or function as a credentialing mechanism for incumbents is the question that will define its legacy.