SecurityTechInsider AI security & governance
EN/ NL
Governance

US AI safeguards become concrete: what to record per model and workflow

The US frontier assessment framework and Senate duty-of-care plans make AI safeguards auditable. Learn what evaluations to record per model and workflow.

17 September 2026 4 min
Illustration for this article: US AI safeguards become concrete. The cut edges of a thick stack of blank paper, fanned slightly, raking light along the fibres.
US AI safeguards now require documented evaluation records and demonstrable controls per model and workflow, shifting governance from voluntary practice to auditable obligation. Image: SecurityTechInsider — original editorial illustration

You must now record, per AI model and workflow, which government or standard evaluations it has passed, which safeguards are documented, and how you demonstrably apply those controls locally. This is no longer optional practice; it is becoming an auditable obligation.

The prompt is an analysis of 17 September 2026 of US frontier assessment frameworks and Senate duty-of-care proposals, which argues that AI safeguards are shifting from non-binding commitments to concrete, recordable obligations. Executive Order 14409 established a classified benchmarking process and a voluntary framework through which government experts can examine advanced frontier models before public release, finalised by the White House in August 2026. In our assessment, the significance lies not in the framework's voluntary label, but in the fact that a model can now demonstrably either have or have not undergone government assessment—a distinction that matters for anyone deploying such a model in sensitive work.

What has changed in US AI governance?

The US is moving away from abstract safety rhetoric towards auditable safeguard requirements. Executive Order 14409 required US agencies to establish a classified benchmarking process within sixty days and a voluntary framework for government experts to examine frontier models up to thirty days before public release. That framework is now operational, though not public. Separately, Senate negotiators are considering legislation that would impose a statutory duty of care on AI developers, requiring them to design products so that catastrophic risks are prevented, with government and judges potentially able to block the release of unsafe models.

This represents a shift from promises to possible statutory obligations, audits and powers to restrict deployment. The direction is already usable for governance teams: safeguards become something whose existence you must be able to demonstrate, not merely assert.

Which safeguard obligations apply to your deployment?

There is no comprehensive federal AI law in the US, so safeguards emerge through multiple overlapping instruments. These include frontier-AI frameworks, risk assessments for catastrophic risks, documentation requirements, governance programmes, impact assessments and designated responsible officers. The practical conclusion is that you do not follow a single law, but must know per model and per state which of these instruments apply.

For professionals deploying AI in confidential or high-trust work, the question shifts from "is this model safe?" to "can I demonstrate which safeguards exist and how I apply them?"

What must you record per substantial AI deployment?

  1. Identify the model and its lawful basis — document which model each workflow uses, its source, and the lawful basis for any personal data it processes.
  2. Record government and standard evaluations — capture which frontier assessments, safety tests or industry benchmarks the model has passed.
  3. Document safeguards in place — list the specific controls applied to the model in your workflow, including access restrictions, output monitoring and human review steps.
  4. Establish responsible oversight — designate who owns the model's governance, who approves its use in each workflow, and who monitors its performance.
  5. Log integration and verification — record when the model was integrated, which evaluations were reviewed before deployment, and what logs or records show safeguards were actually applied.

Which failure modes must your safeguards address?

  • Frontier-model capability drift — advanced models may exhibit unexpected capabilities or behaviours not caught by pre-release assessment.
  • Deployment context mismatch — a model safe in one workflow may pose unacceptable risk in another, depending on data sensitivity and decision stakes.
  • Catastrophic-risk scenarios — models used in high-trust decisions may cause harm if they hallucinate, contradict themselves or are manipulated through adversarial input.
  • Supply-chain opacity — you may not know which evaluations a model has undergone or which safeguards the provider has implemented.
  • Audit trail gaps — you cannot demonstrate after the fact which safeguards were applied when the model was integrated or how it was monitored.

How can tooling support this work without replacing your judgement?

Verification layers and privacy-focused infrastructure can increase visibility and control. A verification layer can route a task through selected independent models and expose verification steps, corrections, disagreements and sources for inspection—making control and recording possible without certifying that an answer is correct or removing the risk of hallucinations. Privacy-focused infrastructure can replace sensitive document values with synthetic, session-only equivalents before AI processing, with workflows that fail closed so that when a privacy check fails, nothing is sent onward.

These tools do not certify safety or remove your responsibility. The professional final judgement—which model to use, which workflows warrant deployment, which safeguards are sufficient—remains yours. Tooling can make that judgement auditable and your compliance demonstrable.

Sources: This article draws on reporting and guidance from Congressional Research Service, Institute for Project Management, Axios, Reuters and Inside DeepTech.

Marit Halversen

Written by

Marit Halversen

Covers AI governance and regulatory design, with a focus on how compliance obligations land on architecture rather than on paperwork.