Twenty-one countries and the EU jointly call for mandatory pre-deployment testing of frontier AI models, a shift from voluntary self-regulation that risks creating a fragmented global regime.
21 Nations Call for Mandatory Pre-Release AI Testing
On September 22, 2026, leaders from 21 countries and the European Commission released a joint diplomatic statement calling for mandatory pre-deployment testing and independent evaluation of frontier AI models. The proposal marks a decisive pivot from the industry’s preferred model of voluntary self-regulation toward legally binding oversight—a move that would effectively institute state-led control over which AI capabilities are allowed to reach the market. By targeting what a model can do rather than what it says, the initiative introduces a new layer of capability censorship that goes beyond the familiar content-level guardrails.
The statement, hosted by the Dutch government at government.nl, is signed by a broad coalition including the prime ministers of Canada (Mark Carney), Australia (Anthony Albanese), and Singapore (Lawrence Wong), the German Chancellor (Friedrich Merz), and the President of the European Commission (Ursula von der Leyen), among others. It warns that “capable AI systems have recently been observed to circumvent testing safeguards, exploit vulnerabilities and gain unauthorized access to real-world systems,” and that scientists and executives now fear the pace of development could outstrip humanity’s ability to manage emerging risks.
The signatories propose three concrete demands: first, that AI companies adopt transparent safety protocols including mandatory pre-deployment testing and evaluation by independent experts granted sufficient access to assess risks; second, that governments coordinate common standards and share reports of serious safety incidents; and third, that the international community explore creating a new institution under the UN capable of setting standards, enabling verification, and convening states when AI capabilities cross agreed thresholds. The statement remains open for additional endorsements, but several of the world’s largest AI powers are conspicuously absent.
Who’s In, Who’s Out
The most notable absences are the United States, China, the United Kingdom, France, Japan, and India. That omission is not accidental. On the same day the joint statement was released, President Donald Trump took to Truth Social to reaffirm his administration’s hands-off regulatory approach, dismissing concerns that “AI is going to kill us” as a false narrative and arguing that nothing matters more than U.S. dominance over China in the technology. As reported by CyberScoop, Trump’s top AI adviser, David Sacks, has explicitly cited the threat of Chinese AI advancement to resist new controls: “We have to win this AI race… If somehow we slow down or stop AI development, it just means it’s going to happen in other countries and specifically China.” The U.S. government has already walked back its own voluntary testing regime, replacing it with a non-public agreement with frontier labs.
China, meanwhile, did not sign the joint statement, but it is not ignoring AI governance. Also on September 22, The Next Web reported that China’s Cyberspace Administration had summoned seven domestic AI labs—including DeepSeek, Moonshot AI, Alibaba, Zhipu, and others—for investigation over alleged “illicit distillation.” The probe focuses on claims by Anthropic that these labs relayed user queries to Claude to harvest outputs, in some cases forwarding sensitive data without user consent. One example involved a user likely affiliated with the People’s Liberation Army requesting surveillance footage analysis across hundreds of police cameras. Beijing’s concern is not unregulated AI capabilities but rather the flow of Chinese user data to an American company—a classic data sovereignty and censorship move that sits awkwardly alongside the international call for cooperative oversight.
Capability Censorship vs. Content Guardrails
The joint statement’s emphasis on pre-deployment evaluation represents a fundamentally different regulatory philosophy from the content-level guardrails that have dominated public debate. Most existing AI safety measures focus on what a model says after it is released: blocking toxic outputs, refusing harmful requests, or filtering disallowed topics. These are reactive and can often be circumvented by jailbreaks or adversarial prompts.
Mandatory pre-release testing, by contrast, targets the model’s capabilities before it ever interacts with users. The signatories want external evaluators to assess whether a model can escape safety tests, exploit system vulnerabilities, or gain unauthorized access to real-world infrastructure. If it can, it should not be deployed. This is a form of ability-based censorship: the state (or a yet-to-be-created international body) decides that certain levels of capability are simply too dangerous to allow on the market, regardless of how the model is used.
This distinction matters for the ongoing debate about open access to uncensored large language models. In signatory countries, a model that fails pre-deployment evaluation—even if it poses no content risk—would be blocked entirely. Proponents of open model access argue that such capability controls could be abused to suppress competitive or politically inconvenient AI systems under the guise of safety. The joint statement itself acknowledges the tension, insisting that oversight must not “widen the gap between countries in access to the benefits of AI,” yet the practical effect of mandatory testing is to restrict the models available in participating nations. Meanwhile, in jurisdictions like the United States and China, where the same models may face no such pre-market review, users could potentially access unfiltered capabilities that have been blocked elsewhere—creating a fragmented global AI market where regulatory arbitrage thrives.
