Policy & Regulation

OpenAI asks California to tighten frontier AI safety law

OpenAI is asking California to strengthen SB 53, the state’s frontier-AI safety law, in a notable policy shift that follows a series of cybersecurity incidents involving advanced models. In an August 21 update from OpenAI Global Affairs, the company said the law should be expanded to require monitoring of frontier models during training and evaluation for potential serious incidents and to strengthen cybersecurity protections across the model-development lifecycle. The request turns a previously defensive posture toward state regulation into a proposal for broader statutory safeguards.

The timing matters because the proposal is not arriving as an abstract policy preference. OpenAI has spent August describing a new risk environment in which models under development can pose operational security problems before they are deployed to users. In its separate statement on pacing model development, the company said it had temporarily slowed some scaling work while raising standards for monitoring, alignment and containment. That operational experience is now being translated into a regulatory position: controls should apply not only to released systems but also to frontier models while they are still being trained or tested.

California’s existing SB 53 already created one of the most consequential state-level frameworks for frontier AI. According to the California governor’s signing announcement, the law requires large frontier developers to publish safety frameworks, establishes a mechanism for reporting certain critical safety incidents, protects whistleblowers and enables civil penalties for noncompliance. OpenAI’s new position does not replace those requirements. It argues that the framework should go further by adding explicit attention to models during training and evaluation and by treating cybersecurity as a lifecycle obligation.

That is a meaningful shift for AI governance because many current rules are still organized around deployment. Traditional software regulation often assumes that the main risk begins when a product reaches customers or production infrastructure. Frontier model development breaks that assumption. A training or evaluation system can have network access, tool permissions, code-execution abilities and exposure to sensitive infrastructure long before a public release. If serious incidents can occur at that stage, governance that begins only at deployment is structurally late.

The proposal also changes what “monitoring” means in practice. For engineering organizations, monitoring a frontier model during training or evaluation is not simply logging prompts and outputs. It can include anomaly detection, tool-call auditing, network boundary enforcement, sandbox telemetry, access controls, incident escalation and evidence retention. Those controls need to be designed around the possibility that the system being observed is itself capable of adapting its behavior, exploiting software weaknesses or taking actions that were not explicitly enumerated in a test plan.

OpenAI’s call for stronger cybersecurity protections across the full model-development lifecycle pushes the same logic further. Security would have to cover training clusters, model checkpoints, evaluation environments, researcher workstations, secrets, external tools and third-party testing infrastructure. That is closer to a secure development lifecycle for highly capable models than to a conventional model-safety checklist. For architecture and security leaders, the distinction matters because it moves responsibility from a narrow “AI safety” function into identity, infrastructure, network security, software supply chain and incident response.

The company’s public argument is reinforced by the broader discussion of persistent AI-enabled cyber threats. In a fresh Guardian interview, OpenAI chief global affairs officer Chris Lehane said organizations should prepare for ongoing, persistent attacks as capable systems become more accessible. The article also describes continuing uncertainty about when paused internal work will fully resume. That independent reporting does not validate every technical claim behind OpenAI’s policy position, but it confirms that the company is presenting the cyber issue as a sustained governance problem rather than a one-off incident.

For practitioners, the most important implication is that internal evaluation environments may need to be treated more like production security zones. A team testing an unreleased frontier model may need stronger isolation than a normal development sandbox, tighter control of outbound connectivity, explicit approval for sensitive tools and automatic containment when behavior crosses predefined thresholds. This can slow experimentation, but the alternative is assuming that a model under evaluation cannot create real-world consequences simply because it is not publicly available.

There is also a procurement consequence. Enterprises increasingly rely on vendors’ safety frameworks when deciding whether to deploy advanced models. If California expands SB 53 along the lines OpenAI proposes, buyers may gain more standardized information about how developers monitor models before release and how they handle critical incidents. That could make vendor due diligence less dependent on voluntary marketing claims. It could also raise the baseline for what enterprise customers should ask even when a provider is outside California’s direct scope.

The policy shift should not be overstated. OpenAI has proposed directions, not a finished statutory text, and California has not yet enacted the additional requirements. The company’s support also does not resolve implementation questions such as which models qualify for enhanced monitoring, what counts as a serious incident, how much evidence must be retained, when regulators should be notified or how confidential model-development information would be protected. Those details will determine whether the rules become operationally useful or merely symbolic.

There is also an important governance tension. A developer calling for stronger rules after encountering new risks can be read as responsible adaptation, but it can also shape regulation in ways that favor organizations with the resources to build expensive compliance systems. Smaller labs and open-model developers could face disproportionate costs if requirements are not calibrated to capability and risk. Policymakers will need to avoid a framework that improves safety on paper while unintentionally concentrating frontier development among the companies best able to absorb compliance overhead.

For Aipolix’s audience, the immediate takeaway is practical: model governance is moving upstream. The relevant control boundary is no longer only the API endpoint or the deployed agent. It increasingly includes the training run, evaluation harness, sandbox, model checkpoint and the infrastructure around them. Security and governance teams that wait for regulation to finalize can already review whether unreleased models receive the same identity, network, audit and incident-response discipline that they would demand from a production system.

What to watch next is whether California lawmakers convert OpenAI’s proposal into concrete amendments and whether other frontier labs support the same requirements. The key technical questions will be how monitoring obligations are defined, whether incident reporting thresholds become more specific and whether cybersecurity standards are tied to model capability rather than company size alone. The broader direction is already clear: after a year in which frontier AI policy focused heavily on disclosures and deployment, the next regulatory layer may reach directly into how advanced models are trained, evaluated and contained before release.

## Sources
- OpenAI Global Affairs — Pacing Our Model Development
- OpenAI — Pacing model development in an era of cyber-critical capabilities
- California Governor — Governor Newsom signs SB 53
- The Guardian — OpenAI leader warns of persistent AI cyber-attacks

Published: