Building standards for the next phase of AI
Published September 21, 2026 · Printed at the top of the article header, above the "Global Affairs" category label and the title; the openai.com Global Affairs newsroom lists the same post as "Sep 21, 2026". The page footer repeats only the year, "2026", beside the author credit.
Not law. This is a company's own public position on AI regulation. It is not law, and it carries no legal force.
What it argues for
This is OpenAI's case for international technical standards as the main lever for governing automated AI research and recursive self-improvement (RSI), published under Global Affairs and credited simply to "OpenAI". It opens from the premise that "Fully autonomous RSI is not happening today, and we should not pursue it unless and until it can be done safely", and argues that "International standards for safety and security practices in frontier AI development may be as important to pacing the frontier as alignment research itself" — standards being the way to answer "What does good look like in the mitigation of catastrophic AI risk?" It names three problems that national action alone cannot solve (fragmentation of evaluations and incident definitions, collective action, and uneven capacity) and concludes that "the United States should lead an effort to work together with countries around the world to develop global technical standards for frontier AI, including for RSI." The proposed vehicle is the existing network of AI safety institutes, working through CAISI and national industry bodies and building on CAISI's International Network for Advanced AI Measurement, Evaluation, and Science, with ISO, the Frontier Model Forum and others as partners. The standards would cover capability measurement, risk assessment and safeguard sufficiency, and specifically the evaluation of RSI-relevant progress, human oversight of automated AI research, and common incident severity levels and reporting thresholds. Two limits are drawn with care: "These technical standards would not be licenses, mandatory prerelease review, or approval requirements for AI models", and "National governments would decide whether and how to incorporate these standards into their own legal systems." The stated rationale is "rooted in avoiding the concentration of power," and the post also welcomes US–China dialogue: "Dialogue between the United States and China in these areas would be a positive step".
Stated positions (13)
- Fully autonomous recursive self-improvement should not be pursued yet: "Fully autonomous RSI is not happening today, and we should not pursue it unless and until it can be done safely", and whether to proceed "must depend on our ability to preserve human control and on informed democratic choices".
- Standards are treated as a pacing tool on a par with alignment research: "International standards for safety and security practices in frontier AI development may be as important to pacing the frontier as alignment research itself."
- The United States should lead the effort: "the United States should lead an effort to work together with countries around the world to develop global technical standards for frontier AI, including for RSI."
- The mechanism should be the existing network of AI safety institutes — naming those in Australia, Canada, Germany, France, Kenya, Japan, Korea, Singapore, India and the United Kingdom — working "through the CAISI and national industry bodies", focused on frontier models and developers "as measured by capability benchmarks" and on benefit-risk management for automated AI research, including RSI.
- Standards are not to become a licensing regime: "These technical standards would not be licenses, mandatory prerelease review, or approval requirements for AI models. National governments would decide whether and how to incorporate these standards into their own legal systems."
- Standards must be competitively neutral: they "should be developed transparently and designed so that they do not advantage particular companies, countries, or business models, including by making it harder for new entrants or open-weight developers to compete." The post states that "These challenges apply to both open and closed models."
- Proposed standards areas for autonomy and RSI: "Evaluation of RSI-relevant AI progress and the amount of autonomous research happening within an AI company"; "Human oversight over automated AI research, including what kinds of automated AI research processes should trigger immediate human review"; and incident handling "such as common incident severity levels and reporting thresholds."
- Offers OpenAI's own work as starting points: its recent report on research acceleration is "an initial contribution" to measuring RSI progress, and its misalignment reporting framework "is an early contribution" to incident standards.
- Calls for secure government and critical-infrastructure channels: critical infrastructure operators and governments worldwide should "establish secure channels of communication to share national security concerns, emerging vulnerabilities and threats, and best practices", and "Dialogue between the United States and China in these areas would be a positive step".
- Labs remain individually accountable regardless of standards: "any AI lab that pursues automated AI research or other advanced capabilities must take accountability for doing so safely, in accordance with basic principles of self-responsibility and existing laws."
