When frontier AI labs signed a round of voluntary safety commitments, agreeing to practices like pre-deployment testing, red-teaming, and information sharing about model capabilities, the natural skepticism was that voluntary commitments with no enforcement mechanism are close to meaningless. A company can sign a pledge and quietly under-deliver on it with little real consequence beyond reputational risk, and reputational risk has historically been a weak deterrent in fast-moving technology markets.
What has happened since is more interesting than either the optimistic or the cynical prediction. Government AI safety institutes, standing up in the UK, the US, and several other jurisdictions, have started using those same voluntary commitments as the practical baseline they evaluate frontier models against, even in the absence of binding legislation that would require it. A commitment that started as a public relations gesture is functioning, in practice, as the first draft of a regulatory standard, evaluated by institutions with growing technical capacity to actually test whether it is being met.
Soft Law Moving Faster Than Hard Law
This pattern has a name in policy circles: soft law, non-binding norms and standards that end up shaping behavior through reputational, market, and institutional pressure well before, or instead of, formal legislation. AI safety governance is turning into one of the clearer recent examples of soft law moving faster than hard law, largely because the pace of model development has outrun the pace at which most legislatures can draft, debate, and pass binding rules. Safety institutes filled that gap by building technical evaluation capacity and simply starting to test models against the commitments labs had already made, whether or not a law required them to.
The result is a governance structure that looks informal on paper but is developing real teeth in practice. A frontier lab that wants continued access to government pre-deployment testing relationships, continued credibility with enterprise customers who increasingly ask about safety evaluation results, and continued standing in a policy conversation that will eventually produce binding rules, has strong incentives to actually meet the commitments it signed, even without a court able to enforce them today. The UK's AI Safety Institute and the US AI Safety Institute housed within NIST, documented at nist.gov, have both published evaluation methodologies that labs are now designing pre-release testing around, not because they are legally required to, but because the alternative is being publicly out of step with an emerging baseline everyone else in the industry is visibly meeting.
There is a real risk in this arrangement worth naming honestly: soft law built on voluntary commitments and institutional reputation can erode as quietly as it formed, if commercial pressure intensifies or if a lab decides the reputational cost of falling short is one it can absorb. Voluntary frameworks lack the durability of legislation precisely because they can be voluntarily abandoned. The current equilibrium holds because enough of the frontier labs have concluded that being seen as the company that broke ranks is more expensive than the cost of compliance, and that calculation could change.
XioX's view is that this soft-law period, however informal it looks, is not a placeholder to be ignored until real regulation arrives. It is actively setting the substantive baseline that eventual binding legislation is likely to codify, the same way industry self-regulatory practices in other sectors have historically become the starting template for the laws that followed them. Teams building on frontier models should be reading safety institute evaluation methodologies now, not because they are legally binding today, but because they are a reasonably reliable preview of what compliance will formally require tomorrow.
Advertisement