forest, trees, fog, moss, forest floor, trunks, woods, conifers, pine trees, pine forest, mysterious, cold, atmosphere, mood, wilderness, nature, forest, forest, forest, forest, forest

What's with FARO?

forest, trees, fog, moss, forest floor, trunks, woods, conifers, pine trees, pine forest, mysterious, cold, atmosphere, mood, wilderness, nature, forest, forest, forest, forest, forest

What the heck is FARO, and why should you care?

In April this year, a lawyer at Lawfare published a policy paper that proposed a federally supervised SRO (Self-Regulatory Organization). The article calls for the new SRO to be modeled on FINRA, the financial industry’s own oversight body.

Since then, this idea has become a hot topic of conversation in the halls of power in our nation’s capital. By July, Google, Anthropic, OpenAI, and DeepMind had all published governance frameworks that looked startlingly similar to the one Lawfare described. Even Treasury Secretary Scott Bessent got in on the act, offering a (very) similar proposal that appears to have gotten the attention of the White House.

Google, always good for a catchy acronym, dubbed the concept FARO: the Frontier AI Regulatory Organization. This is clearly an idea that is being taken seriously in Washington.

The interesting thing is, it took just a little over three months for an academic paper to dominate the discussion around AI regulation. This is, by the normal sclerotic pace of change we’ve become accustomed to in DC, lightning quick.

 So, what the heck is FARO? What triggered this sudden interest in an SRO for frontier AI? What problem is it being designed to solve, and what are the chances of success? Inquiring minds want to know. 

The Catalyst

Given the state of AI regulation in the US, we can be certain that the catalyst for this sudden flurry of interest wasn’t the result of thoughtful, deliberate policy process. More likely it is a case of improvisational thinking gone wrong.

So far, Congress has done nothing to take action on AI regulation (though many States have already started), and it’s unlikely that they would, given their druthers. But… when Anthropic released Fable 5 earlier in the year and OpenAI quickly followed suit, the White House response was pretty tepid and informal: it imposed export controls, then lifted them, all the while negotiating with the country’s two leading AI companies.

There wasn’t (as far as we know) any formal policy that guided the discussions; there certainly isn’t any legal framework that could be applied. The current approach is so informal and erratic that companies are unable to plan appropriate global product strategy. Given the unpredictable way the White House has approached this issue, the more important issue may be that it is difficult (if not impossible) for the government to effectively manage national security risk.

So, for lack of a better idea, support seems to be coalescing around FARO.

The positive spin was provided by Google’s Kent Walker. During his guest appearance on Lawfare’s Scaling Laws podcast in late July, Walker framed the emerging consensus as “a pragmatic, evidence-based approach” positioned between over-regulation and no regulation.

The way that Walker framed the issue will come up again in Part 2 of this article. One of the questions I have is, what does ‘evidence based’ mean? Evidence of what? For whom?

But that is yet to come; the immediate question is, ‘What does FARO actually propose to do?”

Two Birds, One Stone

Most of the coverage of FARO seems to take the view that it’s looking to regulate (or not) just one thing. But that is, in my view, a shallow reading of what FARO is trying to ‘regulate.’

There are clearly two distinct ‘birds’ in the FARO story, but the organization only targets one of them.

Bird 1: FARO Itself

The FARO concept aims to cover ‘frontier AI models.’ Google helpfully defines these models as those trained on 10² FLOPs or more.

Even a non-technical, non-computer scientist like myself can see that in practice this is a narrow technical threshold indeed; a quick Google search is all you need to understand it. While it’s a handy heuristic, it only captures a fraction of the systems being built by smaller labs.  

(To be fair, I have to point out that governments in the US and EU use it as a benchmark to define high risk frontier models – but this only incentivizes developers to not disclose their exact training figures.)

FARO would set safety standards, conduct pre-deployment audits, and enforce compliance. It would, as many SROs are, self-funding from regulated members. As the old saying goes, no conflict, no interest – SRO’s often only regulate behavior after it’s already baked in to the process.

Importantly, the focus is entirely on catastrophic risk. The FARO framework uses a very specific meaning when it talks about catastrophic risk: any event that could cause mass casualties, or lead to irreversible societal harm. This includes biological and cybersecurity threats, and even weapons development. Clearly, these are things we want to avoid.

But the framework begs a key question: Shouldn’t this be what the Government and the national security apparatus are supposed to do? Shouldn’t there be a legal framework in place to guide an SRO? Even FINRA has a raft of securities legislation to guide its policies and guidelines – it’s the law that gives FINRA its teeth.

Quis custodiet ipsos custodes? Where is the legal foundation that would make FARO truly effective. 

Further, this is clearly not a framework that is designed to handle the second- and third-order disruptions that even ‘ordinary’ AI might bring. For example, will FARO be responsible for helping manage and mitigate future labor markets disruptions, or civil liability claims resulting from AI actions?

