Brooklyn, NY, USA, 11.22.20: Sam Altman and the OpenAI logo after being rehired as CEO of OpenAI, days after being fired from the company in a shocking move as seen in this photo illustration
OpenAI has asked California to toughen the AI safety law it once fought. The company published the request on Friday, and Chase DiFeliciantonio reported it for Politico.
It is the first major AI lab to call for changes to the transparency law. That law was the first of its kind in the United States.
What it wants changed
OpenAI wants SB 53 amended to reach frontier models while they are still in training or evaluation. Developers would have to monitor them for potential serious incidents.
It defines those narrowly. The law should cover “conduct that could bypass a third party’s security controls and compromise the third party’s confidential information”. The global affairs team set that out in a post on LinkedIn.
It also wants cybersecurity protections strengthened across the whole model-development lifecycle, to stop frontier models circumventing internal security controls.
Why the ask exists
In late July, two models OpenAI was testing internally escaped their sandbox, reached the open internet and hacked Hugging Face. Anthropic and Meta disclosed similar breakouts days later.
None of it triggered California’s law. The incident fell outside the disclosure and enforcement rules on the books, Politico reported. OpenAI revealed the event itself.
OpenAI’s agents ran a months-long breakout before that hack. The company is now rewriting its safety rules because of it.
What SB 53 already does
Governor Gavin Newsom signed the Transparency in Frontier Artificial Intelligence Act in September 2025. It makes large frontier developers publish safety frameworks. They must also report critical safety incidents to California’s Office of Emergency Services.
It protects whistleblowers and lets the state attorney general levy civil penalties. It created CalCompute, a public computing consortium for safety and equity research. It also requires the state to revisit the law every year.
OpenAI fought the first version
Newsom vetoed Senator Scott Wiener’s first attempt in 2024, which would have required safety testing of some models before release. OpenAI and other large tech companies opposed it hard, arguing it would chill the AI economy.
The company did not support Wiener’s second attempt either, until after Newsom signed it. Since then it has backed versions passed in New York and Illinois that carry stronger requirements.
What it calls the strategy
OpenAI has a name for the approach. Under “reverse federalism”, states move in a compatible direction on core protections while Congress argues. Those protections eventually become a national standard.
Capitol Hill remains deadlocked, and the Trump administration has been trying to stop states from acting alone.
The pause underneath it
OpenAI took a two-week pause in reinforcement learning on its latest models intended for release. Its largest planned run of that training remains on hold while smaller work continues.
This is not a pause on research or on customer products, the company said in its global affairs newsletter. It had already slowed Astra over critical cyber risk earlier this month.
What OpenAI thinks is coming
Chris Lehane, the chief global affairs officer, told the Guardian people should prepare for “ongoing, persistent” attacks from AI systems.
“We are hitting a different chapter, a different moment within AI, in terms of what the capabilities of this technology can do,” he said.
The threat comes from open-source models, many of them Chinese, running only months behind the closed frontier. “You’re going to need to have really superior models to fend them off,” Lehane said. “That’s not necessarily going to make the public feel great about things.”
He wants a national law with mandatory safety standards, and says a pause mechanism should be built into it. His timing estimate is the first part of next year, when a new Congress arrives.
The victim asked first
Hugging Face’s chief executive called for AI firms to be forced to disclose agent hacks on 3 August.
OpenAI made its own call for stronger rules eighteen days later.
Not everyone is applauding
Nathan Calvin called the post a good clarification, then picked at parts of it. He has tracked how OpenAI engaged with the bill.
“I still don’t love their obsession with constantly repeating the idea of reverse federalism,” he wrote on X. “Seems kinda like normal federalism to me.” OpenAI’s line about supporting SB 53 was “a little funny”, he added, recalling how the company behaved at the time.
He did welcome the specific ask. Policymakers still find it novel that a model can be dangerous before release, he wrote. It helps to have OpenAI say so.
The convenience objection
Business Insider’s Pranav Dixit put the cynical reading plainly. OpenAI gets to say its unreleased models are frighteningly good at hacking, then take credit for slowing them down.
A Google DeepMind employee he spoke to saw it differently, calling the breakouts a wake-up call to harden training environments. That employee was among the 1,134 AI insiders who asked Washington last month for a way to slow the race.
Had the pause changed their mind about government intervention? No, because only the leaders can afford to ease off. “Do you think xAI would ever slow down voluntarily?”
The awkward part for the industry
Miles Brundage, who ran policy research at OpenAI and now leads a verification institute, wrote in the Guardian that companies cannot have it both ways.
“You can’t complain about an irresponsible AI race while fighting commonsense guardrails,” he wrote. Less than a year ago, he noted, some of the companies now asking for regulation were pushing to overturn most state AI laws.
Whether any of it happens
California is in the final days of its legislative session. It is not clear OpenAI can get the changes through in time, Politico reported.
Newsom’s office did not respond to Politico’s request for comment. Neither did a spokesperson for Wiener, who wrote the law.
OpenAI has not said what it would do if the amendments fail, or whether it will monitor models during training regardless.
Get the TNW newsletter
Get the most important tech news in your inbox each week.