Over 100 AI experts and evaluators have signed an open letter urging leading model companies such as OpenAI and Anthropic to provide adequate resources, access, and protections for third-party security assessments. The signatories argue that without independence and transparency, external evaluations struggle to form reliable judgments about the rapidly advancing capabilities and risks of these models.
The open letter outlines five demands.
This open letter is co-signed by members from multiple universities, research institutions, and nonprofit evaluation organizations, including Geoffrey Hinton and researchers from Johns Hopkins University, Stanford University, and the evaluation organization METR.
The letter requires that frontier model companies, when engaging third-party evaluators, meet at least the following basic conditions: evaluators must maintain substantive independence, possess full authority to issue conclusions, and disclose and mitigate potential conflicts of interest; companies should allow multiple evaluators to work from different risk perspectives; evaluation methodologies, access scope, and key findings must be more transparent; evaluators must be protected against retaliation; and evaluators should be granted access close to the company’s high-privilege employees.
- Evaluation agencies must not be held or controlled by model companies.
- Funding should not be withdrawn due to differing evaluation conclusions.
- Main findings and evidence may be made public after limited modifications.
Access rights become the focus of discussion
The discussion has intensified following recent remarks by Anthropic CEO Dario Amodei, who proposed granting certain external evaluators “employee-like” access to inspect state-of-the-art models and their development processes. Supporters argue that this would bring the public closer to understanding the actual risk landscape, particularly regarding internal systems that have not yet been released.
The report mentioned that such access may include using company computers, communicating directly with employees, and viewing sensitive internal data and unreleased systems. OpenAI CEO Sam Altman, SpaceX’s Elon Musk, and Microsoft CEO Satya Nadella have publicly supported this direction, but it remains unclear who will evaluate this access or to what extent they will be able to see.
Signatories request external verification
Vinh Nguyen, a senior fellow at the Council on Foreign Relations and former chief AI officer at the U.S. National Security Agency, who signed the open letter, stated that when only a few labs control capabilities that could impact cybersecurity, critical infrastructure, and national economic systems, the government and the public cannot rely solely on these companies’ self-assessments of “safety.”
The signatories also emphasized that third-party assessments are not meant to replace internal security testing, but rather serve as an external verification mechanism to help identify potential vulnerabilities, incident risks, and governance gaps. The letter also noted that early standardization efforts have already emerged within the industry, but for embedded assessments to be truly effective, more unified implementation conditions are still required.
