The Future of Life Institute released its 2026 AI Safety Index this week, grading the world's leading AI companies on governance, transparency, and risk management. The result is uncomfortable: not even the number-one spot scored above a C+. Anthropic ranked first, with a C+; OpenAI and Google DeepMind followed with a C; Meta received a D+; and xAI, DeepSeek, and Mistral failed the assessment outright.
What Changed
According to the Future of Life Institute's report, corroborated by outlets including Axios, TIME, and MIT Sloan Management Review, Anthropic leads five of the six evaluated dimensions — transparency, an already-established safety framework, technical research, and governance — yet still doesn't clear a C+. The institute itself was blunt: even the top-ranked companies' current safety measures are "completely inadequate" relative to the pace of AI capability advancement.
Why It Matters
For anyone buying or deploying AI inside a company, this index is a simple reminder: no AI vendor — not even the ranking's leader — has safety governance mature enough to treat as settled. Choosing an AI vendor today can't be just a decision about technical capability or price; it's also a risk decision, exactly like any other critical outsourcing choice.
The Impact for Brazil
Brazilian companies selecting AI vendors — or already relying on one for critical processes — now have a concrete due-diligence criterion: ask for transparency into a vendor's safety practices, and don't assume that "being the biggest" or "being the most-used model" equals being the safest. This connects directly to the ongoing discussion around Brazil's AI bill (PL 2338): risk assessment shouldn't wait for the law to take effect — it should already be part of the procurement process.
Entercast's Take
We've talked a lot about the bottleneck being implementation, not the model (see yesterday's post on OpenAI buying Northslope). This index shows the other side of the same coin: neither implementation nor the model alone solves the trust problem. AI governance — who you buy from, how you audit them, what you require contractually — needs to sit at the center of your adoption strategy, not be a compliance checklist bolted on after the project is already live.