Updated September 11, 2026. The measures described are public proposals from OpenAI, not already approved standards.
OpenAI has called for mandatory national requirements for the safety of the most powerful AI models, standards for independent auditing, and shared criteria for slowing or stopping development when controls are not sufficient. The position, published on September 9, comes after the release of GPT-6 Astra, the Hugging Face incident and new political pressures. The company claims that the voluntary commitments of individual laboratories are no longer enough.
What rules for AI safety does OpenAI propose
The first point is national regulation based on capabilities, not just model size or product name. A system capable of finding vulnerabilities, accelerating biological research or operating autonomously would face more stringent scrutiny. OpenAI says it wants to work with Congress and supports four California proposals on audits, youth, assessment infrastructure and biothreats.
The second level concerns standards developed together with other laboratories, even before a federal law. The objective is to measure capabilities, monitor border systems and define common thresholds. The problem of conflicts of interest remains: a standard written by companies can be quick and technical, but requires external verification and enforceable consequences.
Independent audits and shutdown thresholds
OpenAI says confidence in security should determine the pace of progress. If a model cannot be adequately protected, development or distribution should slow or stop. To make this promise credible, public thresholds, independent evaluators, access to data and a procedure that prevents the company from changing criteria under competitive pressure are needed.
For Astra, OpenAI says it has introduced universal tracking of full trajectories and a mandatory alignment gate before broader internal deployment. These measures are important, but the public cannot reproduce every assessment. Regulation must therefore establish who controls the controllers and what information can be shared without spreading offensive capabilities.
| Proposal | State |
|---|---|
| National requirements | Requested by OpenAI |
| Independent audits | Supported, details to be defined |
| Standards between laboratories | Proposed voluntary initiative |
| Pause thresholds | To be harmonized |
| Global coordination | Declared objective |
| Current law | Not yet built |
Because OpenAI talks about a limited window
The company uses the concept of a “policy window”: a period in which institutions and defenders can build protections before advanced capabilities become widespread. Open and international models will move closer to the frontier, making a rule applied to just one company less effective. Hence the demand for compatible methods between countries.
This argument can also be read critically. Costly rules can consolidate large operators and hinder smaller competitors. A balanced policy must focus on actual risk, offer accessible compliance tools and not transform incumbents into the only entities authorized to develop AI.
The relationship with the Hugging Face incident
The request comes while the Senate has opened checks and whilethe OpenAI crash during testingshowed concrete limitations of sandboxing and monitoring. It’s not enough to evaluate what a model responds in chat: you need to check tools, network, credentials, persistence and actions performed during long tasks.
Even the statements ofJacob Coxon on the risks of the AI raceaccelerated the debate. Its predictions remain attributed opinions, while OpenAI proposals are the company’s political commitments. Putting the two things on the same level would produce confusion; together they show, however, that security has become a problem of governance, not just research.
What a credible rule should contain
We need verifiable definitions of critical capabilities, pre- and post-release testing, mandatory incident notification, protection for those who report issues, data center audits and response plans. Authorities should be able to review logs and assessments without forcing the publication of exploits. Sanctions must be proportionate but real.
A pause threshold must specify who activates it, for how long, and what conditions allow it to resume. Without these elements “we will slow down if necessary” remains a discretionary promise. International coordination must also consider export controls, open research and regulatory differences.
What changes now
Access to OpenAI products does not change immediately. The proposals may influence federal and state bills, but will require negotiations. However, the political signal is clear: one of the main developers is asking for mandatory constraints even at the cost of slowing down capacity. The test will be to observe whether it will support enforceable rules, external audits and transparency when they conflict with speed and market.
We will keep monitoring AI safety rules and update this analysis when new verifiable data or final decisions emerge.
