OpenAI and Anthropic Discussed a Pact to Test Each Other’s Models

The conversation began with a simple proposal: two of the world’s most advanced artificial-intelligence companies would hand each other access to their most capable systems, not to compete, but to hunt for flaws. Earlier this year, OpenAI and Anthropic and their lawyers discussed a legally binding agreement under which each would run a battery of tests on the other’s models to find vulnerabilities or potential dangers, according to a person familiar with the matter.

The talks were reported by The Information, which cited a person with knowledge of the discussions. Under the proposed terms, each company would receive application-programming-interface access to the other’s commercially available models, the systems already released to customers, but not to models that have yet to be made public. Both companies gave assurances that they would not retain the other’s data during the testing, the person said.

The arrangement would mark an unusual detente between two rivals whose relationship has been shaped as much by competition as by a shared argument that frontier AI needs outside scrutiny. OpenAI and Anthropic have competed for customers, researchers and safety talent since Anthropic was founded by former OpenAI employees in 2021, and the two now sit among a small group of companies whose models rank near the top of public benchmarks.

Stress-testing another company’s model is normally the work of independent evaluators or government labs, not of a direct competitor. The appeal of the arrangement, people familiar with the talks said, is that the companies themselves understand best where the weaknesses of such systems tend to hide. A rival that builds similar models has the technical staff, the compute and the institutional knowledge to probe a system in ways a general-purpose auditor might miss.

The proposal drew a boundary around the frontier. API access would cover models that have been commercialized, the systems any developer or enterprise customer can already call through an interface. Models still in training or awaiting release would remain off-limits, a line that preserves each company’s most sensitive work while still exposing the products that reach the public to outside testing.

The data-retention assurance addresses a second concern. In ordinary commercial use, a company sending prompts to another’s API generates logs that the provider could in principle store. Under the proposed pact, the person familiar with the talks said, the companies agreed not to hold on to each other’s data during the tests, a condition aimed at keeping a safety exercise from becoming an intelligence-gathering one.

Whether the discussions will produce a signed agreement remains unclear. The Information described them as discussions rather than a completed deal, and people familiar with such negotiations said the gap between a shared intent and a binding contract can be wide, particularly when the parties are competitors with divergent commercial interests.

The talks arrive as both companies face pressure to demonstrate that their systems are safe at a moment when the technology is moving faster than the rules that govern it. OpenAI and Anthropic have each argued for forms of external testing and oversight, and a mutual pact would give each a concrete way to point to outside scrutiny without waiting for regulators to impose it.

There is also a strategic logic. If the agreement works, each company could tell its enterprise customers that its models have been probed by the people most motivated to find problems, its chief rival. That is the kind of assurance that sells to banks and government agencies weighing whether to deploy frontier models in sensitive settings.

Skeptics inside the industry questioned how much real testing would occur. A stress test run by a competitor is only as rigorous as the competitor’s incentives, they said, and a company that discovers a serious flaw in a rival’s system faces an awkward choice between quiet disclosure and public embarrassment. The proposed data safeguards, while reassuring, do not by themselves resolve the question of what each side does with what it learns.

For now, the discussions signal a degree of mutual recognition that neither company can credibly police itself alone. The models they ship have grown powerful enough that the cost of a hidden flaw is measured in more than market share. A pact between two rivals to test each other’s systems would be, in the eyes of its architects, a small step toward a shared safety floor.

Whether that floor ever gets built depends on lawyers and executives, not on the researchers who first floated the idea. The talks, people familiar with them said, have moved from the labs to the legal teams, where the hard questions, liability for what a test turns up and who sees the results, tend to slow things down.

Related Posts

  • September 24, 2026
  • 9 views
Big Cloud’s AI Bill Tops $4.2 Trillion Through 2029

For years, the largest cloud companies paid for their data centers the way they paid for everything else: out of the cash their businesses threw off. That habit is breaking.…

  • September 24, 2026
  • 10 views
Microsoft Puts $10 Billion Behind Middle East AI

Two years ago, Microsoft paid $1.5 billion for a stake in G42, an Abu Dhabi artificial-intelligence company, and took a seat on its board. This week the software giant said…