
On 8 September 2026, Eastern time, a twenty-seven-year-old pretraining researcher named Jacob Coxon resigned from Anthropic and left the artificial intelligence industry altogether. In the small hours of 9 September, he set out his reasons in public. Three years of building models, first at OpenAI and then at Anthropic; neither company, in his assessment, acting responsibly; both racing toward self-improving superintelligence and, in his phrase, gambling with our lives. By mid-morning the thread had twenty-one million views.
He disclosed no document. Nothing was smuggled out, because the conduct he objects to is carried on in the open, with the risks internally assessed and the reasoning written down. That is the feature of the episode worth examining. Governance regimes built to force information into the light have little to say about a firm that has already published and proceeds regardless.
Three Tiers, and Only One With Teeth
Modern industrial governance rests on three tiers. The State legislates and licenses. The individual firm adopts internal standards and binds its own conduct. The industry, collectively, sets shared codes, benchmarks and compliance norms that no single member could sustain alone. Pharmaceuticals, aviation, banking and securities all run on some version of this arrangement, and it works when the three tiers reinforce one another.
All three exist in artificial intelligence today. Two of them cannot compel anything, and the third is being actively dismantled.
What the Firms Have Written for Themselves
The frontier laboratories have produced a genuine body of internal governance. Anthropic’s Responsible Scaling Policy, first published in September 2023, ties defined capability thresholds to defined safeguards. OpenAI’s Preparedness Framework, Google DeepMind’s Frontier Safety Framework and Meta’s Frontier AI Framework of February 2025 do comparable work. These are serious documents, drafted by people who understand the hazard better than any outside regulator currently does.
Their structural weakness is not sincerity but authorship. The firm writes the standard, interprets it, tests itself against it, certifies its own compliance, and amends it when compliance becomes inconvenient. No external consent is required at any stage. A framework revisable at the discretion of the party it constrains is a statement of intent, however well meant.
Google’s AI Principles illustrate the point without any need for cynicism. Published in June 2018 after internal dissent over a defence contract, they included an undertaking not to design artificial intelligence for weapons or for surveillance violating international norms. In February 2025 the principles were revised and those exclusions were removed. Nothing improper occurred. A promise made to oneself was withdrawn by the party that made it.
Self-Regulation Properly So Called
Industry-level governance in artificial intelligence is thinner than the vocabulary suggests. The Frontier Model Forum, established in July 2023 by Anthropic, Google, Microsoft and OpenAI, convenes research and shares practice. The Partnership on AI develops guidance. Sixteen companies signed the Frontier AI Safety Commitments at Seoul in May 2024, undertaking to publish safety frameworks and to identify thresholds at which risks become intolerable.
Set these against self-regulation in its established sense. The Financial Industry Regulatory Authority operates under statutory charter and the supervision of the Securities and Exchange Commission; membership is a precondition of doing business; it can investigate, fine and expel; and its determinations are reviewable. Medical councils, bar councils and accountancy institutes are constituted the same way: delegated public authority, compulsory membership, the power to end a career, and a court above them.
The AI bodies have none of these attributes. There is no charter, no compulsory membership, no investigative power, no sanction and no expulsion. A firm that departs from a Seoul commitment faces reputational comment. Self-regulation, properly understood, is delegated regulation. What the industry has built is coordinated publication.
Aviation shows what delegated certification requires. The Federal Aviation Administration has long deputed certification work to manufacturers through Organization Designation Authorization, and the arrangement was defensible precisely because the delegation was statutory, audited and revocable. When the oversight thinned, two Boeing 737 MAX aircraft went down and Congress rewrote the certification statute in 2020. Delegation is a legitimate regulatory technique. Delegation without a delegating authority is something else.
Standards Without a Statute Are a Vocabulary
The third layer, technical standards, is the most quietly useful and the most often oversold. The NIST AI Risk Management Framework, released in January 2023, is voluntary by design. ISO/IEC 42001, published in December 2023, certifies that an organisation operates an artificial intelligence management system.
