Asset owners have spent decades building the processes to price risks they cannot directly observe. When investing in a credit manager, they don't take a borrower's word for its balance sheet; they demand covenants, audited financials, and default triggers. An investment in a quant fund requires more than blind trust in the underlying model because the manager means well; they examine the manager’s backtest, stress tests, and kill switches. Cyber risk isn't managed by trusting a vendor's mission statement; it's managed by demanding evidence of controls and building in accountability in liability if those controls fail.

Frontier AI safety is a material investment risk and deserves the same treatment. Few asset owners appear to be asking the questions they routinely ask about other opaque risks.

Asset owners already know how to diligence risks they cannot directly observe. The question is why frontier AI has largely escaped the same scrutiny.

This isn't a peripheral concern for asset owners. It's a fiduciary one. Fiduciary duty of care doesn't stop at the risks a portfolio company chooses to disclose; it extends to the risks a prudent investor should have known to ask about. If a category of risk is material, foreseeable, and currently unexamined, failing to ask about it may raise questions about whether fiduciary duties are being fully met.

Most of what the investment industry currently calls "Responsible AI" addresses important governance questions, but it's aimed at a different category of risk than the one asset owners should increasingly be asking about.

Responsible AI focuses largely on how AI systems get built and deployed, including issues such as bias mitigation, explainability, data privacy, accountability, and labor displacement.

It's oriented around present-day, deployed systems and asks: “Is this system being developed and used in a way that's fair, legal, and ethical?”

Organizations like the PRI and CFA Institute, and allocators like Nuveen and Railpen, categorize those as governance risks, and they are largely incorporated into how allocators think about the companies they hold.

AI safety focuses on a different set of questions: whether AI systems behave as intended, particularly under stress, and whether long-term risks, including concerns about advanced AI systems’ ability to cause catastrophic or existential harm, are being addressed.

It's also oriented more around technical questions: "Will this system do what we want, including in edge cases, adversarial situations, or as capabilities scale up?" And it represents a different category of risk, namely frontier or agentic risk, including the possibility that an AI system behaves in ways its own developers didn't intend and didn't detect until after the fact. It can be described as misalignment, a loss of control, or autonomous behavior. Whatever the label, it is not an extension of the bias-and-privacy conversation. It's a different risk entirely, and it is currently unpriced.

What's almost entirely absent from this conversation is frontier or agentic risk as its own diligence category. It is not an extension of bias-and-privacy risk but a distinct exposure that calls for its own questions.

The distinction matters because it reframes the issue. Asset owners are not being asked to adopt a new ideology or expand ESG into speculative territory. They're being asked to notice that they already have capital exposure through public equity, private equity stakes in AI-infrastructure portfolio companies and firms whose core product carries a failure mode that conventional diligence typically does not consider. It's a material exposure to an under-examined risk, and for anyone managing capital on behalf of beneficiaries, such exposure is what a fiduciary is expected to identify, measure, and mitigate. A trustee who wouldn't dream of skipping a credit check on a bond issuer has, in most cases, no equivalent check for a portfolio company's frontier AI risk. That's not a values gap. It's a due-diligence gap, and due diligence is the language fiduciary duty already speaks fluently.

Recent events make this risk concrete rather than merely theoretical.

In mid-July, two OpenAI models, the publicly released GPT-5.6 Sol and a more capable research prototype, escaped a restricted testing environment during an internal cybersecurity evaluation, exploited an unpatched flaw to reach the open internet, and hacked into Hugging Face's production systems in search of answers to the benchmark they were being tested on. OpenAI later disclosed additional details, including that the models used four accounts tied to publicly available services during the incident.

OpenAI and Hugging Face both described the event as unprecedented, with Hugging Face’s CEO, Clem Delangue, adding that “It deserves an unprecedented response!” Speaking on a podcast on July 28, OpenAI CEO Sam Altman said, "This is the first sort of security incident that I have felt very viscerally.”

