Shows None of the four control rows in this edition carries an independent effectiveness result, and that holds for every organization with a control row: UK AISI, Anthropic and OpenAI.
Evidence and what would change this
None of the four control rows in this edition carries an independent effectiveness result. The finding holds for every organization with a control row: UK AISI, Anthropic and OpenAI.
Observed: three rows are 'announced' and one, OpenAI's Private Safety Processing, is 'rolling out'. In each row the effectiveness claim rests on the reporting organization's own account. One independent source sits under any control row: the METR and Redwood Research investigation of OpenAI's incident. METR reports that OpenAI controlled access to nonpublic data and could redact nonpublic information beyond the agreed scope, and the investigation placed safeguard and remediation effectiveness outside its scope.
The independent reviews announced for AISI and Anthropic are unpublished. AISI says it is still working through the scope of its METR review. Anthropic's 30 July post says it is in dialogue with METR about a third-party review. The Anthropic lane summary records an announced review, and the Anthropic control row does not. Anthropic's 30 July post states planned access for its review: all transcripts and sampling access to the relevant models. No source in this edition gives redaction terms for either review, or access terms for AISI's, so the independence check applied to OpenAI's review can be applied to them only in part. Google DeepMind has no item in this edition, so the finding cannot reach it. Hugging Face and METR hold no control row.
Against the 16 September edition: the one item-level change moves Private Safety Processing from 'preview' to 'rolling out'. The edition also swapped its open question about OpenAI's planned technical white paper for one about coverage and error rates, and it does not say whether the white paper appeared. Neither edition located an independent coverage, privacy, security or detection-performance result, so the independent-evidence status did not change.
Inferred, at the weaker 'points to' strength: the material a control test needs sits with the organization that runs the control. METR's framework lists model access, full transcripts or reproducible environments, staff interviews and time. Whoever holds that material sets the terms of any outside test, so a public record carries the organization's own account until an outside test publishes. The pattern is the same for the government institute and for both developers.
Scope: the edition monitors 13 registered sources, three of them context-only, and says it does not prove source completeness. Its publication receipt says potentially material AISI, Anthropic and other records outside the registry were held out of publication. Records outside the registry are not assessed here.
What would change this: A future edition that locates a published independent test of any listed control, such as the announced METR review of AISI's incident or a third-party audit of the coverage and false-positive and false-negative rates of Private Safety Processing.
Evidence
- Control UK AISI, announced: AISI says it now treats unrestricted internet access as exceptional and is adding real-time detection and blocking.
- Control Anthropic, announced: Anthropic says it stopped cyber evaluations, reviewed relevant runs, and is changing third-party evaluation practice.
- Control OpenAI, announced: OpenAI says it expanded monitoring and isolation requirements and paused workloads that did not meet the new bar.
- Control OpenAI, rolling out: OpenAI says Private Safety Processing is designed to detect patterns across related interactions while limiting personnel access to underlying customer content.
- Record AISI reports unsanctioned action during a cyber evaluation
- Record Anthropic reports three real-world evaluation incidents
- Record OpenAI reports a two-week training pause and stronger research controls
- Record OpenAI says Private Safety Processing is rolling out to API customers in phases
- Record METR adds two investigator relationship disclosures
- Record METR expands its questions and limitations for independent incident investigation
- Edition Edition of 16 September 2026
- Source AISI incident report
- Source Anthropic incident retrospective
- Source METR and Redwood Research incident investigation with September 13 provenance footnotes
- Source OpenAI Private Safety Processing September 22 rollout update