OpenAI Releases Frontier Governance Framework in Response to Emerging AI Regulatory Requirements
OpenAI released a frontier governance framework on Thursday, responding to emerging regulatory requirements such as California's Frontier AI Transparency Act and the EU AI Act's general-purpose AI code of practice. The document details the company's safety practices in areas such as cyberattack assessments, risk management, and incident response, and commits to continuous updates in line with national and international AI risk management standards.

Core Overview:
- OpenAI released on Thursdaya frontier governance framework, systematically detailing the company's safety and security practices, and how it plans to align with emerging state-level and global AI regulatory requirements. The document details the company's practices in cyberattack assessment and mitigation, risk management, incident response, and other security elements.
- The company stated that the framework is a response toCalifornia's Frontier AI Transparency Actrequirements. The act requires model builders to disclose risk management protocols. OpenAI also citedthe General-Purpose AI Code of Practice under the EU AI Act, which assigns regulatory responsibilities to AI developers, requiring them to reduce risks of harm caused by their systems and provide technical documentation for review by EU officials.
- The company said the framework will continue to evolve and will reference national and international AI risk management standards. In the framework document, OpenAI stated: "We are committed to safely developing and deploying high-capability AI models, which bring significant benefits but also new risks."
In-Depth Analysis:
Before Memorial Day, OpenAI and other AI vendors had expected the Trump administration to issue an executive order establishing a voluntary AI model review process. However, Trumpcancelled the orderon the day it was originally scheduled to be signed, andtold reporters in the Oval Officethat he "didn't want to do anything" to hinder the US's lead over China in AI.
According toreports, the order would have allowed federal agencies to conduct voluntary reviews of AI models before their public release. This marks a shift in the Trump administration's stance, which had previously adopted ahands-off approach。
Samir Jain, Vice President of Policy at the Center for Democracy and Technology, believes that Anthropic's preview of its powerful model Mythos in April highlighted multiple cybersecurity concerns and weaknesses, which likely drove the idea of federal review. OpenAI quickly responded to related concerns by launching itscybersecurity initiative Daybreak。
Jain said: "This may have given national security agencies more interest in participating in the debate and having a greater say."
Despite the withdrawal of the executive order, AI vendors still face regulatory pressure at the state and global levels.
The EU's Code of Practice cannot directly dictatehow US companies operate their AI models, but when the Act fully takes effect in August 2027, non-European companies will still need to meet specific compliance standards to operate in Europe. OpenAI signed the voluntary Code of Practice last summer.
In its governance framework, OpenAI documented its technical and organizational procedures for risk reduction, based on definitions in California's AI Act. California joined Colorado, which wasthe first state to pass comprehensive AI legislation in 2024. Lawmakers in Illinois are awaiting the governor's signature on ahistoric AI bill, which would require oversight measures similar to those in California and Colorado, and introduce third-party audits for model safety issues.
The National Institute of Standards and Technologyannounced on Fridaythat it will expand the scope of its AI-focused consortium founded two years ago and recruit new members. Jain said that even without federal regulations, the Mythos preview may have highlighted the need for greater transparency in AI models.
He said Anthropic's latest model "made certain risks that AI models could pose, especially national security risks, more concrete."
Dion Hinchcliffe, Vice President and Practice Lead at The Futurum Group, said in an email statement that as AI becomes an increasingly regulated industry, CIOs should closely monitor these developments.
Hinchcliffe said: "Large enterprises are already leaning toward vendors that can demonstrate rigorous testing, red-teaming, and operational assurance before models go into production. Therefore, even a voluntary federal review framework could accelerate AI procurement toward vendors with mature governance systems and more robust, predictable release engineering."
OpenAI said it will continue to assess whether its models pose serious harm risks through its regular risk assessment process, and will incorporate feedback from researchers, industry bodies, the US government, and other regulators.