OpenAI Backs Mandatory AI Safety Rules: What It Is Asking Congress to Do
The company is calling for capability-based federal rules, independent assessments, cybersecurity standards, and incident reporting—but implementation details will decide whether the shift matters.

Bottom line
OpenAI says voluntary commitments are no longer enough for frontier AI. Here is what its call for mandatory national safeguards includes and what remains unresolved.
Editorial accountability
Who checked this guide
- Evaluation type
- Research-based verification
- Last materially checked
- Evidence
- 4 listed sources
Hands-on testing is identified explicitly. Research-based coverage uses cited product documentation and other named sources; it does not imply every paid plan was used. Read the full methodology.
Editorial basis
What this guidance is based on
- Editorial basis
- Source-led analysis
- Primary references
- 4
- Products covered
- 1
- Last checked
- 2026-09-10
Important limits
- • Features, availability, and pricing can change after publication; confirm consequential details with the provider.
In this guide
*This research-based analysis covers OpenAI's September 9, 2026 policy statement. It describes the company's public position, not enacted law. Bill status, text, enforcement, and OpenAI's support can change during the legislative process.*
The short answer
OpenAI says the United States should adopt mandatory, capability-based national AI safety requirements rather than rely on voluntary company commitments alone. Its stated framework includes common testing, independent assessments, stronger cybersecurity, serious-incident reporting, national preparedness, and shared measures for tracking AI systems that accelerate AI development.
The company also announced support for four California bills addressing independent safety assessments, AI-auditor standards, youth protections, and biological-risk safeguards. The change is politically significant because a frontier-model developer is explicitly asking for binding rules. It is not yet a regulatory system: thresholds, evaluator independence, disclosure, enforcement, preemption, and consequences for failing a safety bar remain the tests of substance.
What is OpenAI proposing?
OpenAI's statement calls for national requirements that activate based on model capabilities rather than a fixed label or company size. The idea is that stronger systems face stronger obligations as their cyber, biological, autonomous-research, or other consequential abilities increase.
The proposed ingredients include standardized evaluations, independent assessment, cybersecurity protections around models and research, reporting for serious incidents, government preparedness, and shared measures for recursive self-improvement. OpenAI says industry standards can move sooner but should complement—not replace—mandatory rules and democratic oversight.
Why capability-based rules are attractive
Capability triggers can focus obligations on the systems that create the greatest marginal risk while avoiding identical compliance burdens for a small classifier and a frontier agent. They can also evolve as benchmarks and deployment methods change.
The hard part is measurement. A model's risk depends on scaffolding, tools, fine-tuning, access, safeguards, and the skill of the operator. A benchmark threshold can be gamed or become stale. Regulators need multiple evaluations, real-world incident evidence, secure access for independent testers, and authority to update thresholds without abandoning due process.
What independent assessment must mean
An evaluator is not meaningfully independent if the model developer chooses every test, controls publication, pays under terms that discourage adverse findings, or can withhold the system needed to reproduce results. Auditor standards should address conflicts, access, competence, evidence retention, incident escalation, and public reporting.
Some findings will be too sensitive for full release, especially detailed cyber or biological procedures. A credible regime can still publish scope, methods, aggregate outcomes, remediation status, and oversight findings while protecting dangerous details. “Security” should not become a blanket exemption from accountability.
The federal and state tension
OpenAI argues for national rules while supporting current state action until Congress acts. A federal framework can reduce conflicting requirements and set a floor across the country. It can also weaken oversight if it broadly preempts stronger state protections without providing equally enforceable national standards.
The central question is whether federal law establishes a genuine floor or a ceiling. Policymakers also need to define coverage for open-weight models, cloud-hosted systems, fine-tuned derivatives, foreign providers, and products assembled from several models.
What buyers and builders should do now
Do not wait for legislation to inventory high-impact systems. Document model versions, capabilities, tools, data, deployment controls, evaluators, incidents, owners, and stop authority. Define internal reporting thresholds and rehearse containment. Require vendors to disclose evaluation scope, material incidents, model changes, and the evidence behind safety claims.
These steps reduce operational risk today and create the records a future audit will need. They also reveal where a supposedly low-risk assistant becomes a higher-risk agent because it can browse, write code, use credentials, operate equipment, or improve another model.
The verdict
OpenAI's support for mandatory regulation is a meaningful policy signal, particularly its acknowledgment that voluntary commitments are insufficient. The proposal's value will depend on details that a public statement cannot settle.
Strong rules need measurable capability thresholds, genuinely independent assessment, incident reporting with enforceable deadlines, regulator access, protection for good-faith researchers, and consequences when a developer cannot meet the required bar. Until those pieces exist in law and practice, the announcement is a position—not a safeguard.
Sources and verification
Product details and claims were checked against the following primary sources.
Frequently asked questions
Does OpenAI support mandatory AI regulation?
Yes. OpenAI says it supports mandatory, capability-based national safety requirements for advanced AI systems.
What safeguards is OpenAI proposing?
Its public framework includes common tests, independent assessments, cybersecurity protections, serious-incident reporting, national preparedness, and measures for AI-accelerated AI development.
Are these AI safety rules already law?
No. OpenAI's September 9 statement is a policy position and expression of support; specific bills must still pass and implementation details remain unresolved.
Why use capability-based requirements?
They can scale obligations with a system's demonstrated risk, but they require robust, updateable measurements that account for tools, scaffolding, access, and deployment safeguards.
Found this useful?
Get the next one in your inbox.
One five-minute briefing a week: a meaningful change, a practical workflow, and a clearer tool decision—already filtered for lean teams.
Free · one email a week · unsubscribe any time
Tools mentioned in this article
ChatGPT
The general-purpose AI assistant that started it all
OpenAI's flagship conversational AI model, powering everything from casual chat to complex reasoning, coding, and creative work.
Read next
