AI evaluator safeguards are protections intended to let outside experts assess frontier AI systems independently. On September 18, 2026, the AI Evaluator Forum published a letter proposing five conditions for evaluators embedded at AI companies.

The point is to pair access with independence: reviewers need enough visibility to assess systems and company practices, while retaining control over their work and findings. The Forum’s page listed more than 200 signatories when it was updated on September 23, 2026.

What the Forum means by evaluator safeguards

An embedded evaluator is an outside expert who assesses an AI company’s systems and practices from within the organization. The Forum’s proposal covers more than access to model outputs: it calls for access to relevant systems, data, tools, physical spaces and staff, so evaluators can examine risks and company practices directly.

The letter proposes five conditions for making that kind of review credible. Each addresses a different way an evaluation could lose independence or useful reach.

The five proposed safeguards

Proposed safeguardWhat the letter calls for
Substantive independenceEvaluators should not be owned or governed by the companies they assess, have other significant commercial business with them, or receive payment tied to their findings. They should retain editorial control and disclose and mitigate conflicts of interest.
Multiple perspectivesCompanies should work with multiple evaluation organizations whose expertise and risk perspectives vary, rather than rely on a single team. Differences between evaluator conclusions and employee views should be communicable.
TransparencyMethods, findings, access and evaluation terms should be disclosed. Evaluators should be able to communicate promptly and without filtering with boards or other oversight bodies. Any redactions to public findings and evidence should be narrow and time-limited.
Protection from retaliationEvaluators should have protection against retaliatory litigation and funding arrangements that do not penalize reasonable methods or unfavorable conclusions.
Employee-equivalent accessEvaluators should receive access comparable to senior employees conducting similar risk assessments, including relevant systems, data, tools, physical spaces and direct communication with staff. Exceptions should protect sensitive customer and third-party data.

In practical terms, the framework asks who controls an evaluation, whether more than one perspective can challenge it, what findings can be shared, and whether reviewers can do their work without losing access or financial support because of their conclusions.

How the proposal relates to company commitments

Separate September reports described Anthropic CEO Dario Amodei and OpenAI CEO Sam Altman as committing to integrate embedded evaluations, and xAI CEO Elon Musk as endorsing Amodei’s proposal. These reported commitments are distinct from the AI Evaluator Forum’s five conditions; they do not establish that the companies have adopted the Forum’s proposal.

The distinction matters because an evaluator’s presence inside a company is only one part of the Forum’s framework. Independence, multiple organizations, transparency, protection from retaliation and meaningful access are separate conditions, each addressing a different part of the review process.

Embedded reviews are one layer of oversight

The AI Evaluator Forum says embedded evaluations should complement—not replace—broader transparency and independent research access. Its letter calls for the proposed conditions to be standardized, codified and enforced; the letter itself sets out recommendations rather than binding requirements.