The Conventional Wisdom
When the Frontier Model Forum launched, it followed a familiar pattern: major AI companies forming a voluntary consortium to "advance AI safety research" and "identify best practices." The industry greeted it with cautious optimism. The hope was that we'd finally have a coordinated voice to shape standards before regulators imposed them.
This narrative assumes that industry self-organization leads to effective governance. That collaborative forums lay the groundwork for regulation. That voluntary cooperation among frontier model developers will produce the safety frameworks we need.
It's a comforting story. It's also incomplete.
Why We Disagree
Industry bodies don't create governance frameworks. They produce consensus documents reflecting the lowest common denominator among members with competing interests. The Frontier Model Forum may advance research and facilitate information sharing, but confusing that activity with governance architecture is a mistake.
Here's what industry consortia actually do well: They coordinate on pre-competitive technical standards, like model card formats or API specifications. They aggregate member concerns into policy recommendations. They provide a single point of contact for regulators who'd otherwise need to engage dozens of companies separately.
What they don't do: Set binding requirements. Enforce compliance. Resolve conflicts between commercial incentives and safety obligations. Create accountability structures with real consequences.
You can't outsource governance to the entities being governed. The EU AI Act doesn't delegate conformity assessment to industry working groups. SR 11-7 doesn't suggest banks form a consortium to define model validation standards. ISO/IEC 42001 certification requires third-party auditors, not peer review from competitors.
The Evidence
Look at how actual AI governance frameworks allocate responsibility. The EU AI Act places legal obligations on providers and deployers, not industry associations. Article 9 conformity assessment must be performed by notified bodies or through internal procedures subject to regulatory oversight. The General-Purpose AI Code of Practice, while developed with industry input, will be enforced through regulatory mechanisms, not voluntary compliance.
ISO/IEC 42001 requires top management commitment (Clause 5.1), documented AI policies (Clause 5.2), and competent personnel assigned to governance roles (Clause 7.2). None of these requirements can be satisfied by joining an industry forum. Your AI Management System needs internal controls, risk owners, and audit trails that exist whether or not you participate in collaborative research.
The NIST AI RMF makes this explicit in the Govern function: "Governance is enacted through specific policies, processes, procedures, and practices." Industry bodies can inform those policies. They cannot substitute for them.
Consider vendor due diligence under SR 11-7. If you're deploying a foundation model from a Frontier Model Forum member, you still need to validate its performance on your use case, document its limitations, and monitor it post-deployment. The provider's participation in safety research doesn't reduce your validation burden. Their commitment to safety doesn't transfer liability.
What to Do Instead
Build your governance framework on regulatory requirements and recognized standards, not industry commitments.
Start with your risk tier. If you're developing high-risk AI systems under the EU AI Act, your conformity obligations are non-negotiable. Map them to internal controls. Assign owners. Document evidence. An industry body's white paper on safety research doesn't check any of those boxes.
If you're implementing ISO/IEC 42001, use Annex A as your control baseline. Clause A.6.1.3 requires you to determine and document the intended purpose and reasonably foreseeable misuse of your AI system. That determination happens in your organization, by your team, based on your context. Industry consensus might inform your analysis, but it doesn't replace it.
For financial services firms operating under SR 11-7, your model risk management framework must include effective challenge, independent review, and ongoing monitoring. These functions require internal separation of duties and technical competence. Participating in information-sharing forums is fine. Relying on them as your second line of defense is not.
Use industry bodies for what they're good at: technical coordination, research collaboration, and pre-competitive standard development. When the Frontier Model Forum publishes research on adversarial simulation techniques, read it. When they propose a common format for system cards, consider adopting it. When they engage with policymakers, track the dialogue.
But don't mistake coordination for compliance. Don't substitute their roadmap for your risk assessment. And don't assume that because your foundation model provider joined a safety consortium, you can reduce your vendor due diligence.
When the Conventional Wisdom Is Right
Industry bodies do serve a legitimate governance function in one specific context: when regulation explicitly delegates standard-setting authority to them.
The EU AI Act's General-Purpose AI Code of Practice will be developed with industry participation. If you're a GPAI provider, engaging with that process isn't optional. The code will establish presumption of conformity with certain obligations. That's regulatory delegation working as designed.
Similarly, when ISO technical committees develop AI standards, industry expertise is essential. ISO/IEC 42001 reflects years of multi-stakeholder input. The resulting standard has teeth because it's backed by third-party certification, not because the drafting committee reached consensus.
Industry bodies also matter when they create interoperability standards that reduce friction across the AI supply chain. If major foundation model providers agree on a common format for technical documentation, that makes your vendor due diligence more efficient. If they standardize API rate limiting approaches, that simplifies your integration risk assessment.
The conventional wisdom is right about one more thing: unilateral company commitments are even weaker than industry consortia. A forum with multiple members, public commitments, and some governance structure is better than nothing. It's just not a substitute for actual governance.
So participate in industry bodies if the work aligns with your interests. Learn from their research. Adopt their technical standards when they're sound. But build your AI governance framework on requirements you can be held accountable for, not commitments someone else made on your behalf.



