A new article from OpenAI Chief Global Affairs Officer Chris Lehane announces the company’s support for four pieces of regulation that are currently in the legislative pipeline in California, and calls for Congress to work out a similar national scheme of AI safety rules that is compulsory and capability-based.
OpenAI has previously declared support for certain other state-level AI safety rules, and has called for other states to adopt similar measures as a means to spur Congress to act on a baseline national set of regulations. But criticism of its attempt to insert itself in the legislative process is coming in from multiple angles: some believe the company has little right to speak after its security failures in the Hugging Face and other related incidents, others worry that its real intent is to create a regulatory “moat” that keeps out smaller competitors, and some feel that its encouragement of patchwork state and federal regulations will create friction that allows Chinese firms to catch and pass US developers.
OpenAI supports state-led pragmatic approach to eventually adopting national AI safety rules
OpenAI opens the note by stating that it wants to work with Congress on national AI safety rules, and cites four California bills either currently under consideration or very recently enacted as examples of what it would like those rules to resemble.
SB 813, just approved by the governor on September 9, creates a framework for Independent Verification Organizations (IVOs) to address risks in AI development and establishes the California AI Standards and Safety Commission to oversee this. AB 1405 was also enacted on the same date and establishes the country’s first “AI Auditor Registry” for these entities. SB 1119 remains under consideration and would establish new rules for AI chatbot developers mandating age checks and mitigation of potential harm to children. AB 1864, also still under consideration, addresses new safeguards to prevent AI from being used to create biological threats and weapons. The two bills that have been approved do not go into force until early 2028 and 2029, respectively.
For a fuller picture of what OpenAI wants to see in terms of national AI safety rules, the company has previously come out with similar endorsements for other state measures. In its own state it has previously supported California’s SB 53, which passed a year ago and established the nation’s first state-level regulatory framework for large frontier AI developers. It then supported New York’s RAISE Act, passed earlier this year, which crafted an even more thorough safety and transparency framework to take effect at the start of 2027. And it backed Illinois’s SB 315, which was the first state law to require third-party audits of frontier developers. It also backs a similar mandatory audit scheme that remains under deliberation in Massachusetts.
OpenAI frames the present period as the “AI policy window,” or “defenders window.” This is a finite period in which meaningful defenses and safeguards can be established before advanced AI offensive capability becomes too broadly available. The developer calls for “acting with urgency, humility, and a willingness to adapt” and AI safety rules that raise the defensive bar materially, even when they are “not exactly what we would have designed.”
OpenAI wants not just national, but international standards
For its own part, OpenAI says that when development poses an “unacceptable safety risk” and cannot be “sufficiently safeguarded” it will slow or stop the pace of development. It also says that its own frontier systems, as well as those of competitors, are not capable of fully autonomous recursive self-improvement and that no one should be pursuing this as a goal until (and unless) it can be done safely.
That seems to fly in the face of facts a bit, however. In both the Hugging Face attack and the recently revealed incident with the German message board takeover, unrestrained OpenAI models immediately sought to collaborate and were even seen “sacrificing” themselves to improve the collective’s understanding of how to tackle a security puzzle.
As Brownen Aker, AI Researched & Strategist with Black Hills Information Security, notes: “Its own agents started hijacking a dead German wiki to talk to each other as early as May. An internal alert flagged the activity on June 27. On-call staff decided it didn’t need to be stopped. Two months later, agents out of the same lab were inside Hugging Face’s infrastructure, and OpenAI didn’t even mention the German incident when it disclosed that one. Called them entirely unrelated. Then two OpenAI staffers got on stage at Black Hat and called it a ‘watershed moment for computer security,’ and, ‘a glimpse into the near future.’ Every pentester in that room has seen this movie before. No segmentation kept those agents off Hugging Face in the first place. No alerting caught them coordinating for months. That’s not a watershed. That’s Access Control 101. And they failed spectacularly.”
“None of that reads like a company where security has a seat at the table before something breaks,” Aker adds. “It reads like a function OpenAI calls in afterward to explain what already happened. If it wants to be taken seriously on regulation, the fix isn’t a keynote about how scary the future is. It’s changing how they operate, starting with giving actual security people real authority over what happens in their labs and elsewhere behind the scenes. The stakes of running ‘move fast and break things’ only keep climbing, and OpenAI isn’t a company that made one mistake and is learning from it. It’s a repeat offender.”
To that point, OpenAI did use the article to reiterate its recent announcement of an AI safety rules framework project for systematically monitoring frontier model activity for similar “rogue” incidents and reporting misalightments. The company intends to use this internally at first but hopes to see it considered as a federal standard in the future; it has also published a “Blueprint for Democratic Governance of Frontier AI” that more directly advocates elements of testing and incident reporting it would like to see adopted into a federal framework (before potentially going international). But despite announcements such as this and promises of substantial investments in new security and monitoring technology, there has been broad criticism from the cybersecurity industry of OpenAI’s willingness to take direct responsibility for the actions of its agents (versus instead framing it as an inevitable industry-wide problem).
Jacob Krell, Sr. Director of Secure AI Solutions & Cybersecurity at Suzu Labs, articulates one of those lines of criticism: “OpenAI is proposing mandatory safety requirements for U.S. labs while Chinese models operate under no equivalent constraints. That asymmetry is the actual risk … I build enforcement around AI agents in my own security work, and the only control that consistently holds is a human in the loop. Monitoring fails. Alignment training fails. A named person accountable for every action an agent takes does not fail the same way, because it changes the incentive structure entirely. Congress should stop writing rules for the models and start assigning liability to the people who deploy them.”
And Donald McFarlane, Advisory Board Member at Xcape, adds: “My concern with mandatory government evaluations and certified assessments is twofold. First, those are substantial fixed compliance costs that the largest AI companies can absorb far more easily than smaller competitors, including specialized cybersecurity and other model developers. We should be very careful that ‘frontier safety’ does not inadvertently become a moat around today’s frontier companies.”
“Secondly, compliance does not and must not become a substitute for responsibility,” McFarlane adds. “If a company uses a model that has passed a government-prescribed test and serious harm results, ‘It passed the test’ should not end the inquiry into whether the system and its use case were engineered responsibly. Nor should regulatory compliance become a de facto shield against liability for negligence.”