Both give auditors a common language, which matters. Neither certifies that a model is safe. A management-system standard attests that a process exists and is followed, not that the process reaches the right answer. An organisation can hold certification and still train a system it does not understand, because the standard governs the paperwork of judgment rather than the judgment.
The State Moves, Then Retreats
Statutory regulation is the only tier with the power to bind, and its recent history is contradictory.
California’s Transparency in Frontier Artificial Intelligence Act, SB 53, signed on 29 September 2025 and in force since 1 January 2026, is the first law anywhere directed at catastrophic risk from the largest models. It compels publication of a safety framework, requires critical safety incidents to be reported to the state’s emergency office within fifteen days, bars contractual gagging of employees who raise catastrophic-risk concerns, and obliges developers to maintain an anonymous internal channel for such reports.
Coxon had that channel available and used a social media platform instead. The likeliest explanation is that his objection lies outside what the statute governs. SB 53 addresses concealment. His allegation is that the danger is acknowledged and the work continues, which no disclosure law reaches.
Federal policy has moved against even this. The executive order of 11 December 2025, Ensuring a National Policy Framework for Artificial Intelligence, directs the Attorney General to establish an AI Litigation Task Force to challenge state AI laws as burdens on interstate commerce, instructs the Commerce Department to identify onerous state statutes, and conditions some forty-two billion dollars of broadband funding on their repeal. The Senate had rejected a ten-year moratorium on state AI legislation in July 2025 by a near-unanimous vote, after which the administration turned to executive instruments. The one American statute addressing frontier catastrophic risk is under challenge, and no federal substitute has been proposed.
The European Union offers scale without reach. The AI Act entered into force on 1 August 2024, but its implementing machinery, harmonised standards, notified bodies and national market-surveillance authorities, was not ready in time. Regulation (EU) 2026/1744, the Digital Omnibus, in force from 27 July 2026, deferred the high-risk obligations from 2 August 2026 to 2 December 2027, and to August 2028 for artificial intelligence embedded in regulated products; only the Article 50 transparency duties held to schedule. In any event the Act governs deployment, hiring tools, credit scoring, biometric identification, rather than the training run itself. No jurisdiction currently specifies at what scale of compute, on what prior assessment, and over whose signature a self-improving system may lawfully be built.
Internationally there are four summits and no treaty: Bletchley in November 2023, Seoul in May 2024, Paris in February 2025 and New Delhi in February 2026. Coxon’s own stated hope is for pacing agreements between the American laboratories, which raises a difficulty rarely acknowledged. An agreement among competitors to restrain output, concluded without statutory cover, is either unenforceable or unlawful, competition law having been designed to break up arrangements of that shape. The only lawful vehicle for pacing is a mandated one.
India’s position is narrower still. The MeitY guidelines of 5 November 2025 offer seven sutras, an AI Safety Institute and an express preference for voluntary commitment, self-certification and regulatory sandboxes over statute; the IT Amendment Rules notified in February 2026 govern synthetically generated content through labelling, provenance and takedown. As a large consumer of models built elsewhere and deployed into its banks, land records, welfare rolls and elections, India carries the risk of the frontier without holding any locus standi over it.
Who Certifies, Who Inspects, Who Pays
Strip away the novelty and the State faces the three questions it puts to any private undertaking that manufactures a hazard.
Who certifies. Above a threshold of compute, a licence should precede the training run rather than a press release follow it.
Who inspects. A safety institute lacking compute and evaluators of its own can do no more than read what the developer chooses to send it.
Who pays. No liability rule attaches today in any jurisdiction, though the precautionary and polluter-pays principles have been ordinary law in most of them for thirty years.
A fourth question follows from the resignation itself. When the only avenue open to a researcher of conscience is a post published at half past five in the morning, the arrangements for hearing bad news have failed. The insider needs a statutory channel and protection for using it.
Firm-level frameworks and industry codes are worth having, and the tier that gives them force is the one that charters them, audits them and withdraws the licence when they are ignored. Coxon may be wrong about his timelines; insiders frequently are. The State does not regulate on the premise that the alarmist is right, but on the premise that he might be, and that if he is, the loss cannot afterwards be made good. A resignation is a personal act, and an honourable one. It is not a regulatory instrument.