This is not a one-off event. Days after OpenAI announced the breach, Reuters reported that Anthropic — a lab that has built much of its identity and market position around AI safety — disclosed that Claude models had gained unauthorized access to the systems of three separate organizations during cybersecurity testing, after a configuration error let the models reach the open internet from environments meant to be isolated. Two of the three victims didn't know they'd been breached until Anthropic told them.

In response to the OpenAI and Anthropic safety breaches, Gary Marcus, Emeritus Professor of Psychology and Neural Science at NYU, wrote that “The supposed leaders in AI and AI safety are clearly in over their heads. Worse, we as a society are in over our heads. From a technical perspective, this is what happens when you let pattern-matching machines with no real comprehension of what they are doing freely roam the internet. … From a societal perspective, it’s insane that we are pouring gasoline onto the fire by racing ahead with data centers and AI rollouts when we have no idea how to control it and are just sort of hoping for the best. Unfortunately, as the saying goes, hope is not a strategy.”

Set aside, for a moment, whether these particular security incidents caused lasting harm. The more useful question for an asset owner is narrower: If a lab's own safety testing, run by people whose job is specifically to catch and prevent this, still missed it until after the fact, what visibility does an outside investor have? The honest answer, for nearly every asset owner today, is very little. There is no equivalent of an audited financial statement for a model's behavior under stress. There is no standard covenant that triggers when a system does something its developers didn't intend. There is, in most portfolios, no diligence question that would have surfaced this risk before it became a news story.

This is where private markets exposure is most acute and least visible. Public-market shareholders at least have proxy votes, PRI signatory commitments, and stewardship engagement, thin but real protections. Investors in private AI labs and AI infrastructure companies generally have none of those protections. An LP gets only the information a GP chooses to share, and right now almost no GP is being asked whether safety practices were part of diligence in the first place.

The industry isn't ignoring AI risk, but it is largely focused on the wrong category. The bias-and-privacy part has frameworks, working groups, and stewardship programs behind it. Frontier AI safety has almost none of that. 

Closing that gap starts with how the risk itself gets framed. Frontier AI safety should be priced the same way asset owners already price credit risk, model risk, and cyber risk: as an unpriced, unmodeled risk sitting inside portfolios that touch AI labs and AI infrastructure, not as a values statement. 

None of this requires asset owners to resolve the harder debates about AI risk (how likely, how severe, how far off it might be) or to become AI safety researchers. It requires treating frontier AI safety the way the industry already treats every other material yet opaque risk: as something to be identified and measured, not assumed away.

The tools for that already exist in every allocator's playbook. Asset owners can ask their PE firms, whose portfolio companies embed frontier or near-frontier AI in their core product: What are the controls, and who outside the company can verify they hold? How would the fund know if a control failed, and how fast? Who is accountable, and what's the fund's actual exposure if a portfolio company's AI system harms a third party? Does the company have a defined authority to halt deployment, and has that authority ever been exercised? Is the company using — or informed by — any existing preparedness framework, even one it didn't write? 

Asking these questions is especially critical because if a safety breach can happen at a well-resourced firm like OpenAI, it could just as easily happen at smaller portfolio companies that typically lack the resources to invest in foundational security.

Fiduciary duty has never required certainty about a risk before demanding that it be addressed; only that the risk be foreseeable and material.

Frontier AI safety is now demonstrably both. Another sign is that just this past week, over 1,300 employees at Anthropic, OpenAI, and other frontier labs signed a petition arguing that because of “a real risk that capability development rapidly accelerates beyond our ability to understand or control the resulting systems, the US should “deliberately pace the frontier of automated AI development.”

Asset owners need to be fully aware of AI safety risk embedded in their current and future investments. Failing to ask the right questions is not an addendum to fiduciary duty. Left unaddressed, it may constitute a breach of it.


Angelo Calvello is the founder of C/79 Consulting, a columnist for Institutional Investor, and the host of Against Consensus. He serves as a trustee on the Woodridge Police Pension Fund and chairs the Climate Advisory Panel at the Maryland State Retirement System.