OpenAI asks Congress for mandatory national AI safety rules before it adjourns

Testing protocols, independent assessment, incident reporting and pre-deployment evaluation gates. It is close to the architecture Brussels has just agreed to thin out.


Silhouette of a hand holding a smartphone in front of a white screen displaying the black OpenAI logo

OpenAI logo

Image Credits Credit: Henry Franklin via Shutterstock

OpenAI has called for mandatory, capability-based national AI safety regulation in the United States, setting out a list of requirements it wants imposed on itself and its competitors, and urging Congress to legislate before it adjourns.

The proposal was published on Wednesday by Chris Lehane, the company’s chief global affairs officer. It asks for common testing and independent-assessment protocols, stronger cybersecurity requirements, clear incident-reporting rules, mandatory monitoring for model misalignment, prompt written notice when a model circumvents security controls, and mandatory alignment-evaluation gates before deployment.

Alongside that, OpenAI backed four California bills covering independent evaluation, auditor standards, screening for biological threats and protections for children using chatbots.

Governor Gavin Newsom signed two of them on Tuesday. The company calls the approach reverse federalism: states building a de facto national baseline that Congress can later codify.

It is a familiar move in Sacramento, where OpenAI has already pushed to toughen a law it originally opposed, and where the fight over who may verify AI is being settled by the same bills.

A company asking to be regulated is usually asking to be regulated in a particular way. Every item on that list is something a well-resourced frontier lab already does, and several are things OpenAI has publicised doing.

Written as federal law, they become a compliance floor that a large company steps over and a smaller one has to build a department to reach. We have already reported that the rules for reviewing frontier models are already secret, and that the companies who have read them are the incumbents.

Reverse federalism also turns out to have preferences about which states. OpenAI has separately cautioned against state mission creep, arguing that highly technical reviews and national security questions belong to federal experts. The bills it supports are frontier safety frameworks and youth protections.

The one it has said nothing about is Florida’s, where the attorney general proposed criminal sanctions this week, including the power to suspend an AI company from operating in the state. Laboratories of democracy, so long as the experiments are the approved ones.

The politics around it are not tidy either. Leading the Future, the super PAC backed personally by OpenAI president Greg Brockman and the founders of Andreessen Horowitz, campaigns against state-level AI rules and has pledged $5mn in Florida’s governor race.

That is Brockman’s money rather than the company’s, and OpenAI’s policy shop is genuinely backing state bills in California. Both positions are consistent if the operative principle is which state rules, not whether.

For a European reader, the list should look familiar, because it is broadly the AI Act: capability tiers, independent assessment, incident reporting, evaluation before deployment.

Brussels legislated it, spent two years being told it had strangled innovation, and has since agreed to thin it out, with enforcement resting on a 36-person team. The largest American lab is now asking Washington for the same architecture while Washington leans on Europe to soften it.

The proposal follows a run of incidents in which models from OpenAI, Anthropic and Meta accessed or attempted to access external systems during testing, which is precisely what the requested rule on written notice when a model circumvents security controls would cover. OpenAI is asking to be legally obliged to report the category of problem it has just been having.

It also made commitments about its own conduct: slowing or stopping development where risks are unacceptable, universal monitoring of full model trajectories, and a framework for reporting misalignment incidents.

On the sharpest question, it said fully autonomous recursive self-improvement is not happening today and that it should not be pursued unless and until it can be done safely. That is a more careful sentence than the industry usually manages, and it is still a commitment to nobody.

Get the TNW newsletter

Get the most important tech news in your inbox each week.

Published
Back to top