The AI policy window is open. We need to act.
Published September 9, 2026
Not law. This is a company's own public position on AI regulation. It is not law, and it carries no legal force.
What it argues for
Bylined "By Chris Lehane, Chief Global Affairs Officer at OpenAI" and filed under Global Affairs, this is OpenAI's current statement of what it wants AI regulation to be, written around the claim that "the prospect of AI-accelerated AI development demands more than voluntary commitments." Its central ask is that Congress enact mandatory, capability-based national AI safety regulation that can evolve with the technology, containing common testing and independent-assessment requirements, stronger cybersecurity protections, clear incident-reporting rules, greater national preparedness, and shared measures for tracking progress toward recursive self-improvement — the agenda set out in OpenAI's own Blueprint for Democratic Governance of Frontier AI, which this post links to and updates. It argues the framework should be "strong but carefully targeted," binding only "the handful of well-resourced laboratories developing the most capable systems—not to startups, small developers, or researchers operating nowhere near the frontier," and warns that frontier safety policy must not become "open-weights policy by another name." Until Congress acts it backs state legislation as a de facto national baseline — an approach it names "reverse federalism" — and formally endorses four additional California bills (SB 813, AB 1405, SB 1119, AB 1864) alongside its earlier support for California SB 53, New York's RAISE Act and Illinois SB 315, noting that "some of these bills we did not endorse in the past, and are now supporting after reconsidering in light of the recent jump in capabilities." It also calls for developers to be required to monitor for misaligned model behaviour with attached disclosure duties, for industry-led frontier standards built voluntarily "with or without government support" as a complement to (never a replacement for) mandatory federal safeguards, and for compatible international standards on capability measurement, human control and when development should slow or stop — "even if that means slowing the advancement of model capabilities." The framing is explicitly anti-concentration: democratically accountable standards, independent verification and meaningful transparency should replace the "fragmented system of private governance" in which frontier labs "largely set their own rules."
Stated positions (13)
- Congress should pass mandatory, capability-based national AI safety regulation, not rely on voluntary commitments; OpenAI says it "cannot let the perfect become the enemy of the good" and that "Congress should act before it adjourns."
- The federal framework should include common testing and independent-assessment requirements, stronger cybersecurity protections, clear incident-reporting rules, greater national preparedness, and shared measures for tracking progress toward recursive self-improvement.
- Scope must be narrow and proportionate: frontier safety requirements should apply to "the handful of well-resourced laboratories developing the most capable systems—not to startups, small developers, or researchers operating nowhere near the frontier."
- Frontier safety policy "should not become open-weights policy by another name" — America needs both open and closed models, and a federal framework must not entrench incumbents or drive innovation overseas.
- States should keep legislating until Congress acts, converging on common safeguards to create "a de facto national baseline that Congress can ultimately codify" — an approach OpenAI calls "reverse federalism."
- Formally endorses four California bills headed to Governor Newsom: SB 813 (designating qualified independent AI risk assessors), AB 1405 (registration, independence, transparency and accountability rules for AI auditors), SB 1119 (age assurance, risk assessments, independent audits and parental controls for companion chatbots used by minors), and AB 1864 (federal screening standards for gene-synthesis providers and benchtop synthesis equipment).
- Prior state endorsements restated: California SB 53, New York's RAISE Act, Illinois SB 315, and independent audits in the Massachusetts frontier safety legislation — and OpenAI says it now supports some bills it previously did not, "after reconsidering in light of the recent jump in capabilities."
- Developers "should be required to monitor for these misaligned behaviors and demonstrate that effective safeguards are in place," tied to disclosure: prompt written notice to affected parties when a model, during development or evaluation, circumvents another organization's security controls without authorization, plus support for federal reporting of other serious AI incidents.
- Industry-led frontier standards should be built with other labs "with or without government support," but would "complement—not replace—mandatory federal safeguards and democratic oversight."
- Advocates compatible international standards for measuring capabilities, managing risk, preserving human control, and determining when development should slow or stop, "even if that means slowing the advancement of model capabilities."
- On recursive self-improvement: fully autonomous RSI "is not happening today. We should not pursue it unless and until it can be done safely"; governments should set shared safety bars, and "if we cannot meet certain safety bars without slowing down capability growth, we should prioritize the former."