- Standards are framed as an anti-concentration measure: "Our rationale for standards is rooted in avoiding the concentration of power, and producing better practical outcomes", giving "more stakeholders outside of the labs" a say.
- Models the approach on aviation and financial stability, "where countries have developed common technical standards and trusted channels for cooperation without giving up national authority", and wants it to work with ISO, the Frontier Model Forum, the Agentic AI Foundation and the Open Secure AI Alliance.
- Argues US leadership is strategic, not only safety-driven: "Leading now will determine whether the United States shapes the global AI framework or watches a fragmented, uneven, and conflict-ridden system take hold around it."
About this document
A web article on openai.com, filed under "Global Affairs" and dated September 21, 2026, of roughly 1,670 words. It carries no individual byline: the footer credits the author as "OpenAI". It has no footnotes and cites no statute. It opens with a short, unheaded restatement of OpenAI's mission and three goals ("As outlined recently by Sam Altman and Jakub Pachocki"), then runs through three headed sections carried in a jump menu: "RSI", "International standards" (with two numbered sub-headings, "(1) A mechanism that facilitates complementary national and international frontier standards" and "(2) Common measurements and incident reporting protocols for better collective action") and "The United States should lead". It names outside bodies it wants involved — CAISI and its International Network for Advanced AI Measurement, Evaluation, and Science, ten national AI safety institutes, ISO, the Frontier Model Forum, the Agentic AI Foundation, the Open Secure AI Alliance and the Appia Foundation — and points to OpenAI's own material: the Hugging Face Incident it disclosed, its report on research acceleration and its misalignment reporting framework. It asks nothing of any specific legislature and names no bill. It closes: "Strong national governance, connected through practical international cooperation, offers a path to stronger safeguards, continued innovation, and broad access to the benefits of AI."
How this sits against AI law
Each stance compared with what EU and US instruments actually require. Where no instrument addresses a theme, that gap is shown rather than hidden.
Internationally agreed technical standards for frontier AI, led by the United States
The United States should lead a coalition of countries, working through the network of AI safety institutes, CAISI and national industry bodies, to develop global technical standards for capability measurement and evaluation, risk assessment and safeguard sufficiency, including for recursive self-improvement.
The Act relies on standards to make its duties concrete: Article 40 gives a presumption of conformity to systems that follow harmonised standards, and Articles 55(2) and 56 let a provider of a systemic-risk model show compliance through an approved code of practice until a harmonised standard is published.
The White House's March 2026 legislative recommendations to Congress back "industry-led standards" and say Congress "should not create any new federal rulemaking body to regulate AI", but they are a domestic document that says nothing about building frontier standards jointly with other countries, which is the core of OpenAI's proposal.
Standards must not become licensing or mandatory pre-release review
The proposed technical standards "would not be licenses, mandatory prerelease review, or approval requirements for AI models"; each national government would decide whether and how to write them into its own law.
For general-purpose AI models, even those with systemic risk, the Act sets no licence and no prior approval: Articles 53 and 55 attach documentation, evaluation, incident and cybersecurity duties to the provider, and the Commission's powers under Articles 92 and 93 to evaluate a model or require measures operate after it is on the market.
Executive Order 14409 states that nothing in its frontier-model section "shall be construed to authorize the creation of a mandatory governmental licensing, preclearance, or permitting requirement for the development, publication, release, or distribution of new AI models, including frontier models", and makes its pre-release access scheme for covered frontier models voluntary.
Common incident severity levels and reporting thresholds
International standards should cover incident classification, tracking, reporting and response for alignment and automated-AI-research issues, with common incident severity levels and reporting thresholds, so that national incident definitions do not conflict.
Article 55(1)(c) obliges providers of systemic-risk models to track, document and report serious incidents and possible corrective measures to the AI Office "without undue delay", and Article 3(49) supplies a single EU-wide definition of a serious incident.
