Democratic Governance of Frontier AI: A blueprint for a federal framework
Published June 2, 2026 · Printed on the cover page, beneath the title "Democratic Governance of Frontier AI: A blueprint for a federal framework". The inner pages carry no date, only a running footer and a page number. The announcement page that links to the PDF is dated one day later, June 3, 2026.
Not law. This is a company's own public position on AI regulation. It is not law, and it carries no legal force.
What it argues for
This is OpenAI's formal legislative blueprint for US federal regulation of frontier AI, and its premise is that the decisions should not be the industry's: "democratic governments—not private companies acting alone—must ultimately determine the rules, safeguards, and accountability mechanisms", and "decisions about the pace of AI innovation should not be left to any one lab, company, or special interest group". It argues "the world needs more than voluntary commitments, individual company policies, and isolated regulatory interventions" and sets out a three-part strategy. First, "reverse federalism": Congress should adopt the consensus already written into California's SB 53, New York's RAISE Act and Illinois's SB 315 — risk evaluations and mitigations, published safety frameworks and transparency reports, annual independent audits, critical safety incident reporting, model-weight security, whistleblower protections and enforceable consequences — treating those laws as "the foundation for federal frontier safety legislation—not its endpoint", and then preempting "state laws that seek to regulate the same frontier safety risks". Second, a statutory, better-resourced CAISI that, once capable, would run a mandatory pre-release evaluation of the most capable models, though its role "should be to conduct evaluations and recommend mitigations—not to approve or block deployments", with developers free to deploy if CAISI misses a statutory deadline, and would certify third-party assessors for periodic independent technical assessments focused on recursive self-improvement (RSI). Third, a whole-of-government resilience strategy: legal certainty for safety collaboration between labs, stronger export controls and compute investment, a ban on federal use of unevaluated frontier systems, and defensive capabilities that scale faster than offensive ones. It closes by conceding that "The framework outlined here is not intended to be the final word on frontier AI governance."
Stated positions (13)
- Governments, not companies, should decide: "democratic governments—not private companies acting alone—must ultimately determine the rules, safeguards, and accountability mechanisms", and "decisions about the pace of AI innovation should not be left to any one lab, company, or special interest group."
- Congress should codify the state consensus through "reverse federalism": "This approach, which we call reverse federalism, allowed states to develop and refine common legal frameworks first, creating models that Congress should now adopt at the national level", naming California's SB 53, New York's RAISE Act and Illinois's SB 315.
- Minimum content of a national framework: companies "should evaluate frontier capabilities for risks related to cyber, CBRN, loss of control, misalignment, and progress towards RSI"; publish frontier safety frameworks and transparency reports "with appropriate redactions to protect security, trade secrets, and proprietary information"; report critical safety incidents; and "implement cybersecurity and insider-threat protections to secure unreleased model weights."
- Mandatory annual independent audit: "Large frontier developers should annually retain an independent third party to audit compliance with frontier safety requirements", underpinned by common standards "that allow for interoperable audits across jurisdictions."
- Whistleblower protection and real enforcement: employees "should be protected from retaliation when reporting credible concerns about severe risks, safety failures, critical safety incidents, or violations of law", companies "should face enforceable consequences", and "Liability frameworks should preserve accountability for severe harms and should not provide blanket safe harbors from responsibility."
- Federal preemption, but only once a comprehensive framework exists: with it in place, "policymakers should also preempt state laws that seek to regulate the same frontier safety risks", while states keep legislating "in areas beyond frontier safety, including youth protection, electricity and environmental policy, and AI education and literacy."
- A statutory CAISI: establish it "as a permanent institution with clear statutory authorities and sufficient funding" to evaluate frontier models, develop safety standards and certify third-party assessors, with its Director reporting "directly to the US Secretary of Commerce or another senior Cabinet-level official" and hiring authorities "similar to those used by CHIPS for America".
- Mandatory pre-release evaluation that is not a licence: once CAISI is ready, "policymakers should require the most capable frontier models to undergo a CAISI evaluation before public release", but "CAISI's role should be to conduct evaluations and recommend mitigations—not to approve or block deployments."
- Deadline protection for developers: if CAISI misses a statutory timeline, "developers should be permitted to deploy without penalty", and companies stay free to use other evaluators because "A strong evaluation ecosystem requires multiple sources of expertise rather than a single institutional gatekeeper."