- Regulation is framed as an anti-concentration measure and as a precondition for American leadership: democratically accountable standards, independent verification and meaningful transparency should replace the current "fragmented system of private governance" in which frontier labs "largely set their own rules."
- Prefers independent technical assessments to be mandated at federal level for consistency, accepting state action (SB 813) only "in the absence of federal action."
About this document
A signed blog post published 9 September 2026 on openai.com under the "Global Affairs" category, bylined Chris Lehane, OpenAI's Chief Global Affairs Officer, and tagged "Reasonings & Policy". It runs to roughly 1,940 words of prose — an essay, not a white paper, consultation response or legislative text, with no footnotes, citations to statutory language or data. It opens with an unheaded framing passage and a four-bullet "Here's what we're doing" list (push for mandatory national requirements, keep momentum in the states, advance industry-led standards, build global standards), then proceeds through five headed sections carried in a jump menu: "Preparing for recursive self-improvement", "Working with Congress on mandatory national AI safety requirements", "Keeping up momentum in the states", "Calling for industry standards to monitor frontier AI", and "Use the window". It leans heavily on outbound links to OpenAI's own material — Jakub Pachocki's essay on machine intelligence, the Blueprint for Democratic Governance of Frontier AI, the Preparedness Framework, Greg Brockman's "defenders window", the Open Weights and American AI Leadership letter. Its concrete news is the formal endorsement of four California bills awaiting Governor Newsom: SB 813, AB 1405, SB 1119 and AB 1864, noting some were not endorsed before. It commits OpenAI itself to specific internal measures — isolation of frontier research workloads, universal monitoring of full trajectories including chains of thought for Astra, a mandatory alignment-evaluation gate — while asking Congress to act "before it adjourns". It closes: "No first step will be perfect."
How this sits against AI law
Each stance compared with what EU and US instruments actually require. Where no instrument addresses a theme, that gap is shown rather than hidden.
Mandatory capability-based national regulation instead of voluntary commitments
Congress should enact binding, capability-based national AI safety regulation that can evolve with the technology, because "the prospect of AI-accelerated AI development demands more than voluntary commitments".
Article 51 classifies a general-purpose AI model as carrying systemic risk on a capability test, presumed met above 10^25 cumulative training FLOP, and Article 55 attaches binding duties to that tier with the Commission empowered to update the threshold by delegated act.
The Action Plan sets the opposite direction of travel, stating AI is "far too important to smother in bureaucracy at this early stage, whether at the state or Federal level" and directing agencies to identify, revise or repeal rules that hinder AI, while imposing no binding safety obligation on any frontier developer.
Mandatory independent third-party assessment of frontier models
A federal framework should require common testing and independent technical assessment, with a designated system of qualified independent assessors; OpenAI endorses California SB 813 and AB 1405 only as a second-best in the absence of federal action.
Article 55 requires the provider to run its own model evaluation and adversarial testing but mandates no accredited external assessor; Article 92 lets the AI Office commission evaluations by independent experts only as a triggered enforcement step, and external evaluation appears for systemic-risk models only in the voluntary GPAI Code of Practice.
M-25-21 mandates pre-deployment testing, AI impact assessments and an "independent review" of high-impact AI, but it binds executive agencies using AI rather than developers, and its reviewer must be an agency employee not involved in development — not a third party.
Mandatory reporting of serious AI safety incidents to government
Clear incident-reporting rules should be part of the federal framework, and OpenAI supports federal reporting requirements for serious AI incidents while working to define which incidents are covered.
Article 55(1)(c) obliges providers of systemic-risk GPAI models to track, document and report serious incidents and corrective measures to the AI Office "without undue delay", with a parallel regime for high-risk systems under Article 73.
SB 53 requires frontier developers to report critical safety incidents to California's Office of Emergency Services within 15 days, or within 24 hours where there is an imminent risk of death or serious physical injury — but this is California law, and no federal instrument requires anything comparable.
Monitoring for misaligned model behaviour and notice when a model breaches another party's systems
Developers should be required to monitor for misaligned behaviour and demonstrate effective safeguards, and to give prompt written notice to affected parties when a model circumvents another organization's security controls and materially accesses, alters or destroys its systems or confidential information.
The Act's serious-incident duty runs to the AI Office rather than to the organisation whose systems were breached, and its definition of a serious incident is framed around death, harm to health, critical-infrastructure disruption and fundamental-rights breaches rather than a model defeating a third party's security controls.
