Five Ways to Make the New AI Task Force a Success
Self-regulation of the AI industry can be effective. But ensuring safety, security, and public trust will require collaboration with major stakeholders, including the U.S. government.

Vinh X. Nguyen previously served as the National Security Agency’s chief artificial intelligence (AI) officer.
Over the weekend, the White House launched the Super Intelligence Force, a new artificial intelligence (AI) task force to ensure U.S. leadership in the global AI race and protect the American people’s interests. The justification is clear: the United States should lead in identifying new AI security threats and safety risks, especially those posed by adversaries, while resisting overregulation and regulatory capture that would undermine innovation and competition. But success rests on the U.S. government navigating a range of tensions and competing interests to ensure safety and earn public trust while still allowing AI companies to thrive.
The new task force is the U.S. government’s unified effort to operationalize the White House Accord on Super Intelligence, under which U.S. President Donald Trump and the heads of six leading AI companies—Anthropic, Google, Meta, Nvidia, OpenAI, and SpaceXAI—committed to bolstering internal security controls, independent safety evaluations, and board oversight of frontier AI development.
Many have so far overlooked an important Trump concession, namely that AI companies are encouraged to “meet regularly to establish standards and best practices to improve the safety of their systems.” That marked a shift in tone from just a couple of weeks earlier, when Trump suggested he would rein in the AI sector, saying “We’re going to watch it closely through the Department of Justice.” Now, the new AI task force says it will follow Trump’s guidance to let the industry lead on safety and risk management, while also actively assessing adversaries’ misuse of the technology and shaping safety standards to mitigate those risks.
In practice, Trump’s new AI czar, Director of National Intelligence Jay Clayton, will likely give the six AI companies an implicit green light to establish an AI self-regulatory organization (SRO) to coordinate and set safety specifications and incident-response standards. The task force will likely provide voluntary guidance to ensure that SRO developments align with national security and public interests and will assess whether these efforts could harm the U.S. competitive posture vis-à-vis China. It will also assess whether additional executive or legislative backstops are needed to codify the government’s enforcement and oversight powers over the AI SRO. Indeed, as former chair of the Securities and Exchange Commission, Clayton has direct experience with SROs, having overseen the Financial Industry Regulatory Authority—a financial SRO.
But if the White House AI task force and the industry-led SRO proposals move forward, they will need to navigate five potential traps to ensure long-term success: determining who sets safety standards, securing legitimacy in the eyes of the public and allies, responding to national security incidents, ensuring open-weight safety, and competing with China. Only by avoiding these traps can they meet the task force’s goals of preventing frontier AI safety and security surprises, protecting the American public’s interests, and maintaining a durable edge over China.
Whoever sets the safety standards sets the terms of debate. No one will trust the six AI companies if they are left to define what safety means, what to measure, and who judges their own safety specifications. Left to themselves, these companies will likely rely on three narrow safety measures: whether AI can develop itself automatically; how capable its cyber, bioscience, and chemical capabilities are; and how controllable and aligned their systems are. For their part, national security and civil society communities would likely focus on whether these systems can produce classified insights or leak sensitive personal information, respectively.
To ensure the national security community helps prioritize AI safety measures, the AI task force should establish a national security bridge to prioritize what to measure with the SRO, leveraging a national laboratory or a federally funded research and development center with expertise in testing frontier AI capabilities, such as Sandia National Laboratories or Carnegie Mellon University’s Software Engineering Institute. Civil society groups should nominate a technology policy organization to convey what they consider the most egregious harms to society—ranging from child safety to agentic privacy violations—to ensure companies assess the safety problems most relevant to the public interest.
Whatever is built needs to be legitimate in the eyes of the public and U.S. allies. The Financial Industry Regulatory Authority has earned its legitimacy because it has thousands of members and an independent board with public-interest directors who can check for potential capture by a few financial firms. The AI SRO can start with six core AI company members, but it should add another membership category to include frontier AI deployers in the financial and health-care industries, key government and national security AI labs, and technology public-interest groups.
These groups should advise on setting safety and security standards. When their demands and feedback are not adopted, they can voice that publicly or escalate to an AI task force-designated government overseer to ensure clarity and transparency in the standard-setting process. The SRO should also quickly provide a forum for U.S. allies, such as the United Kingdom’s AI Security Institute, to participate and provide feedback.
Establish AI incident-response protocols to build trust and accountability. The AI task force and the SRO can jointly collaborate on notification procedures for major national security or cybersecurity AI incidents, such as the recent OpenAI incidents that compromised tech company Hugging Face and a range of institutions worldwide. Without a standard procedure across AI companies and the national security community to understand and remediate ongoing incidents, the response will be limited and confidence in the industry’s self-regulation will erode. Similar notification thresholds and procedures can be adapted and shared with Beijing to reduce uncertainty as part of the U.S.-China Super Intelligence Dialogue.
Push open-weight models toward established AI safety standards. If the AI task force and SRO aim to shore up safety for closed, proprietary models, it would be a missed opportunity not to address the open-weight model market, which offers little to no assurance of security or safety and is quietly used by U.S. companies. Nvidia and Meta, as vocal supporters of open and secure AI, should invest in the Linux Foundation’s Open Secure AI Alliance and the OASIS Coalition for Secure AI to establish a team that prioritizes widely used open-weight models, regardless of origin, to retrain, refine, secure, and build safeguards that meet the same SRO standards, and to provide them on Hugging Face as a service for AI deployers worldwide. This aligns with U.S. industry’s commitment and commercial interests—a win-win for U.S. companies and international partners to access assured open-weight AI systems.
Create a new, durable safety industry and gain an advantage over China. U.S. companies have repeatedly built enterprise value on open-source software from abroad, including Finland’s Linux operating-system kernel and France’s FFmpeg video-processing library powering online streaming. The industry can also dominate testing, evaluation, certification, and support services for AI capabilities. That was how software company Red Hat built the leading commercial Linux business, and U.S. industry can lead the market for AI safety, security, and assurance services in the same way.
The U.S. government, regulated industries, and critical infrastructure providers should use their procurement power to require AI services to meet the SROs’ safety and security standards. If successful, the United States can leverage momentum in standard-setting through the SRO, working with allies and international organizations, to lead in practices and capture the safety layer for frontier AI capabilities that Chinese AI companies need to match to compete in global markets.
After the 2001 crash that fatally injured racing legend Dale Earnhardt Sr., NASCAR didn’t ask for a halt to racing. Instead, it focused on protecting the driver inside the car and managing energy impact. If the United States establishes a credible SRO to standardize safety and security practices for both closed and open AI models, it can set standards that rivals would have to meet.
Washington insiders typically poke fun at China’s win-win arguments—meaning China wins twice. The United States can finally win twice, too: in advanced capabilities and in safety.
This work represents the views solely of the author(s). The Council on Foreign Relations is an independent, nonpartisan membership organization, think tank, and publisher, and takes no institutional positions on matters of policy.
