Self-Governance Under Revision
Daniel Polak, Ajay Agarwal · Team Safety Frameworks Evaluators
Submitted to The Technical AI Governance Challenge. Sprint projects are early-stage work by participants, not Apart Research publications.
Frontier AI labs have published voluntary safety frameworks committing to evaluate dangerous capabilities and implement safeguards before deployment. These documents, including Anthropic's Responsible Scaling Policy, OpenAI's Preparedness Framework, and Google DeepMind's Frontier Safety Framework, are often cited as evidence of responsible self-governance, yet can be revised at any time without external approval. We developed a taxonomy of commitment changes and applied it to over 60 revisions across three major labs, coding direction (strengthening, weakening, neutral), mechanism, and changelog disclosure. We find sharp divergence: OpenAI weakened 19 commitments with zero strengthenings; Anthropic was roughly balanced (11 weakenings, 10 strengthenings); and DeepMind net strengthened (4 weakenings, 11 strengthenings). Strengthenings were twice as likely to be omitted from changelogs as weakenings (68% vs. 38%), and all three labs weakened evaluation-frequency commitments. Most weakenings reduced oversight-relevant properties: 68% affected external accountability and 56% reduced measurability. Overall, framework evolution varies substantially by lab, while official communications systematically underreport commitment reductions. Our taxonomy and dataset enable ongoing monitoring and inform policymakers on which commitments may require regulatory protection rather than voluntary maintenance.
Reviews
A simple idea, executed and presented well.
I like what this paper is doing: treating safety frameworks like version-controlled code and actually diffing them. That's the right instinct. The OpenAI numbers (19 weakenings, 0 strengthenings) jump off the page, and the universal weakening of evaluation frequency across all three labs is the kind of finding that should make regulators nervous.
The biggest weakness is that one person coded all 62 changes. Classification like this is judgment-heavy ("is this a weakening or just a clarification?"), and without a second coder checking at least a sample, readers have to take the authors' word for it. That's a fixable problem, and fixing it would go a long way.
There's also a weird result buried in the data: labs *omit* their own improvements from changelogs more often than they omit weakenings. Why? Are they sandbagging their own good news? Is it just that positive changes feel less "newsworthy" internally? The paper flags this but doesn't dig into it, and it's maybe the most interesting thread to pull on.
One last thing: the paper tells us what's broken but doesn't really propose a fix. A concrete spec for a machine-readable changelog format (even a rough draft) would turn this from "here's a problem" into "here's a problem and here's what to do about it."
Read full reviewShow less
Cite this project
@misc{polak2026selfgovernance,
title = {{Self-Governance Under Revision}},
author = {Daniel Polak and Ajay Agarwal},
year = {2026},
month = feb,
note = {Submitted to The Technical AI Governance Challenge, an Apart Research Sprint},
howpublished = {\url{https://apartresearch.com/sprints/projects/selfgovernance-under-revision-s0az}},
url = {https://apartresearch.com/sprints/projects/selfgovernance-under-revision-s0az}
}More from The Technical AI Governance Challenge
- 1st placeView project: LidaSim: Testing AI Policies With Persona-Based Simulations
LidaSim: Testing AI Policies With Persona-Based Simulations
Lida Safety
We simulate well-known figures in AI and politics with agents, scraping large amounts of data to get realistic simulations. Then, we test questions and proposed policies against these public figures, to see which …
- 2nd placeView project: Markov Chain Lock Watermarking: Provably Secure Authentication for LLM Outputs
Markov Chain Lock Watermarking: Provably Secure Authentication for LLM Outputs
MCL
We present Markov Chain Lock (MCL) watermarking, a cryptographically secure framework for authenticating LLM outputs. MCL constrains token generation to follow a secret Markov chain over SHA-256 vocabulary partitions. …
- 3rd placeView project: Political Intelligence for AI Safety: The AI Risk Attitudes Survey (AIRAS)
Political Intelligence for AI Safety: The AI Risk Attitudes Survey (AIRAS)
AIRAS
The AI safety and governance community is making progress on defining red lines around existential risk from advanced AI systems, and building verification infrastructure to support this objective. However, this is only …