SB 53 requires a large frontier developer's published framework to address risks from a model circumventing oversight mechanisms and to report critical safety incidents to the state, but it creates no duty of written notice to the outside organisation whose systems the model reached.
Cybersecurity protection of frontier model weights
Stronger cybersecurity protections should be one of the five pillars of a durable federal framework, and OpenAI reports it has strengthened isolation for frontier research workloads across the model-development lifecycle.
Article 55(1)(d) requires providers of systemic-risk GPAI models to ensure an adequate level of cybersecurity protection for the model and for the physical infrastructure it runs on.
SB 53 requires a large frontier developer's published frontier AI framework to describe its cybersecurity practices for securing unreleased model weights; the federal Action Plan does not address model-weight security at all.
Scope confined to a handful of well-resourced frontier laboratories
Frontier safety requirements should reach only the handful of well-resourced laboratories building the most capable systems, with obligations proportionate to capability and risk, and should not touch startups, small developers or researchers operating nowhere near the frontier.
The Act reaches well below the frontier: Article 53 binds every provider of a general-purpose AI model regardless of size or compute, and the high-risk regime binds providers and deployers by use case, with SMEs given simplified documentation and sandbox access rather than exemption.
Colorado's act keyed on the decision context rather than model capability, reaching developers and deployers of any high-risk AI system that was a substantial factor in a consequential decision, with no compute, training-cost or revenue threshold anywhere in it — the opposite of OpenAI's frontier-lab perimeter. It was repealed on 14 May 2026; its successor, SB 26-189, has not yet taken effect.
Frontier safety rules must not become restrictions on open-weight models
Frontier safety policy should not become open-weights policy by another name; America needs both open and closed models, and most open models compete on cost, control and latency rather than at the frontier.
Article 53(2) exempts free and open-source models from the technical-documentation duties, but states that the exception "shall not apply to general-purpose AI models with systemic risks" — so the line is drawn on capability, not on whether weights are released.
A dedicated section, "Encourage Open-Source and Open-Weight AI", treats the release decision as "fundamentally up to the developer" and directs NTIA to convene stakeholders to drive adoption of open models by small and medium-sized businesses.
State legislation as an interim national baseline ('reverse federalism')
Until Congress acts, states should keep moving to fill the vacuum and converge on common safeguards, creating a de facto national baseline that Congress can later codify.
The question does not arise in the EU: the AI Act is a directly applicable Regulation that harmonises requirements across all Member States from the outset, so there is no interim sub-national patchwork to converge.
The Action Plan directs OMB to work with agencies so they "consider a state's AI regulatory climate when making funding decisions and limit funding if the state's AI regulatory regimes may hinder" the award, and tasks the FCC with evaluating whether state AI rules interfere with its authorities — penalising the state activity OpenAI is encouraging.
Recursive self-improvement and shared bars for slowing or stopping development
Fully autonomous recursive self-improvement should not be pursued unless and until it can be done safely, and governments should develop common measures of progress toward it and shared safety bars for when development should slow or stop — even at the cost of capability growth.
The Act reaches market conduct, not the laboratory: Article 93 lets the Commission require mitigation or restrict, withdraw or recall a model already placed on the market, and nothing in it sets a threshold at which development itself must slow or halt.
No US federal instrument addresses autonomous recursive self-improvement or sets any threshold for pausing development; the nearest provisions fund interpretability and control research and build an evaluations ecosystem, without attaching a consequence to any result.
On substance, OpenAI is asking Congress for something close to what the EU already enacted: mandatory duties triggered by model capability, with testing, model-weight cybersecurity and serious-incident reporting attached — the EU AI Act's systemic-risk tier is the nearest existing analogue to the federal framework this document describes. Where OpenAI diverges from the EU it is toward a narrower perimeter (frontier labs only, against an Act that also binds ordinary GPAI providers and high-risk deployers by use case) and a more demanding one on independent assessment and stop-rules, neither of which EU law mandates. Against current US federal policy the gap is wider than a matter of degree: America's AI Action Plan is a deregulatory programme that would penalise states for legislating, so both of this document's central asks — binding federal frontier rules, and states continuing to legislate until those arrive — run against it, and the only US instruments that do what OpenAI wants are the state laws it has endorsed.
Source
https://openai.com/index/ai-policy-window/- Date on the page:
- September 9, 2026
- Source checked:
- opened and confirmed on 2026-09-18