- Periodic independent technical assessments above a capability threshold, focused on RSI: policymakers "should also require frontier developers above specified capability thresholds to undergo periodic independent technical assessments conducted by CAISI-certified organizations", with RSI-related measurements shared with CAISI.
- Government procurement as a lever: "Federal agencies should prohibit the use of frontier AI systems that have not undergone a recognized safety evaluation on government-owned systems and devices", and should bar procurement of products relying on unevaluated frontier models in sensitive government contexts.
- Compute and export controls as safety policy: policymakers "should strengthen export controls, close known loopholes, and invest in the compute, energy, and infrastructure needed to maintain US leadership"; the document calls compute leadership "also a frontier safety strategy".
- Scope stays narrow: the framework should act "without creating unnecessary barriers for startups, researchers, and developers building on top of frontier capabilities" and "should reduce risk without locking today's industry structure into law."
About this document
A 9-page PDF of about 3,300 words, hosted on cdn.openai.com and produced from Google Docs (embedded metadata title "Frontier safety blueprint"; no author or creation date in the metadata). The cover carries only the title, "Democratic Governance of Frontier AI: A blueprint for a federal framework", and the date June 2, 2026, and each later page has a running footer repeating the title with a page number. No individual author or signatory is named, and the OpenAI name appears in the body only once, where it cites "OpenAI's Cyber Action Plan"; authorship is established by the host domain and by the openai.com announcement page that links to it. It opens with two pages of framing — five principles for any framework (address national-security and public-safety risks, advance democratic governance, promote transparency, protect innovation, build adaptive institutions) — and then sets out a three-part strategy in numbered sections: "1. Building a national framework through reverse federalism", "2. Strengthening safety through strong institutions" (on CAISI, with the sub-heads "Build CAISI’s foundation", "Create a mandatory evaluation process" and "Support independent technical assessments") and "3. Mobilizing a whole-of-government resilience strategy". A closing section, "Building the institutions for democratic governance", follows. It contains no draft statutory text, no footnotes and no data; it names SB 53, the RAISE Act, SB 315, the EU AI Act Code of Practice, the UK AI Security Institute and the White House executive order on Promoting Advanced Artificial Intelligence Innovation and Security, which it calls "an important step forward".
How this sits against AI law
Each stance compared with what EU and US instruments actually require. Where no instrument addresses a theme, that gap is shown rather than hidden.
A federal frontier safety law built on the state consensus, then preempting state frontier laws
Congress should adopt the common core of SB 53, the RAISE Act and SB 315 as the foundation of a national frontier safety framework and, once that framework is in place, preempt state laws regulating the same frontier safety risks, leaving states free to legislate on youth protection, energy, environment and AI education.
The AI Act is the EU version of the end-state OpenAI describes: a single, directly applicable Regulation that imposes binding frontier-model duties (Articles 51 to 55) uniformly across all Member States, leaving no room for divergent national frontier rules.
The White House's March 2026 recommendations to Congress also seek preemption, but of "state AI laws that impose undue burdens" to create "a minimally burdensome national standard", adding that "States should not be permitted to regulate AI development" — preemption without the substantive frontier safeguards OpenAI makes its precondition. The recommendations are not binding law.
Evaluation and mitigation of severe risks, including loss of control and RSI
Companies should evaluate frontier capabilities for cyber, CBRN, loss-of-control, misalignment and RSI risks, implement appropriate safeguards and explain why residual risks are appropriately managed, with assessments tailored to deployment context.
Article 55(1)(a) and (b) require providers of systemic-risk models to evaluate the model, including adversarial testing, and to assess and mitigate possible systemic risks at Union level; the Act does not name recursive self-improvement as a category.
SB 53 requires a large frontier developer to publish a frontier AI framework describing how it assesses catastrophic-risk capabilities and applies mitigations, and it counts loss of model control among the critical safety incidents to be reported.
Published safety frameworks and transparency reports
Companies should publish frontier safety frameworks and transparency reports describing how they evaluate severe risks, implement safeguards, make deployment decisions and track progress towards RSI, with redactions to protect security, trade secrets and proprietary information.
Article 53 requires technical documentation for the AI Office and downstream providers and a public summary of training content, but no article of the Act obliges a provider to publish its safety framework or its evaluation results.
