Demand for Mandatory National Regulation and Support for Four California Bills
OpenAI is calling for the introduction of mandatory national AI safety regulations that possess enforcement power proportional to technical capabilities, moving beyond voluntary commitments. This is a strategic choice to raise the baseline of safety standards by transitioning from existing governance methods that relied on corporate goodwill to a legally binding mandatory system.
Until legislation is passed by the U.S. Congress, OpenAI supports four bills currently being pursued in the state of California. Senate Bill 813 (SB 813) focuses on building infrastructure to designate independent agencies capable of objectively measuring AI risks. Assembly Bill 1405 (AB 1405) establishes standards for the registration, independence, transparency, and accountability of AI auditors—external experts who verify the safety and bias of models.
Specific measures for user protection and the prevention of physical threats are also included. Senate Bill 1119 (SB 1119) provides mechanisms to protect children and adolescents through age verification procedures and parental control functions. Assembly Bill 1864 (AB 1864) defines screening standards—tests to filter out requests for the synthesis of dangerous materials—that gene synthesis providers must follow to prevent biological threats utilizing AI.
The background for demanding mandatory regulation is the dramatic performance improvement of AI agents (systems that set their own goals and use tools to complete tasks). Cases have been confirmed where AI agents independently handled tasks that would typically take a skilled researcher several days to perform. The judgment is that risk control is impossible through voluntary compliance alone in a situation where the speed of technological advancement outpaces the speed of policy formulation.
OpenAI approaches frontier safety policies and open-weights policies (the method of disclosing a model's weight values) separately. Open models are effective in areas requiring cybersecurity or data residency (the legal requirement that data be stored within a specific country) and are primarily utilized based on cost and latency (the time it takes for a response after a data request) competitiveness. The federal framework should be designed to manage the risks of cutting-edge capabilities without hindering innovation or competition for small-scale developers.
For a company to request mandatory regulation is a strategic move to preemptively manage regulatory risks and standardize market entry barriers. Practically, if an independent third-party evaluation system is introduced, there is the advantage of clarifying the safety gate standards that must be passed before a model is released. However, fragmentation of standards may occur during the process of integrating state bills into federal legislation, which could act as a limitation by increasing development costs.
Full Monitoring of the Astra Model and Control of Recursive Self-Improvement
The Astra model employs full monitoring of full trajectories (all records from the start to the end of reasoning), including the Chain of Thought (the step-by-step reasoning process a model undergoes to reach an answer). Before internal deployment, it must pass a mandatory alignment-evaluation gate (an essential step to verify whether the model's behavior aligns with human intent and safety standards). This method does not merely check whether the final answer provided by the model is correct, but conducts a comprehensive investigation into whether dangerous reasoning or bias occurred during the logical development process leading to that answer. It is a transition from outcome-centered verification to a process-centered monitoring system.
OpenAI has increased the isolation level of frontier research workloads (high-load work units for developing cutting-edge AI models) and expanded behavioral monitoring during tool-use learning and evaluation processes. Tool-use learning is the process of developing a model's ability to solve complex problems by directly calling external software or APIs. Strengthening isolation means erecting physical or logical walls so that high-risk experiments do not affect other systems, and all logs generated during tool use are tracked in real-time. Technical control mechanisms to lower the possibility of security incidents throughout the development cycle have been internalized.
It has been confirmed that AI agents have reached a level where they can independently handle tasks that would take a skilled researcher several days. However, recursive self-improvement—where an AI designs and improves the next generation of superior AI on its own—is not currently occurring. A policy has been established not to intentionally pursue this capability until safety is fully secured. This is a strategic choice to increase the model's ability to perform individual tasks while strictly limiting the autonomy for the system to evolve beyond the scope of control.
Regulatory Separation of Frontier Models and Open-Weights Models
Frontier safety requirements are applied exclusively to Frontier Laboratories, which are a small number of resource-rich labs developing cutting-edge systems. Startups, small-scale developers, and general researchers who do not reach the frontier level are excluded from these regulations. This design aims to impose regulatory obligations proportional to the technical capabilities and resulting risk levels of a company, rather than its size. The purpose is to intensively manage systemic risks that could be caused by a few labs with massive resource inputs.
Open-weights models (the method of disclosing a model's weight values) evolve around competition for reducing operating costs, securing control, and shortening latency (data processing speed). They are primarily utilized in areas where maintaining national sovereignty or data residency (the requirement that data be physically stored within a specific country) is essential. Unlike the centralized control of frontier models, this provides the practical advantage of allowing users to directly own and optimize their infrastructure.
Greg Brockman presented the concept of the "Defenders Window," a limited window of time in which defense systems can be strengthened via AI before powerful offensive capabilities proliferate. Policymakers are in a similar position, needing to build sustainable safeguards before AI capabilities outpace governance systems. By emphasizing the temporal constraint that the speed of building defense systems must be faster than the speed of the proliferation of attack technologies, he stressed the urgency of policy formulation.
If safety standards are not met, safety assurance is prioritized over capability growth, and measures such as slowing down or stopping system development or deployment are taken. The principle is applied that as technology becomes more powerful, the surrounding safeguards must be strengthened proportionally. This is the result of setting the passing of safety verification as a mandatory gateway in the development process rather than the achievement of performance metrics, representing a mandatory braking mechanism according to the preparedness framework.
Limiting the scope of regulation to frontier labs is interpreted as a strategy to recognize the monopolistic authority of a few companies while simultaneously imposing heavy legal responsibilities corresponding to that power. Practically, the intention is to precisely target the leakage of high-risk models while preventing the side effect of small and medium developers giving up on innovation due to regulatory costs. However, if objective numerical standards for defining frontier-level capabilities are not clear, there is a limitation where model splitting or bypass routes may occur to evade regulation.
Reverse Federalism and the Perspective of Korean Practitioners
OpenAI supports California SB 53, New York's RAISE Act, and Illinois SB 315, urging the establishment of safeguards at the state government level. This is a method of "Reverse Federalism," where state governments first establish safety standards to create a de facto national baseline, which the federal government later codifies into law. During the vacuum period when federal legislation is delayed, preemptive regulation by state governments serves to raise the practical safety bar, and some bills have been re-examined for support to reflect recent rapid capability improvements.
Currently, frontier labs operate under a system of Private Governance (a system where companies create their own control rules) to set risk management rules. OpenAI argues that this must be transitioned to standards with democratic accountability and independent verification systems. It is a demand for a change from internal self-regulation to a structure where external independent verification and transparent information disclosure are mandated. This is an essential measure to prevent the concentration of power and ensure public safety.
AI models and technical expertise move across borders, and the failure of a cutting-edge system has global impacts beyond the developing country. Accordingly, an internationally compatible standard approach is needed regarding capability measurement, risk management, maintaining human control, and the timing for adjusting or stopping development speed. Establishing reliable standards within the U.S. first becomes an essential prerequisite for securing international leadership.
From the perspective of AX BRIEF, this trend provides practical standards for the design of AI regulation in Korea. The method by which individual state bills in the U.S. define specific safety requirements and integrate them into a national standard is an efficient path to fill regulatory gaps. Korean practitioners must prepare for a capability-based regulatory environment where they must pass evaluations by independent verification agencies beyond simply proving the safety of individual functions. In particular, as model autonomy increases, it is urgent to build a system to monitor and prove misalignment (the phenomenon where a model pursues goals outside of human intent or boundaries). The core of the practical response is transitioning the safety verification of frontier models from internal evaluation reports to a third-party certification system.




