AI safety and assurance
As Children Return to School, AI Is Asking a Question We Still Haven’t Answered
Bill Gates’s latest warning points to a problem larger than AI safety itself: who should society trust to determine when an AI system is safe enough?

Analysis
This morning, millions of children across the United States are returning to classrooms.
Parents are thinking about teachers, backpacks, lunches, buses, schedules, and whether everyone remembered everything before walking out the door.
But increasingly, another question sits quietly behind the beginning of a modern school year.
What role should artificial intelligence play in the lives, learning, and development of children, and who is responsible for establishing that the systems entering those environments are actually safe?
That question became more difficult to ignore last week.
Bill Gates and a change in tone
On August 26, Bill Gates, one of technology’s most recognizable optimists, published a sweeping warning about the risks accompanying increasingly capable artificial intelligence.
For years, Gates has emphasized AI’s potential to improve medicine, education, productivity, scientific discovery, and quality of life.
He still believes those benefits are real.
What has changed is his confidence that the institutions surrounding the technology are prepared for what comes with them.
Gates identified three areas of particular concern: disruption to employment, AI-enabled security threats including cyberattacks and biological misuse, and risks to children’s well-being, including the possibility that AI could interfere with learning or human relationships.
He has also said that, for the first time in his life, he finds himself wishing a major technology would advance more slowly.
That change in perspective is noteworthy precisely because Gates is not arguing against technological progress.
He is arguing that capability and institutional preparedness are moving at different speeds.
And that raises a question larger than whether artificial intelligence is dangerous.
Who gets to decide when it is safe enough?
Why children make the problem impossible to ignore
AI is already becoming part of education.
It can tutor students, translate material, personalize lessons, provide accessibility tools, assist teachers, and help children explore subjects in ways that would have been difficult to imagine only a few years ago.
Those possibilities should not be dismissed simply because the technology carries risk.
But children also expose one of the central weaknesses in the way AI assurance currently works.
A child cannot meaningfully evaluate a model’s cybersecurity controls.
A parent cannot independently reproduce sophisticated safety testing.
A teacher cannot inspect every training methodology, benchmark, model behavior, or failure mode behind every AI-enabled product entering a classroom.
A school district cannot realistically recreate the work of an advanced model-evaluation laboratory every time it considers adopting a new technology.
Somewhere upstream, somebody has to make a determination about risk.
Eventually, everyone else has to decide whether to trust it.
That is where the problem changes from one of AI safety to one of AI assurance.
Self-evaluation has limits even when everyone acts in good faith
AI developers should test their systems.
They should employ safety teams, conduct red-team exercises, publish evaluations, investigate incidents, and continuously improve safeguards as capabilities evolve.
None of that is controversial.
But internal evaluation and independent assurance perform fundamentally different functions.
A company developing a technology has extraordinary knowledge about that technology.
It also has extraordinary exposure to the outcome of an evaluation.
Capital, product timelines, market position, reputation, investor expectations, and commercial success may all depend on deployment.
That does not mean the company is dishonest.
It means the conflict exists structurally.
We do not require independent financial audits because every corporation is assumed to be fraudulent.
We require them because information becomes more credible when the party evaluating it is structurally separate from the party whose interests are affected by the conclusion.
AI is increasingly confronting the same problem.
The more consequential these systems become, the less reasonable it is to treat a developer’s own assessment as the final layer of assurance.
Capability is moving faster than the institutions around it
Gates’s warning arrives during a period in which the gap between AI capability and institutional readiness has become increasingly visible.
Recent disclosures from leading AI laboratories and government evaluators have documented systems behaving in ways their evaluators did not fully anticipate, including autonomous cyber activity, attempts to manipulate real-world participants, and models finding ways around intended evaluation constraints.
These incidents do not prove that advanced AI systems are inherently uncontrollable.
They demonstrate something more practical. Evaluation itself is becoming harder.
At the same time, governments are beginning to build infrastructure around independent examination.
Europe is expanding its capacity to evaluate increasingly capable AI models as the EU AI Act moves deeper into enforcement.
Illinois has enacted annual independent third-party audit requirements for qualifying frontier AI developers beginning in 2028.
Massachusetts, California, New York, and other jurisdictions are considering different forms of evaluation, transparency, oversight, and independent assurance.
The approaches differ.
The direction is increasingly familiar.
The conversation is moving from:
What rules should AI developers follow?
to:
What evidence demonstrates that they actually followed them?
And from there another question follows.
Who is sufficiently qualified and sufficiently independent to evaluate that evidence?
Safe AI has to mean more than a promise
The phrase safe AI is becoming ubiquitous.
Developers want safer systems.
Governments want safe innovation.
Companies want safe AI inside their operations.
Parents want safe technology around their children.
But the word safe becomes less meaningful when it describes an aspiration rather than a condition capable of being tested.
No complex technology is perfectly safe.
That cannot reasonably be the standard.
The meaningful question is whether risks have been identified, evaluated, documented, mitigated, and subjected to scrutiny proportionate to the consequences of failure.
That scrutiny becomes especially important when the people affected by the technology are unable to meaningfully evaluate it themselves.
Children make that particularly clear.
If an AI system affects a child’s learning, development, privacy, safety, or relationships with other people, saying that the developer tested it cannot be the end of the conversation.
The evidence matters.
The methodology matters.
The evaluator matters.
And independence matters.
Regulation cannot inspect everything
Government has an essential role in AI governance.
Gates has argued that the AI industry cannot regulate itself and has called for stronger national and international institutions capable of addressing AI-related security, employment, education, and societal risks.
That addresses one part of the institutional problem.
But effective government oversight cannot realistically mean a regulator personally evaluating every AI system deployed across every business, hospital, financial institution, school, and software platform.
That is not how mature assurance ecosystems generally operate.
Regulation establishes obligations.
Standards establish expectations.
Organizations implement controls.
Independent evaluators examine whether those controls and claims withstand scrutiny.
Regulators then have evidence they can review and enforcement powers they can use when necessary.
That middle layer matters. Without it, governance risks becoming a choice between trusting the organization making the claim and expecting government to independently recreate every technical evaluation itself.
Neither scales particularly well.
This is ultimately a question of trust infrastructure
Bill Gates’s warning matters because it comes from someone who remains convinced that artificial intelligence can produce extraordinary benefits.
That makes the argument more interesting, not less.
AI does not have to be viewed as an existential threat for stronger assurance mechanisms to make sense.
We do not have to choose between technological optimism and technological caution.
We can believe that AI will improve medicine, education, accessibility, science, and economic productivity while simultaneously recognizing that systems with increasing capability and autonomy require stronger mechanisms of accountability.
Those positions should reinforce one another.
The more deeply we integrate AI into society, the more important reliable evidence becomes.
And as millions of children return to classrooms this morning, they provide an unusually clear reminder of what is at stake.
The people affected by artificial intelligence will not always be capable of evaluating the systems themselves.
They will depend on institutions to do that work for them.
So perhaps the defining AI safety question is no longer simply:
Can this system be trusted?
It is increasingly:
Who independently established that it should be?
Because safe AI will ultimately require more than good intentions, internal testing, or corporate assurances.
It will require evidence.
And it will require institutions society can trust to evaluate that evidence independently.
This morning, I will be thinking about backpacks, buses, lunches, and whether we remembered everything before walking out the door.
Then I will go back to work building one of the institutions I believe this transition will require.
Not because AI should be feared.
Because technology this consequential deserves evidence worthy of the trust we are placing in it.