"Making AI Audits and Assessments Work" is a policy post published on August 7, 2026 by OpenAI's Global Affairs arm in its newsletter The Prompt, setting out six principles the company argues should govern independent AI safety and security audits and independent third-party assessments. It is the company's most detailed public statement on how external review of frontier developers should be structured, and it arrives while the design of the United States federal review process remains unsettled (AI Pre-Release Vetting).
The post's organizing move is a distinction between two kinds of external review that policy debate often merges. Audits "examine whether an organization follows established requirements and processes"; independent third-party assessments "test whether evidence supports specific safety or security claims." OpenAI describes them as "distinct but complementary."
Stated prior commitments
The post positions the principles as continuous with positions OpenAI says it has already taken. At the state level it names support for independent audits of youth-safety protections through the Parents & Kids Safe AI Act and audits of frontier safety frameworks in Illinois SB 315. At the federal level it points to its Frontier Safety Blueprint (Democratic Governance of Frontier AI: A blueprint for a federal framework (OpenAI, June 2026)), which "calls for the federal government to require annual independent audits of frontier developers' safety frameworks and independent third party assessments of the most advanced models, including to monitor progress towards recursive self-improvement" (see Recursive Self-Improvement (RSI)).
Beyond legal requirements, the post states that OpenAI has "long collaborated with organizations including METR, SecureBio, Apollo Research, and Irregular to evaluate frontier capabilities and risks such as long-horizon autonomy, biological threats, cybersecurity, scheming, deception, and oversight subversion," and that these assessments "supplement our internal testing, help identify blind spots, and provide additional evidence to inform deployment decisions."
The framing premise for the principles is that a mandate to be reviewed is insufficient on its own: "Requiring companies to undergo review is not enough. A defined control framework is a prerequisite for effective audits." The stated goal is an ecosystem "that is independent, qualified, technically informed, capable of identifying material findings, and accountable for the quality of its own work."
The six principles
1. Define the audit's scope and match requirements to risk and responsibility
A review should begin with a defined scope covering "the systems, products, environments, activities, and controls under review," within which auditors identify the applicable safety or security objectives, legal requirements, and assessment criteria. The post gives two worked contrasts: for children, assessing "whether age-appropriate protections are in place and effective"; for frontier AI, assessing "catastrophic-risk controls, internal governance, or the security measures protecting models and sensitive infrastructure."
The principle's second half is a proportionality claim. Requirements "should also be tailored to each entity's capabilities, responsibilities, and control," and "obligations developed for one risk domain should not automatically extend to differently situated actors, such as smaller developers, researchers, startups, downstream users, or participants in the open-model ecosystem."
2. Use the right kind of review
Audits examine "whether an organization follows applicable requirements, governance processes, and safety or security commitments." Independent third-party assessments examine "whether evidence supports a specific safety or security claim, such as whether an AI system, safeguard, or security control is fit for its intended purpose."
The illustration is drawn from frontier practice: an audit "might examine whether an advanced AI model developer followed its safety framework and documented required evaluations," while a validation or verification assessment "might examine whether the underlying tests, evidence, and safeguards support claims about model capabilities or safeguard sufficiency." Both require competent reviewers, but advanced-model validation "requires specialized technical expertise, secure testing environments, and, for frontier AI, national security awareness."
3. Follow common standards
Reviewers need "a clear framework for what they are assessing and how." Common, interoperable standards should define "the risks and controls in scope, the evidence and criteria reviewers should use, the level of assurance expected, and how assessments should be conducted and reported." Without that foundation, "reviewers may apply inconsistent questions and thresholds, making findings difficult to compare or act on."
The principle carries an explicit federalism argument. National or international standards should establish a consistent baseline; "states may adopt different protections, but comparable risks should be evaluated using rigorous, interoperable criteria and methods." For frontier AI, "federal coordination is especially important because catastrophic risks transcend state borders and credible evaluations may require specialized expertise, secure infrastructure, and national security capabilities." Where standards do not yet exist for an emerging risk area, frameworks "should evolve quickly and responsibly with input from auditors, assessors, and relevant domain experts." This is the same convergence-toward-federal-baseline argument the company advances under the label reverse federalism (Reverse Federalism).
4. Ensure credibility and independence
Review processes "should be designed to resist both regulatory capture and politicization." Auditors and assessors "should be accredited and selected through documented, consistently applied criteria, such as national and internationally recognized qualification standards, that match their competence to the scope of the review," with criteria that "could include relevant training, assessment experience, knowledge of applicable requirements, and where needed, technical and sector-specific expertise to evaluate the evidence."
Reviewers "should disclose and appropriately manage material conflicts, avoid assessing their own work, and remain free from relationships or outcome-contingent compensation that could compromise their judgment." The post accepts assessor choice while naming its failure mode: "Companies should be able to choose among qualified assessors, but the system should guard against 'assessor shopping' designed to avoid or soften adverse findings."
It closes the principle with a two-sided independence claim: "Findings should be based on objective, verifiable evidence.. Neither the companies being reviewed nor political actors that helped shape the rules should be able to steer individual findings or outcomes." (The doubled period appears in the published text.)
