The highest grade any AI company earned was a C+. That was Anthropic, which has spent years building a brand around being the careful one. Below it, OpenAI and Google DeepMind each landed a C. Meta pulled a D+. Three companies — xAI in the US, DeepSeek in China, Mistral in France — failed outright. Nobody got an A. Nobody got a B.
That is the result of the Future of Life Institute's Summer 2026 AI Safety Index, published July 7 — the fourth edition of a biannual exercise the nonprofit began in late 2024. It asks an independent panel of outside experts to grade leading AI developers on how seriously they manage risk. This round's finding is not that the industry is standing still. It is that on several measures, the panel says, it is walking backward.
What the index actually measured
The Summer 2026 edition evaluated nine companies across 37 indicators in six domains: Risk Assessment, Current Harms, Safety Frameworks, Existential Safety, Governance & Accountability, and Information Sharing. Seven reviewers assigned domain-level grades against absolute standards; final scores are averaged, individual grades kept confidential.
On FLI's 4.0 scale, Anthropic scored 2.66, OpenAI 2.28, Google DeepMind 2.01, Meta 1.32. Z.ai and Alibaba Cloud each drew a D-. xAI scored 0.65, DeepSeek 0.47, Mistral 0.33. Anthropic led five of six domains; OpenAI took Risk Assessment on a broader evaluation suite and wider engagement with external testers. Meta climbed from sixth to fourth. xAI fell from fourth to seventh — the sharpest drop on the board.
The evidence base closed June 3, combining public material — model cards, papers, benchmarks — with a voluntary survey. Five of nine completed it; Alibaba Cloud, xAI, DeepSeek, and Mistral did not respond.
The retreat
The panel's most pointed finding concerns pause commitments. Anthropic, OpenAI, Google DeepMind, and Meta have all, in the reviewers' assessment, weakened or voided earlier pledges to halt development unilaterally if their systems approached red lines — some replacing categorical triggers with conditions contingent on what competitors do. Reviewers called this "moving goalposts," which they said has "undermined safety frameworks across the board."
The index singles out Anthropic. In February the company published Responsible Scaling Policy version 3.0, removing the prior framework's hard stop — the commitment not to train more capable systems absent safety measures demonstrated adequate in advance. FLI's top recommendation is blunt: "Reverse the RSP 3.0 walk-back on pause commitments."
Anthropic's own account is more textured. In its February post, the company said pre-set capability thresholds proved "far more ambiguous than we anticipated," that evaluation science "isn't well-developed enough to provide dispositive answers," and that mitigations at higher safety levels "might prove outright impossible to implement without collective action." It said it restructured transparently rather than define compliance down, adding a Frontier Safety Roadmap, periodic Risk Reports, and external review of them. Reasonable people read the same change as pragmatism or as erosion. FLI's panel read erosion.
The second finding concerns military work. From 2024 to 2026, the index says, companies including Anthropic, OpenAI, Google DeepMind, and Meta that once banned military applications gradually reversed course, joining xAI and Mistral in seeking defense partnerships. "Boy oh boy has that changed," FLI president Max Tegmark told Axios. The panel criticized Anthropic for "questionable military engagements," including a reported link to the Minab school strike that caused mass civilian deaths, despite its limits on domestic surveillance and autonomous weapons. Alibaba Cloud and Z.ai deny U.S. allegations of military ties.
Existential Safety was the weakest domain industry-wide; no company exceeded C-. Reviewers acknowledged concrete work — Anthropic's constitutional classifiers, OpenAI's call for governance institutions, Meta's loss-of-control provisions — but judged it "entirely inadequate," questioning interpretability and chain-of-thought monitoring because "detection is not prevention."
"Companies have backed away from earlier commitments to release new systems only with safety measures appropriate for their capability levels," said panelist Stuart Russell, the UC Berkeley computer scientist. "Now, they're planning to release them even if it's demonstrably unsafe to do so."
What a letter grade can and cannot do
The instrument deserves scrutiny alongside its subjects. FLI is an advocacy organization with a stated position on catastrophic AI risk, and its panel skews toward researchers who share it. That is not a hidden agenda — FLI says plainly the index exists to create reputational pressure. But the grades encode a theory of what matters, and a company optimizing for a different theory scores badly by construction. They are averaged human judgment, not measurement.
The index also measures only what is legible: published frameworks, disclosed policies, benchmarks, survey answers. A firm with excellent documentation and mediocre practice outscores the reverse. Four of nine declined the survey, depressing their scores in ways that may or may not track actual safety posture. And the Chinese firms' grades, FLI concedes, "largely reflect the Chinese regulatory environment rather than independent safety leadership" — a problem it flags rather than solves.
Mistral, graded last, rejected the frame. Its models are open weight, it told Axios, "which means enterprises decide how they're fine-tuned and deployed and can build in the specific safety controls their context requires." It added: "A handful of companies deciding, behind closed doors, what's safe for everyone else is a risk that we would also highlight."
One clarification, given this newsletter covers the graded labs: Anthropic finishing first is a third party's judgment, not an endorsement — and first place means a C+, a grade FLI intends as criticism.
What to watch
The evidence closed June 3, before the attention around Anthropic's Mythos and OpenAI's GPT-5.6; whether those releases shift safety practice is the open question for the Winter edition. Watch also whether the EU's General-Purpose AI Code of Practice and frameworks like California's SB 53 convert voluntary pledges into obligations — the wager being that the voluntary system is eroding, as Axios framed it, before a durable alternative exists. Tegmark says the survey is "already having an impact in internal discussions," noting participation has risen from near-zero to a majority. "It shows that they care," he said. The next scorecard tests whether caring moves grades.
“Companies have backed away from earlier commitments to release new systems only with safety measures appropriate for their capability levels; now, they're planning to release them even if it's demonstrably unsafe to do so.”— Stuart Russell, Professor of Computer Science, UC Berkeley