SB 53 requires frontier developers to report critical safety incidents to California's Office of Emergency Services within 15 days, or within 24 hours where there is an imminent risk of death or serious physical injury — a working incident definition and threshold, though only for one state, which is the fragmentation OpenAI wants standards to resolve.
Human oversight of automated AI research
Standards should define human oversight over automated AI research, "including what kinds of automated AI research processes should trigger immediate human review", because RSI done without care could leave humans "unable to provide oversight on research processes they no longer understand".
Article 14's human-oversight duty is written for high-risk AI systems in use, and the general-purpose model chapter contains no rule on human review of a developer's own automated research inside the lab.
SB 53 has large frontier developers send the state summaries of their assessments of catastrophic risk from internal use of their models, and counts a model's deceptive subversion of developer controls as a critical safety incident, but it sets no trigger at which automated research must stop for human review.
Measuring progress toward recursive self-improvement
Standards should cover the evaluation of RSI-relevant AI progress and "the amount of autonomous research happening within an AI company", with OpenAI's own report on research acceleration offered as an initial contribution.
Article 55(1)(a) and (b) require evaluation and mitigation of systemic risks from the model, and Article 51 measures capability by training compute and benchmarks, but nothing in the Act asks a provider to measure or report how much of its own research is being done autonomously by AI.
No US federal or state instrument in the corpus defines or requires measurement of recursive self-improvement or of autonomous research inside a developer.
Competitive neutrality: standards must not disadvantage open-weight developers or new entrants
Common standards should be developed transparently and must not advantage particular companies, countries or business models, including by making it harder for new entrants or open-weight developers to compete; the risks apply to both open and closed models.
Article 53(2) relieves free and open-source models of the technical-documentation duties but states that the exception "shall not apply to general-purpose AI models with systemic risks", so the Act, like OpenAI, draws its line on capability rather than on whether weights are released.
The Action Plan has a dedicated section, "Encourage Open-Source and Open-Weight AI", treating the release decision as "fundamentally up to the developer" and directing work to drive adoption of open models by small and medium-sized businesses.
Secure channels between governments and critical-infrastructure operators, including US–China dialogue
Critical infrastructure operators and governments worldwide should establish secure channels to share national security concerns, emerging vulnerabilities and threats, and best practices in frontier AI safety, and US–China dialogue in these areas would be a positive step.
The AI Act sets up EU-internal cooperation (the AI Office, the AI Board and national authorities) but creates no channel for sharing AI security threats with third countries or with critical-infrastructure operators abroad.
Executive Order 14409 directs the Treasury, with the NSA and CISA, to form "an AI cybersecurity clearinghouse, in voluntary collaboration with the AI industry and operators of critical infrastructure" to find and patch vulnerabilities — a domestic channel only, with nothing on sharing threats with other governments, least of all China.
The EU has already built what this post asks for in outline, but made it law rather than leaving it to national choice: the AI Act places duties on general-purpose models with systemic risk and relies on harmonised standards and codes of practice to show how to meet them, so standards there are how a legal duty is met, not an option a government may take up. OpenAI's version is looser — technical standards set internationally through safety institutes, which "would not be licenses, mandatory prerelease review, or approval requirements" — and it reaches further than the Act on content, into measuring autonomous research inside a company and setting human-review triggers for automated AI research, which no EU provision touches. In the US the fit is closer in form: Executive Order 14409 explicitly rules out "a mandatory governmental licensing, preclearance, or permitting requirement" and builds a voluntary pre-release framework for covered frontier models, which matches OpenAI's no-licensing line, and the White House's March 2026 legislative recommendations favour "industry-led standards" over any new federal rulemaking body. What US federal policy lacks is the international, multilateral half of the proposal and anything addressing RSI; the only binding US frontier rules OpenAI can point to for incident reporting and risk frameworks are state laws such as California's SB 53.
Source
https://openai.com/index/building-standards-next-phase-ai/- Date on the page:
- September 21, 2026
- Source checked:
- opened and confirmed on 2026-09-29