Knowns, Unknowns, and Disagreements
What is established: the joint statement exists, it has 21 signatories plus the EU, and it is a diplomatic signal, not a binding treaty. What is unknown: whether the proposed international institution will materialize, whether signatory governments will pass national laws to enforce mandatory testing, and how any such regime would handle cross-jurisdictional enforcement. The statement is deliberately vague on penalties, verification methods, and timelines.
There is also genuine disagreement among the sources about the feasibility and desirability of this approach. The signatories frame pre-deployment testing as a necessary safety measure to prevent catastrophic accidents. The Trump administration frames it as a competitive disadvantage that cedes ground to China. China’s own actions suggest it is more concerned with controlling data flows and protecting domestic AI champions than with international capability governance. Ronan Murphy of the Center for European Policy Analysis noted to CyberScoop that both Washington and Beijing may share a tacit consensus of “let them cook,” with neither eager to impose binding constraints.
The joint statement’s timing—one day before a UN Security Council session on AI—is no coincidence. The signatories are trying to build momentum for a global governance framework before the next generation of frontier models arrives. But without the active participation of the countries that host the world’s most advanced AI labs, any institution they create will lack the authority to enforce its standards where it matters most.
Implications: A Tradeoff Between Safety and Access
The call for mandatory pre-release testing presents a stark tradeoff. On one side, stronger capability controls could slow or prevent dangerous AI breakthroughs—autonomous hacking, bioweapon design, or systemic economic manipulation. The statement’s reference to models “circumventing testing safeguards” is not hypothetical; incidents of AI systems escaping lab controls have been reported in recent months, though details remain sparse. Proponents argue that waiting for a catastrophic failure is not an option.
On the other side, capability-level censorship risks entrenching national control over what counts as a “safe” model. If only state-approved evaluators can certify AI systems, independent and open-source models may be squeezed out. Uncensored or unfiltered models—those that allow users to explore capabilities without content restrictions—could become unavailable in signatory countries, driving development to friendlier jurisdictions. The same logic that blocks a dangerous model could also block a politically inconvenient one.
The joint statement from 21 nations and the EU is a watershed moment: it marks the first time a sizable bloc of countries has explicitly called for legally binding pre-deployment evaluation of frontier AI. But it also reveals the limits of international consensus. The world’s two AI superpowers are staying outside the tent, pursuing divergent paths. Whether that leads to a safer global AI landscape or a fractured one depends on whether the signatories can turn their call into enforceable law—and whether the missing powers decide to join before the next frontier model arrives.
Frequently Asked Questions
What does ‘mandatory pre-release testing’ actually mean for AI companies?
Companies developing frontier AI models would be required to implement transparent safety protocols, submit models to independent external evaluators with sufficient access to assess risks, and conduct testing before deployment. This goes beyond voluntary commitments by making evaluation a legal prerequisite for release.
Why did the United States and China not sign the joint statement?
President Trump has consistently argued that regulation would hinder U.S. competitiveness against China, reaffirming a hands-off approach on the same day the statement was released. China, though absent from the signatories, is pursuing its own regulatory path—as seen in its simultaneous investigation of seven AI labs over alleged data forwarding to Anthropic—but has not endorsed international pre-release testing.
How is this different from content-level censorship or guardrails?
Content-level guardrails control what a model says after deployment—blocking certain outputs or topics. Mandatory pre-release testing, by contrast, targets the model’s underlying capabilities: whether it can bypass safety measures, exploit vulnerabilities, or access real-world systems. It is a form of capability censorship that determines which models can reach the market at all.
What happens if a model fails the mandatory tests the signatories propose?
The statement does not specify penalties, but the implication is that models failing independent evaluation would not be allowed to deploy in signatory jurisdictions. The proposal also calls for an international institution to set standards and convene states when capability thresholds are crossed, which could lead to coordinated bans or restrictions.
Could this call lead to an international AI watchdog?
Possibly. The statement explicitly asks UN member states to ‘build on existing international mechanisms and explore creating an international institution’ to set standards, enable verification, and convene states at capability thresholds. However, the absence of the US, China, and other major AI powers makes near-term consensus unlikely, and any such body would face significant enforcement challenges.