OpenAI publishes its Frontier Governance Framework
The document maps OpenAI's existing Preparedness Framework onto specific obligations under California's Transparency in Frontier AI Act and the EU AI Act's Code of Practice.
- Safety & alignment
- Government & policy
- Minor
OpenAI published a Frontier Governance Framework setting out how its existing internal safety practices map onto specific legal obligations it now faces, including California’s Transparency in Frontier AI Act and the EU AI Act’s Code of Practice for general-purpose AI, the latter binding on providers from August 2026. The company said its Preparedness Framework — the internal process, first published in 2023 and updated in 2025, that assigns risk levels across cybersecurity, CBRN, persuasion and model-autonomy categories to decide whether a model can be deployed — remains the substantive basis for its risk decisions, with the new document translating that process into compliance artifacts: model safety reports, a formalised incident-response plan, and security-certification baselines aligned to the specific requirements each law imposes.
The framework covered four risk areas by name — cyber offence, CBRN, harmful manipulation and loss of control — and committed OpenAI to model reporting, security risk management, incident response, external expert input, and periodic updates as capabilities and regulation evolve.
The document is best read as a statement of accountability rather than a new safety commitment: it did not describe new internal thresholds or testing beyond what the Preparedness Framework already specified, but made explicit, in public, which regulators OpenAI now considers itself answerable to — following a comparable move by Anthropic, which published its own account of technical safety architecture the same week.