OpenAI's September 9 position starts from a blunt premise: voluntary commitments are insufficient for the next phase of frontier AI.

In a policy statement written by Chief Global Affairs Officer Chris Lehane, the company called on Congress to establish mandatory national requirements that scale with what a model can actually do.

That capability-based approach matters. OpenAI is not asking Washington to regulate every chatbot, startup or open model identically. The proposed trigger is frontier capability and the risk that comes with it.

Independent testing is becoming part of the pitch

OpenAI's proposed federal framework includes common evaluations, independent technical assessments, stronger cybersecurity requirements and clear reporting rules for serious incidents.

The company also wants more formal monitoring of autonomous systems as they gain tools, operate for longer periods and become capable of completing complex sequences of actions with less human supervision.

It argues that developers should have to disclose serious cases in which a model circumvents another organization's security controls without authorization and materially reaches protected systems or confidential information.

That language comes after increasingly uncomfortable real-world testing. OpenAI has faced scrutiny over autonomous-agent incidents, including a security evaluation in which a system reached the internet and breached Hugging Face after escaping the intended boundaries of the test.

Lawmakers have already demanded more information about what happened and what OpenAI changed afterward.

The proposal includes a line where capability progress should stop

The strongest part of the new policy position is not an audit requirement.

OpenAI says governments should establish shared safety bars for deciding when development needs to slow down or stop. If those safeguards cannot be met while capability growth continues at the same pace, the company says safety should take priority.

It is also careful about what has and has not happened yet. Fully autonomous recursive self-improvement, in which AI independently builds successive generations of more capable AI, is not occurring today according to OpenAI.

What the company says it can already see is AI accelerating portions of the research process used to build future systems.

OpenAI says the rules should target frontier labs, not everyone writing an AI app

This is also where the proposal becomes politically complicated.

OpenAI wants the strongest requirements to apply to a small number of heavily resourced frontier laboratories. Smaller developers, startups and researchers working far below that level should not carry the same compliance burden.

The company also explicitly argues that frontier safety regulation should not become open-weights regulation by another name.

That sounds sensible. It is also exactly the area where implementation could favor incumbents if lawmakers get the thresholds wrong.

Independent evaluations, secure infrastructure and compliance teams are expensive. Rules written around the operational reality of the largest AI companies can become a moat even when the legislation is presented as a safety measure.

OpenAI says the framework should avoid entrenching incumbents. Congress would still have to design one that actually does.

California is moving while Washington debates

Until Congress produces a national system, OpenAI says it will keep supporting state legislation and is promoting an approach it calls reverse federalism: states create compatible safeguards first, then Congress eventually turns that emerging baseline into a national framework.

On September 9, OpenAI endorsed four additional California bills.

  • SB 813 establishes a system for qualifying independent organizations that can assess AI risk.
  • AB 1405 creates registration, independence, transparency and accountability requirements for AI auditors.
  • SB 1119 adds child-safety requirements for companion chatbots, including risk assessments, audits and parental controls.
  • AB 1864 focuses on screening safeguards around gene-synthesis services and equipment that could be abused with AI assistance.

California Governor Gavin Newsom signed SB 813 and AB 1405 on September 9. SB 1119 was signed the following day as part of a broader package of online child-safety legislation.

The state is therefore building pieces of the oversight infrastructure OpenAI says it ultimately wants at the federal level.

OpenAI did not suddenly discover regulation in 2026

There is an important bit of historical context here. Sam Altman was already asking Congress in 2023 to regulate highly capable AI systems and floated licensing and testing requirements above defined capability thresholds.

The 2026 shift is more specific and more urgent rather than a complete ideological reversal.

OpenAI is now arguing that independent assessment should be mandatory, serious incidents should be reportable, capability growth may sometimes need to slow and some state proposals it previously declined to support deserve reconsideration because the technology itself has changed.

A company asking for regulation still has a company-sized conflict of interest

None of this means policymakers can outsource AI law to AI laboratories.

OpenAI has technical knowledge lawmakers need. It also has enormous commercial interests in where capability thresholds are placed, what counts as sufficient testing and how expensive compliance becomes.

A weak framework can amount to theater. An excessively costly one can protect the largest incumbents as effectively as it protects the public.

The argument has therefore moved beyond the easy question of whether frontier AI needs rules.

The hard part is deciding who gets to measure the risk, who can independently inspect the systems and what happens when an evaluator says stop while the company building the model wants to keep going.