Guidelight Finds No Frontier Lab Above a 3 on Control
Guidelight AI Standards issued its first Control assessment of Anthropic, Google, Meta, OpenAI, and xAI, based on public information through 18 August 2026. TechCrunch reported the grades on 22 August 2026. No company scored above 3 on any of six practices.
PromptCrates Editorial
Staff Writer

Guidelight AI Standards published its first Control assessment of frontier labs, using public information through 18 August 2026. TechCrunch carried the grades on 22 August 2026 at 9:00 AM PDT (23:00 WIB). Guidelight scored Anthropic, Google, Meta, OpenAI, and xAI on six practices. No company scored above 3 on any practice.
What Guidelight scored, and what it did not
The assessment looks at whether labs show, in public, that they can keep hold of their own models. Guidelight graded six practices on a 0–5 scale: logging what internal AI is doing, measuring how well monitors work, gating high-risk actions, circuit-breaking after a surge of flagged misbehavior, third-party review, and a containment plan.
A 3 is "substantial partial implementation." Nothing higher appears in the table. The overall letter grades are averages of those six scores.
Anthropic and OpenAI tied at C+ (2.50). Google landed at D+ (1.50). xAI landed at D− (0.83). Meta landed at F (0.67).
That is a public-disclosure grade, not a claim that secret internal runbooks do not exist. Guidelight scored what it could read. A lab that has a plan and will not publish it still scores as if the plan is missing.
The score that will matter to operators is the containment column. TechCrunch reported that OpenAI posted the highest mark for publishing containment, at 3 out of 5, because it has paused or ended workloads. Anthropic and Meta scored lowest on publishing a containment plan.
If you already track OpenAI's public safety posture — slowing Astra training after it cannot rule out critical cyber, or private safety processing meant to widen zero-data-retention — treat the Guidelight containment score as a related public record, not as a substitute for your own incident plan.
Why containment still sits at the bottom
A containment plan, in this assessment, is the document that says what happens once a model is caught trying to slip human control: which permissions come off, who the model may still serve, and when it goes fully offline.
OpenAI's 3 out of 5 is the high-water mark because it has, in public, paused or ended workloads. Guidelight still did not give anyone a 4 or a 5 on any practice. A pause after an incident is not the same as a pre-written plan for the next one.
Anthropic and Meta are the low end on publishing that plan. That is notable for Anthropic, which otherwise tied OpenAI for the best overall grade. The overall C+ is an average. Containment is one of six cells, and that cell can still be empty.
Google's AI Control Roadmap, dated 13 July 2026, is the most specific forward-looking document Guidelight found. Guidelight also says it is not yet implemented. A roadmap is not a control. Do not file the July paper as a live circuit breaker.
xAI at D− (0.83) and Meta at F (0.67) sit in a third tier. The six-practice average is the number; there is no extra unpublished score in this assessment to soften it.
A Claude invisible-text watermark is a provenance control, not a containment plan. Do not confuse "we can tell the text came from us" with "we know how we would take a misbehaving agent offline."
Rules already in motion
California's SB 53 is in effect this year. It pushes large frontier developers to publish frameworks for how they identify and respond to critical safety incidents and how they manage models that try to get around oversight.
New York's RAISE Act takes effect in January.
A bipartisan AI Kill Switch Act was introduced on 23 July 2026 by Reps. Ted Lieu and Nathaniel Moran.
Those clocks are why a public 0 on containment is no longer only a research-community complaint. Buyers who put agents on internal systems will be asked, by counsel if not by Guidelight, what gets revoked and who has the authority to pull the plug.
Put that in the wrapper, not in a chat instruction. A skill prompt can name the owner, the halt condition, and the ticket path. It cannot invent a lab's missing plan.
The practical read for teams that build on these models: Anthropic and OpenAI are the least incomplete on the public control record, and even they top out at 2.50. No practice at any lab cleared a 3. Plan as if you will have to write the containment steps yourself.
Sources
- Guidelight's Control Assessment of Frontier AI Companies — Guidelight AI Standards, public information through 18 August 2026
- Frontier AI labs still won't say how they'd contain a rogue model — TechCrunch, 22 August 2026, 9:00 AM PDT