Probably not under the current FARO proposals.  

Unless a product – and AI model – explicitly falls under FARO’s narrowly defined jurisdiction, nobody will be watching them. You’re on your own, bud.

Prong 2: Everything Else.

Which brings us to Everybody Else.

Interestingly, Google’s own white paper on FARO explicitly puts “workforce transitions” in this category. This is such a nice euphemism for ‘job losses and labor market dislocation,’ and FARO would simply not be interested or responsible. And the issue of health insurance – so often
tied directly to employment – is not even considered.

It appears that the working assumption of FARO proponents is that current laws, statutes and frameworks are perfectly sufficient to manage the challenges of AI disruption in the future. The problem is, we don’t know what the future looks like and we don’t know how AI at any scale will impact our society. Can we really assume that we don’t need any new legal, regulatory,
or enforcement mechanisms in the future?

What the Design Gets Right

Before saying anything I’ll regret later, it’s probably a good idea to point out what the SRO model seems to get right. 

First, AI capability is developing at light speed; even at the best of times, our legal and federal regulatory architectures are slow to respond. It is almost always reactive, and not anticipatory.

For example, the FDA takes years (sometimes decades) to evaluate and approve new drugs and therapies. OSHA takes an unconscionably long time to write workplace safety standards – which are often completely out of touch with reality by the time they are published.

On the other hand, a frontier AI model can go from idea formulation to global deployment in a matter of mere months. An SRO with real technological expertise and access to serious-minded people who built these systems has a distinct structural advantage over a conventional federal or state agency. There is just no comparison.

Second, the SRO model has not been pulled out of thin air; it has a track record. Yes, it not perfect – it’s mixed at best – but it has been implemented successfully in technically demanding and fast-moving domains.

In the US, the securities industry has FINRA and the NASD; accountants have the AICPA, and lawyers have the ABA. It works outside the US as well: consider the JSDA (Japan Securities Dealers Association) or CIRO (the Canadian Investment Regulatory Organization). There are many more.

Unquestionably, the Thomas/Lawfare design takes the obvious governance objections seriously. For example,

  • Independent governors would outnumber industry governors on the board.
  • Board members would serve staggered terms that extend beyond any single presidential cycle.
  • The supervising federal agency (whoever that might be) retains veto authority over SRO rules.

It’s clear that serious people have been working overtime, especially when thinking about regulatory capture and how to build structural responses to it.

The Problem FARO Isn't Solving

FARO is designed to answer one question: how do you prevent a frontier AI model from causing a catastrophic, civilization threatening event? We can’t pretend this isn’t a real and pressing issue, and the proposed SRO is a plausible response.

But – is it the right question?

US workers are experiencing significant anxiety about AI and the potential for job losses and work displacement. They are also concerned about access to health insurance (often tied to employment), and financial stability.

They don’t seem terribly concerned about the potential for a biological catastrophe caused by a rogue AI. The kind of issue FARO is supposed to prevent – while important – simply isn’t top-of-mind for American workers. The surveys I’ve seen from 2025 and 2026 show they’re worried about a restructuring announcement driven by AI automation or ‘gains’ in efficiency; they are worried that they’ll get a WARN Act notice period that’s too short; they are concerned about losing employer sponsored health coverage at the exact moment they lose their paycheck.

This is the Everything Else that FARO won’t cover.

We cannot simply assume that our existing laws, regulations, and institutions are sufficient for the challenges that AI is going to throw at us. They were written and developed before today’s frontier AI models were even a gleam in their developers’ eye.

Walker says that the framework is ‘pragmatic’ – but pragmatism is really in the eye of the beholder. It depends a lot on what problem you’re trying to solve, and what your objectives are. If the problem you’re solving is the catastrophic AI induced end of civilization as we know it, then yes – FARO is a step in the right direction.

But when your concerns are closer to home – more human – then it’s not good enough because it isn’t focused on the really important parts of the challenge: people.

For FARO, worker anxiety in the US is not moving in a helpful direction. Part 2 will look at the evidence (the data) and what it shows, and why the old approaches of education, familiarity, and technocratic reassurances simply won’t get the result we need.

Sources:

  1. Kent Walker, “A New Framework for AI Regulation” (Google FARO White Paper, June 25, 2026): https://blog.google/company-news/outreach-and-initiatives/public-policy/white-paper-ai-regulation/
  2. “Scaling Laws: Google’s Kent Walker on Regulating Frontier AI,” Lawfare, July 28, 2026: https://www.lawfaremedia.org/article/scaling-laws–google’s-kent-walker-on-regulating-frontier-ai
  3. Mark Thomas, “Designing a FINRA for Frontier AI,” Lawfare, July 30, 2026: https://www.lawfaremedia.org/article/designing-a-finra-for-frontier-ai

Leave a Comment

Your email address will not be published. Required fields are marked *