← View All News & Insights
Thought Leadership

Five of Six Said Yes

Five Out of Six : VantageRoad

The AI Review Story Is a Test Every Leader Should Be Watching 

Federal officials are pressing Meta to submit its AI models for voluntary government safety reviews. Five of the six largest U.S. AI developers have already agreed. Meta has not. That is the surface of the story the New York Times reported this week. The deeper story is the one most coverage will miss. 

Buried in the reporting is a striking admission: it is unclear who will lead the reviews, what standards the models will be measured against, and who would sign off if a model were paused and later restored. That is not an AI problem. That is an operating-model problem, the same one I have watched play out in utilities, healthcare, banking, and energy. 

What is being decided here is not just whether Meta’s models get reviewed. It is whether the United States can build a credible oversight system at the same speed it is building the technology underneath it. 

What the story actually says 

Under a June 2, 2026 executive order, the Commerce Department’s Center for AI Standards and Innovation (CAISI) was given a voluntary 30-day window to evaluate frontier AI models before public release. OpenAI, Anthropic, Google, Microsoft, and xAI agreed to participate. Meta, the company behind the open-source Llama model family, has not yet signed on, and the administration has been pressing it through direct outreach (NYTReutersWhite House). 

The backdrop matters. Earlier this month, Anthropic’s Fable 5 and Mythos 5 models were taken offline after Amazon researchers reported that specific prompts could coax Fable 5 into producing output relevant to cyberattacks. Amazon’s CEO raised the findings with the White House and the Treasury Secretary. Commerce issued export controls limiting foreign access. To comply, Anthropic suspended access for all users worldwide, though the company publicly disputed the characterization of the issue and noted that similar capabilities exist in other publicly available models (WSJFortuneThe Verge). 

Soon after, roughly 100 cybersecurity professionals signed an open letter warning that the shutdown took a powerful defensive tool out of the hands of corporate and government security teams, while attackers can still use other AI models, including open-source ones to do the same thing (TechCrunch). 

That entire sequence from a single corporate research finding to a worldwide model suspension played out in a matter of weeks, without a public standard, a published methodology, or a clear path back. Both sides, the developers and the reviewers, are being asked to operate without a settled framework. It shows. 

The story underneath the story 

Most coverage will frame this as a fight over who controls AI. The question is whether the governance model on the company side and the government side is mature enough to support the speed of change. Right now, on both sides, the honest answer is not yet. 

This is not a partisan point. It applies regardless of which administration is in office, which company is the holdout, and which model is in the headlines. AI is simply the most visible example of a pattern I have seen in every serious transformation I have run or advised on. 

The capability moves faster than the management system that is supposed to govern it. 

Most organizations move quickly from experimentation to deployment. The technology improves, investment grows, and new use cases emerge. What often fails to mature at the same pace is the operating model around it. When difficult questions arise, the conversation is no longer about the algorithm. It is about governance: who made the decision, what judgment was applied, what principles guided it, and who has the authority to change course. 

A pattern I have seen before 

Utilities went through this with grid modernization. Banks went through it with model risk management. Health systems went through it with electronic health records. In each case, the technology was real, the business case was real, and the early governance was thin. 

What separated the organizations that scaled cleanly from the ones that ended up in front of regulators was not the quality of the technology. It was the quality of the management system around it. Clear ownership. Documented standards. Predictable escalation. A way to pause, modify, or stop without breaking the business. 

Frontier AI is being held to the same test in real time. 

Modular governance: the missing design pattern 

As I work through the IAPP AIGP material, one idea keeps proving useful in front of executives: modular governance. 

The concept is simple. Shared global principles at the top. Jurisdiction and use-case-specific implementation underneath. One integrated framework that maps AI rules, sector rules, and internal standards into a single operating picture. Regional or functional leads watch for changes and adjust without fragmenting the whole. 

That framing matters because there is no single control point for AI, and there never will be. Pretending otherwise is what produces improvised reviews, inconsistent decisions, and reactive compliance. 

For executives, modular governance shows up in five practical places: 

  1. One map, not a stack of policies.Every applicable rule is integrated into one framework, owned by a named executive, refreshed on a predictable cadence. 
  2. Decision rights by risk tier.Each use case is classified by customer, employee, regulatory, operational, and reputational exposure, with a documented approval path and a named accountable executive. No use case scales without an owner. 
  3. Governance across the full lifecycle.Development, deployment, monitoring, and retirement each have their own controls, review cadences, and escalation triggers. Approval at launch is not the finish line. 
  4. Standards written in plain English.Acceptable error rates, out-of-scope topics, mandatory human review written down, tied to launch decisions. 
  5. One consistent way to engage outside reviewers.Regulators, auditors, government evaluators, community stakeholders handled through a known process. 

That last one is where the Meta and Anthropic stories converge. When the review model itself is improvised, every interaction becomes a one-off negotiation expensive for the company, unpredictable for the regulator, and unsettling for the customer. 

This is bigger than AI, and bigger than Meta 

The lesson is not really about frontier models. It is about every large transformation: M&A integrations, ERP rollouts, cloud migrations, regulatory remediations, operating-model redesigns. Each of them eventually reaches the same point. The organization has to demonstrate that its ambition, its controls, its decision rights, and its risk model are mature enough to support the speed of change. 

Transformation without governance becomes unmanaged risk. Governance without transformation becomes bureaucracy. 

The companies that will lead the next decade will not be the will be the ones that design speed and oversight together. 

The question every executive should be ready to answer 

If a board member, a regulator, a customer, or a reporter asked tomorrow who decided, against what standard, who owned the risk, and who has the authority to decide differently, could your organization answer in plain English, without preparation, without a deck, and without a press release? 

If the answer is not yet, that is not a failure. It is the work. 

In transformation, governance is not the enemy of speed. Good governance is what allows speed to be trusted. 

The Meta question, the Anthropic question, and every transformation question your team is wrestling with this quarter come back to the same test. Can the organization explain the decision under pressure? If it can, speed is an asset. If it cannot, speed is a liability waiting to be discovered.