SB 53 requires large frontier developers to publish a frontier AI framework, to publish a transparency report before or at deployment of a new frontier model, and to republish material changes to the framework within 30 days, with redactions permitted for trade secrets and security.
Annual independent third-party audit
Large frontier developers should annually retain an independent third party to audit compliance with frontier safety requirements, including implementation of their frontier AI framework, internal controls and governance, against common standards allowing interoperable audits across jurisdictions.
Article 55 leaves model evaluation to the provider and mandates no external auditor for general-purpose models; Article 92 lets the AI Office appoint independent experts to evaluate a model only as a step in its own supervision.
Illinois SB 315, which the corpus records as adopted with an effective date of 1 January 2027, provides for annual independent third-party audits of large frontier developers' safety protocols — the provision OpenAI proposes to make federal. It is not yet in effect.
Critical safety incident reporting
Companies should report critical safety incidents involving deployed models, including incidents tied to risks in their frontier safety framework, dangerous model behaviour or unauthorised access to sensitive model weights.
Article 55(1)(c) obliges providers of systemic-risk models to track, document and report serious incidents and possible corrective measures to the AI Office, and as appropriate national authorities, "without undue delay".
SB 53 requires critical safety incidents — including unauthorised access to model weights and loss of model control — to be reported to California's Office of Emergency Services within 15 days, or within 24 hours where there is an imminent risk of death or serious physical injury.
Security of unreleased model weights
Companies should implement cybersecurity and insider-threat protections to secure unreleased model weights.
Article 55(1)(d) requires providers of systemic-risk models to ensure an adequate level of cybersecurity protection for the model and its physical infrastructure, without naming insider threat specifically.
SB 53 requires a large frontier developer's published framework to describe its cybersecurity practices for securing unreleased model weights against unauthorised modification or transfer by internal or external parties.
Whistleblower protection for employees raising safety concerns
Employees should be protected from retaliation when reporting credible concerns about severe risks, safety failures, critical safety incidents or violations of law to company leadership, regulators or other appropriate authorities.
Article 87 applies the EU Whistleblower Directive (EU) 2019/1937 to the reporting of infringements of the AI Act and to the protection of the people who report them.
SB 53 prohibits retaliation against covered employees who disclose information about catastrophic risks or violations to authorities, and requires large frontier developers to run an anonymous internal reporting channel with regular status updates.
Mandatory but advisory pre-release evaluation by CAISI
Once CAISI has the capacity, the most capable frontier models should have to undergo a CAISI evaluation before public release, within a statutory deadline; CAISI would recommend mitigations but not approve or block deployment, and developers could deploy without penalty if the deadline is missed.
The Act gives the AI Office no pre-release evaluation step for general-purpose models: its Article 92 power to evaluate a model and its Article 93 power to require mitigation or restrict a model apply to models already placed on the market.
Executive Order 14409 sets up only a voluntary framework through which developers may give the government access to covered frontier models for up to 30 days before release, and states it may not be read to authorise "a mandatory governmental licensing, preclearance, or permitting requirement"; OpenAI's proposal would make the evaluation compulsory.
On what a frontier developer should have to do, the blueprint reads close to the EU AI Act's systemic-risk chapter and to California's SB 53 — risk evaluation and mitigation, incident reporting, model-weight security and whistleblower protection all have direct counterparts in Article 55 and in SB 53, and OpenAI's list is largely a restatement of them. Where it goes beyond both is on independent scrutiny: an annual third-party audit and a statutory pre-release evaluation by a government institute, neither of which the AI Act or SB 53 imposes. At federal level the blueprint pulls against current US policy on two fronts. Executive Order 14409, signed the same day, keeps pre-release engagement voluntary and forbids reading it as a preclearance requirement, while OpenAI wants CAISI evaluation made mandatory (though advisory). And the White House's March 2026 legislative recommendations want preemption of state AI laws in the service of "a minimally burdensome national standard" and say "States should not be permitted to regulate AI development" — the same preemption OpenAI accepts, but offered in exchange for no substantive frontier safety duties, where OpenAI conditions it on Congress first enacting SB 53-style safeguards.
Source
https://cdn.openai.com/pdf/25752ecb-0e5c-47f9-b9e4-c0f4d76f8d3d/a-blueprint-for-a-federal-framework.pdf- Date on the page:
- June 2, 2026
- Source checked:
- opened and confirmed on 2026-09-29