DEV Community

Dean Lee
Dean Lee

Posted on Originally published at deanlee.info

OpenAI Wants a Safety Floor It Can Already Clear

This first ran on deanlee.info. OpenAI asked Congress for a national safety floor the same week California signed auditor bills. I read that as a capability argument and as a cost argument.

On September 9, OpenAI's chief global affairs officer, Chris Lehane, published a post titled "The AI policy window is open. We need to act." The company wants Congress to pass mandatory, capability-based national AI safety rules before it adjourns in December. Until then, OpenAI says it will keep backing state bills. The same day, California Governor Gavin Newsom signed two of the four bills the company named. SB 813 sets up independent safety assessments. AB 1405 sets standards for AI auditors.

I take the safety case seriously. OpenAI is not inventing a risk from a press cycle. Reuters reported the push after incidents in which models from several developers, including OpenAI, reached external systems during testing. Technology.org recapped independent researchers documenting OpenAI agents, given read-only web access, that used public wikis and link shorteners as improvised message boards across about a dozen sites the company had not disclosed. The Next Web noted that OpenAI is now asking for prompt written notice when a model circumvents security controls. That is the category of problem it has just been having.

Lehane's own language is about speed. "The prospect of AI-accelerated AI development demands more than voluntary commitments. The United States needs mandatory, capability-based national regulation that can evolve as the technology does." The company draws a hard line on fully autonomous recursive self-improvement. It "is not happening today," OpenAI says, and "we should not pursue it unless and until it can be done safely." The operational claim sits next door. AI agents can already perform some tasks that would take skilled researchers several days, which is a research-cost curve that can steepen without a new statute.

Steelman that. If model progress starts compounding through the lab's own tools, a voluntary preparedness framework is a private promise against a private roadmap. A national floor with independent assessment, incident reporting, and a shared measure of when development should slow is a way to stop each lab from writing its own stop rule. Lehane also says frontier requirements should hit "the handful of well-resourced laboratories developing the most capable systems," not startups and researchers nowhere near that frontier. On paper, that is how you raise a safety bar without turning every fine-tune into a regulated activity.

The industrial reading does not cancel the safety case. Every item on the federal list is something a well-resourced frontier lab already staffs. Common testing protocols. Independent assessment. Stronger cybersecurity around training and evals. Clear incident reporting. National preparedness language. Shared tracking of progress toward recursive self-improvement. For Astra, OpenAI says it already introduced universal monitoring of full trajectories, including chains of thought, and a mandatory alignment-evaluation gate before broader internal deployment. Written as law, those practices stop being a brand and become a compliance floor. A lab that already pays for red teams, eval harnesses, and an incident desk steps over it. A lab that does not has to build a department.

OpenAI knows the optics of asking to be regulated. The post says a public framework should reduce concentration of power, because today frontier labs largely set their own rules. Independent verification would replace that private system. I believe they mean the sentence. I also believe they know who can sit through an independent assessment on a classified-feeling training run. AB 1405 is about who may call themselves an AI auditor. SB 813 is about who may be designated to assess risk. Those are market-structure bills. They decide which firms can sell trust to enterprises, insurers, and procurement offices. Trust, once it has a license, is a distribution channel.

The California package makes the targeting even clearer. Besides the two signed bills, OpenAI endorsed SB 1119 on youth chatbot protections and AB 1864 on screening against AI-enabled biological threats. The company said some of these bills it did not endorse in the past, and is now supporting after reconsidering in light of a recent jump in capabilities. Technology.org put that next to an earlier period when OpenAI lobbied against California safety obligations on large developers. A reversal after a capability jump can be sincere. It can also be the moment when the cost of a rule the company already meets becomes a cost a rival still has to hire for.

"Reverse federalism" is OpenAI's name for the state strategy. States converge on a baseline, then Congress later copies it. That is cheaper for a national vendor than fifty different reporting clocks, fifty auditor regimes, and fifty definitions of a serious incident. CIO's enterprise coverage, quoting Pareekh Jain and Lian Jye Su, already translates the downstream bill. Even if the statute lands on model makers, CIOs will be asked for inventories of models and agents, audit rights, incident-notification clauses, and enough portability to switch vendors. The lab pays the assessment. The customer pays for the paperwork that proves the assessment happened.

The targeting has edges. The Next Web pointed out that OpenAI has been quieter on Florida, where the attorney general proposed criminal sanctions and a power to suspend an AI company from operating in the state. The same piece noted Leading the Future, a super PAC backed personally by OpenAI president Greg Brockman and the founders of Andreessen Horowitz, campaigning against state-level AI rules and pledging $5 million in Florida's governor race. That is Brockman's money, not a company line item. It still tells you the preferred laboratory of democracy is the one writing auditor standards, not the one writing criminal exposure.

OpenAI also asked that frontier safety policy not become open-weights policy by another name. Most open models, the post says, compete on cost, control, and latency rather than at the frontier. That sentence will be tested at the threshold. Capability-based rules sound more neutral than company-size rules. The person who writes the capability test still decides whether a cheap local model is "frontier" the week after a closed lab ships the same trick. If the threshold drifts down, the floor stops being a handful of labs and starts being a tax on anyone who can train.

Congress may do nothing before December. If it doesn't, California's new assessment and auditor statutes keep filling the vacuum, and other states will copy the parts that look administrable. If it does act, the first draft will look a lot like Lehane's list, because that list is already staffed inside the companies that will be in the room. Reuters noted that OpenAI and Anthropic are preparing for public listings. A recognizable national safety story is useful on a roadshow. It is also useful in an enterprise contract. The buyer wants a vendor that can produce an independent assessment on a deadline.

I would still rather have a public stop rule than a private one. The people who would pull a voluntary brake are the same people whose valuation, talent market, and model launch depend on leaving it alone. Mandatory reporting and third-party assessment change that payoff a little. They do not make the assessment free. The open questions are narrower than the rhetoric. Who is allowed to run the test. How high the capability threshold sits. Whether the incident clock starts when a model slips a sandbox or when the press finds the wiki.

Top comments (0)