AI Policy Wiki
Dashboard

OpenAI's Frontier Governance Framework

high confidence · updated 2026-06-06

OpenAI's public governance document (May 28, 2026) mapping its frontier-AI safety and security practices to emerging legal requirements — California's Transparency in Frontier AI Act (SB 53) and the EU AI Act's GPAI Code of Practice. Downstream of, and distinct from, the Preparedness Framework.

Primary text: openai.com · PDF: cdn.openai.com · Published: May 28, 2026 (announcement; secondary coverage May 29) · Author: OpenAI

The Frontier Governance Framework is a public governance document published by OpenAI on May 28, 2026 that explains how its safety and security practices "align with emerging legal requirements." OpenAI describes the document as written to the compliance floor set by two regimes — California's Transparency in Frontier AI Act (SB 53) and the EU AI Act's Code of Practice for General-Purpose AI (GPAI Code of Practice) — and designed to "meet and go beyond" them. It is positioned downstream of, and narrower than, the Preparedness Framework.

Relation to the Preparedness Framework

OpenAI frames the document as downstream of, and narrower than, the Preparedness Framework. The Preparedness Framework "remains the foundation" for how OpenAI defines and operationalizes its approach to the most serious risks, including internal practices "that go beyond current legal requirements." The Frontier Governance Framework, by OpenAI's account, "applies relevant parts of that approach into a public governance document focused on specific regulatory obligations." OpenAI characterizes the Preparedness Framework as the internal risk-management approach and the Frontier Governance Framework as the regulator-facing public document derived from it.

Scope

Per OpenAI's announcement, the framework covers risk assessment and mitigation across cyber offense; CBRN (chemical, biological, radiological, nuclear) risks; harmful manipulation; and loss of control. It also addresses the surrounding governance machinery: model reporting, security risk management, incident response, and external expert input. OpenAI commits to revising the document under framework updates "as model capabilities, evaluations, and regulatory requirements develop."

Reception and context

The framework is described as one of the first instances of a frontier lab producing a standalone public document whose organizing principle is mapping internal safety practice onto named statutory regimes (SB 53 and the EU GPAI Code) rather than a lab-defined risk taxonomy alone. OpenAI treats the California and EU requirements as a baseline or floor rather than a ceiling, the same posture it took publicly the day of release.

The document was published as the body of state-level frontier-AI law expanded. The same week, Illinois SB 315 passed with a third-party-audit requirement, so a framework aligned to the legal floor faces a growing patchwork spanning California, the EU, Illinois, and the NY RAISE Act transparency track — a dynamic discussed under Techno-Federalism and the federal-preemption debate.

A voluntary, transparency-anchored governance document of this kind represents the industry-preferred alternative to mandatory pre-release vetting, the fault line running through the Trump frontier-AI EO and the rejected ODNI-led review proposals (see AI Pre-Release Vetting).

Provenance

This page summarizes the announcement text and the framework's stated structure. The full PDF (cdn.openai.com) elaborates the per-domain thresholds and reporting commitments; deeper provision-level detail can be added on a fresh read of the PDF if a future query requires it.

Relationships