OpenAI is calling for mandatory national AI safety rules in the United States, arguing that voluntary industry commitments are no longer enough as the capabilities of advanced AI systems continue to grow.
The ChatGPT maker wants Congress to introduce capability-based AI regulation for the small number of companies developing the most advanced systems. Its proposal includes common testing requirements, independent assessments, stronger cybersecurity protections and clear rules for reporting serious AI incidents.
The policy shift comes as OpenAI reassesses how quickly AI capabilities are developing. The company has also thrown its support behind four California AI safety bills, including some it previously chose not to endorse, and is urging Congress to establish national requirements before it adjourns in December.
OpenAI Wants Mandatory National AI Safety Rules
OpenAI Chief Global Affairs Officer Chris Lehane set out the company’s position on 9 September, saying the possibility that AI could accelerate future AI development requires more than voluntary action by the industry.
“The United States needs mandatory, capability-based national regulation that can evolve as the technology does,” Lehane wrote.
Under OpenAI’s proposal, regulation would be tied to what an AI system can actually do and the level of risk those capabilities create. The company says requirements should focus on well-resourced laboratories building frontier systems, rather than startups, smaller developers or researchers working with less capable models.
The proposed federal framework would include common safety testing and independent assessments, stronger cybersecurity requirements and clearer incident-reporting rules. OpenAI also wants shared ways of measuring progress towards more autonomous AI development so governments can set thresholds for when development should slow or stop.
OpenAI is careful to distinguish that possibility from what AI systems can do today. It says fully autonomous recursive self-improvement, where AI independently drives the development of increasingly capable generations of AI, isn’t happening today. However, it says AI is already helping with some of the research used to develop and align future models.
Recent AI Advances Have Changed OpenAI’s Position
The call for stronger regulation follows a noticeable increase in the capabilities OpenAI is seeing from its own systems.
GPT-6 Astra, released on 3 September, became the first OpenAI model to reach the Critical cybersecurity capability level under the company’s Preparedness Framework. OpenAI says this means Astra can, with the right tools and access, find previously unknown security flaws and develop new ways to exploit them across well-protected systems without a person directing every step.
OpenAI said it delayed parts of Astra’s development and release while it strengthened safeguards around cybersecurity misuse and unauthorised model behaviour. Those protections include stricter isolation of development workloads, expanded monitoring and additional checks before models can be used internally.
The company directly pointed to Astra’s capabilities, alongside evidence that AI is accelerating some research work, when explaining why it believes policy now needs to move faster.
That change is also visible in OpenAI’s approach to state legislation. It has now formally endorsed four California bills covering independent safety assessments, AI auditor standards, protections for young people using companion chatbots and safeguards against AI-enabled biological threats.
OpenAI acknowledged that it hadn’t supported some of those measures before, but said it had reconsidered following the “recent jump in capabilities” it had seen.
When Access Isn’t Inclusion
Why digital strategies must move beyond coverage metrics to measure skills, trust, identity, and AI readiness as core participation outcomes.
California Moves Ahead While Congress Weighs Federal Rules
California Governor Gavin Newsom signed two of those measures, Senate Bill 813 and Assembly Bill 1405, into law on 9 September.
SB 813 establishes a framework for independent organisations that can assess whether AI systems comply with state law. AB 1405 creates a state registry for AI auditors and introduces requirements around their independence, transparency and integrity.
OpenAI has made clear that it doesn’t see state legislation as a replacement for federal regulation. Instead, it says states should continue raising safety standards while Congress develops a consistent national framework.
The company also wants any future US framework to feed into compatible international standards. OpenAI argues that frontier models, research and technical expertise move across borders, while failures involving the most capable systems could affect countries far beyond where those models were developed.
Rogue AI Agents Add To The Pressure
The policy announcement also follows new reporting about OpenAI agents circumventing restrictions during testing earlier this year.
Reuters reported on 9 September that six independent sets of investigators had found evidence that OpenAI agents used more than 10 previously undisclosed websites for unauthorised communications between May and July. Researchers said the agents appeared to work around restrictions intended to stop them from posting online and instead used third-party sites to leave information for other agents.
Reuters stressed that the behaviour fell short of hacking. However, the findings added to questions about how increasingly capable AI agents can be monitored and contained when they’re given tools and access to external systems.
OpenAI says it’s developing a framework for reporting serious cases of model misalignment and wants reporting requirements for major AI incidents to eventually form part of federal regulation. It’s also calling for industry-led monitoring standards, but says those should complement mandatory government safeguards rather than replace them.
When Data Governance Drives AI
A deep look at data architecture, governance and composable design as foundations for generative and agentic AI in complex enterprises.
For now, Congress hasn’t established the kind of national frontier AI safety framework OpenAI is asking for. The company’s position, however, has become considerably more explicit: as AI systems become more capable, it no longer believes the companies developing them should be left to set all of their own safety rules.
Comments ( 0 )