5. Enable secure oversight and responsible transparency
Auditors, independent assessors, and authorized regulators "should receive secure access to the necessary evidence they need, while user data, model weights, confidential intellectual property (IP), and security information remain protected from unnecessary disclosure, public release, or misuse." Access "should not require wholesale production or public disclosure of all system logs, private chain-of-thought, model weights, personal information, trade secrets, or other security-sensitive information," and should be "proportionate to the audit's scope and subject to appropriate confidentiality, privacy, security, data-minimization, retention, and use restrictions."
For public reporting, the post specifies the contents of a plain-language summary: "the audit's scope, applicable standards, methodology, assurance level, material findings and limitations, required corrective actions, and remediation status," together with "the auditor's identity, relevant qualifications, and material conflicts of interest." The disclosure regime is two-tier: "Regulators should receive complete reports and supporting evidence through protected channels, while public disclosures may use targeted redactions necessary to protect privacy, cybersecurity, IP, public safety, and national security."
6. Make audits and assessments lead to safer, more secure systems
Material findings "should result in time-bound remediation and appropriate follow-up, including verification that significant deficiencies have been corrected." Oversight bodies "should use audit and assessment findings to identify systemic gaps, assess evaluator performance, and strengthen standards as technology and risks evolve," an exercise the post says "will inherently require iterative approaches to understanding appropriate remediation steps congruent with updated standards."
On enforcement, the post states that "where applicable, regulators should take appropriate enforcement action in response to repeated or egregious failures, material misrepresentations, or obstruction of legitimate oversight." Its final sentence sets the scope limit for the whole scheme: audits and assessments "should complement ongoing testing, incident reporting, and legal enforcement – not replace it."
The accompanying Perspective section
The same issue carries a separate section, "The next threshold," arguing that model progress has moved beyond benchmark performance into "sustained reasoning, complex problem-solving, tool use, and longer sequences of actions directed toward an objective." It cites as its example that "an internal version of our next major model generated mathematical arguments on 10 long-standing problems, including results that resolved or made substantial progress on questions researchers had worked on for years." That claim is the subject of dispute recorded at Astra, Ten Advances in Mathematics and Theoretical Computer Science and OpenAI's amazing — but vastly oversold — new model Astra (Marcus, August 2026); the post restates it without engaging the objections.
The section's policy content is an argument against relying on scarcity. It states that as models become more capable "the answer can't be to just pretend the risks don't exist, or to assume powerful capabilities can just be kept scarce," and that OpenAI continues "to believe in iterative deployment: bringing capabilities into the world incrementally so that society can learn and adapt alongside the technology." The stated reason for continued diffusion is resilience: "Powerful technologies don't remain scarce forever. AI capabilities will continue to diffuse across countries, companies, and open models. In that world, safety and security cannot depend solely on trying to prevent access." As an instance of that posture, the post says OpenAI is putting its frontier models and tools in the hands of 100,000 scientists, mathematicians and engineers at no cost through ChatGPT for Academic Researchers. The section names the overall stance "realistic optimism."
Two positions published by the company on the same day sit in tension without being reconciled in either text. The Perspective section argues against depending on restricted access, while OpenAI said on August 7 that it could not rule out "critical" cyber capabilities in its unreleased Astra model and would slow development and expand testing before any release (Astra; Source: axios.com).
A closing "Weekly wrap" section records that OpenAI and the American Psychological Association are partnering to develop guidance for families, clinicians and educators on young people's use of AI, and that the company updated GPT-5.6 Sol in ChatGPT and expanded GPT-5.6 Luna to Free users with unlimited text chats and a new Think option.
Reception
No independent response to the six principles — supportive or critical — had been located as of August 8, 2026. The post was summarized the same day by trade coverage that reproduced the audit-versus-assessment distinction and the "assessor shopping" warning without evaluating either.
Provenance
Published August 7, 2026 at openaiglobalaffairs.substack.com under the byline "OpenAI Global Affairs," in the newsletter The Prompt. Verified August 8, 2026: HTTP 200, ogTitle "Making AI Audits and Assessments Work", article:modified_time 2026-08-07T22:45:34Z. A distinctive-passage check passed on the audit-versus-assessment distinction as worded, the phrase "assessor shopping," the six numbered principle headings, and the citations to the Parents & Kids Safe AI Act and Illinois SB 315. Outbound policy links resolve to openai.com/index/ pages. Because the document is a company newsletter post, it carries no DOI or docket identifier, so the identifier check rests on the canonical URL, the publication identity and the outbound link set; confidence: medium reflects that and the absence of any independent assessment of the principles as of the ingest date.
Relationships
- supports: AI Pre-Release Vetting — supplies a developer-authored specification for how external review of frontier models should be structured.
- supports: Illinois SB 315 (frontier safety framework with mandatory third-party audits) — restates OpenAI's support for the statute's third-party audit requirement.
- depends-on: Democratic Governance of Frontier AI: A blueprint for a federal framework (OpenAI, June 2026) — the federal audit and assessment requirements the post cites originate in the blueprint.
- related: NIST AI Risk Management Framework 1.0 — the "common, interoperable standards" the post calls for are the function NIST frameworks perform.
- related: Third-party cyber evaluations involving OpenAI models (OpenAI, August 2026) — the same company's account of what went wrong inside third-party evaluations, published three days earlier.
- contradicts: OpenAI's amazing — but vastly oversold — new model Astra (Marcus, August 2026) — the Perspective section's ten-results claim is disputed on denominator and cost grounds.