AI Policy Wiki
Dashboard

Democratic Governance of Frontier AI: A blueprint for a federal framework (OpenAI, June 2026)

high confidence · updated 2026-08-06

OpenAI's nine-page federal AI policy proposal, June 2, 2026. Sets out a three-part strategy: a national frontier safety framework built by 'reverse federalism' on California SB 53, New York's RAISE Act and Illinois SB 315, coupled with preemption of state laws regulating the same frontier safety risks; a strengthened CAISI with statutory authorization, Cabinet-level reporting, CHIPS-style hiring authorities, classified compute access, mandatory pre-release evaluation of the most capable models and a third-party assessor certification regime, but explicitly confined to evaluating and recommending rather than approving or blocking deployment; and a whole-of-government resilience strategy covering safety-collaboration legal certainty, export controls, a federal procurement bar on unevaluated frontier systems, and AI-enabled biodefense and cybersecurity. Names recursive self-improvement as potentially the defining frontier safety issue of the coming decade.

"Democratic Governance of Frontier AI: A blueprint for a federal framework" is a nine-page policy document published June 2, 2026 by OpenAI and hosted on the company's own content delivery network. It proposes a US federal regulatory framework for frontier AI organized around three elements: national legislation codifying the requirements of existing state frontier-safety laws, an expanded Center for AI Standards and Innovation as the government's primary frontier AI institution, and a cross-government resilience strategy. It is the counterpart document to Anthropic's Advanced AI Framework — both propose US federal frontier-AI regulation, and they differ most sharply on who gets to stop a deployment.

Framing

The document opens on competitive stakes — "the countries that successfully harness artificial intelligence will shape the scientific, economic, and geopolitical trajectory of the 21st century" — alongside capability concerns "about cyber offense, biological misuse, autonomy, alignment, and other threats to national security."

Its distinctive premise is recursive self-improvement as an active rather than prospective condition: "We also see early signs of recursive self-improvement (RSI) in today's systems: where AI development is itself accelerated by AI. We expect this to increase competitive pressures among developers and nations, and create governance challenges that existing institutions are not equipped to address." See Recursive Self-Improvement (RSI).

The argument for democratic governance is instrumental as well as normative: democracies can couple "innovation with public accountability, transparency, independent oversight, and the ability to course-correct through representative government," but doing so "requires visibility into how frontier capabilities are evolving" — which requires institutions capable of producing it. The document states that "democratic governments—not private companies acting alone—must ultimately determine the rules, safeguards, and accountability mechanisms," and that "decisions about the pace of AI innovation should not be left to any one lab, company, or special interest group."

The case for federal primacy rests on capabilities OpenAI describes as unavailable to private firms: "access to classified intelligence, expertise in cybersecurity and chemical, biological, radiological, and nuclear (CBRN) defense, secure computing environments, and the ability to coordinate with international partners."

The document identifies five criteria a framework should satisfy: address frontier risks to national security and public safety, covering "cyber and CBRN threats, RSI progress, and loss-of-control scenarios"; advance democratic governance; promote transparency; protect innovation "without creating unnecessary barriers for startups, researchers, and developers building on top of frontier capabilities" and without "locking today's industry structure into law"; and build adaptive institutions "that can learn, experiment, incorporate new evidence, and update standards over time."

Existing building blocks are enumerated as the foundation to be built on: frontier developers' adoption of the White House voluntary commitments, their partnership with CAISI for pre-deployment evaluations, US companies' signature of the European Union's AI Act Code of Practice, partnership with the United Kingdom's AI Security Institute, the three state laws, and "the White House's recent executive order on Promoting Advanced Artificial Intelligence Innovation and Security."

The stated strategy is threefold: "1) building a national framework that leverages the emerging consensus reflected in state frontier safety laws; 2) strengthening CAISI as the US federal government's primary institution for frontier AI safety; and, 3) mobilizing a broader resilience plan across government."

Reverse federalism and the national framework

The federal framework is presented as codifying an existing state-level consensus. "California's SB 53, New York's RAISE Act, and Illinois's SB 315 demonstrate that a meaningful consensus has emerged around the core elements of frontier AI governance. These frameworks share common requirements, align with international approaches, and provide a practical starting point for federal legislation." OpenAI's term for the sequence — states developing common frameworks that "Congress should now adopt at the national level" — is reverse federalism. See Reverse Federalism, California SB 53, New York RAISE Act, Illinois SB 315 (frontier safety framework with mandatory third-party audits).

The document specifies seven minimum contents for the national framework:

RequirementContent as stated
Severe risk evaluations and mitigationsCompanies "should evaluate frontier capabilities for risks related to cyber, CBRN, loss of control, misalignment, and progress towards RSI; implement appropriate safeguards; and explain why any residual risks are appropriately managed," tailored to deployment context
Transparency requirementsPublished frontier safety frameworks and transparency reports covering evaluation, safeguards, deployment decisions and RSI progress, "with appropriate redactions to protect security, trade secrets, and proprietary information"
Independent assessment and auditingLarge developers should "annually retain an independent third party to audit compliance," underpinned by common standards allowing "interoperable audits across jurisdictions"
Critical safety incident detection and reportingReporting of incidents involving deployed models, "dangerous model behavior, or unauthorized access to sensitive model weights"
Model weight securityCybersecurity and insider-threat protections for unreleased weights
Whistleblower protectionsProtection from retaliation for reporting severe risks, safety failures, critical safety incidents or legal violations to leadership, regulators "or other appropriate authorities"
Meaningful accountability mechanismsEnforceable consequences for non-compliance; liability frameworks "should preserve accountability for severe harms and should not provide blanket safe harbors from responsibility"

The three state laws are framed as "the foundation for federal frontier safety legislation—not its endpoint," to be built beyond by formalizing CAISI's role and adding the resilience measures.

The preemption ask is the document's most contested element and is stated as OpenAI's position rather than as consensus: with a comprehensive federal framework in place, "policymakers should also preempt state laws that seek to regulate the same frontier safety risks, creating a single national framework that combines strong safeguards with regulatory certainty." Three areas are carved out, where states "should continue serving as laboratories of democracy": youth protection, electricity and environmental policy, and AI education and literacy. See AI Federalism and EO — Trump Federal Preemption of State AI Laws (Dec 11, 2025).

The claim that the three state laws "share common requirements" holds at the level of obligation categories — each requires a published safety framework, pre-release evaluation, critical-incident reporting and whistleblower protection — but the record of the individual statutes shows divergence in mechanism and timing that the characterization does not capture. Illinois SB 315 (frontier safety framework with mandatory third-party audits) requires annual independent third-party compliance audits, which neither California SB 53 nor the New York RAISE Act does; the RAISE Act sets a 72-hour incident-reporting deadline against SB 53's 15-day standard with a 24-hour imminent-danger trigger. The blueprint's own recommendation of annual third-party audits therefore tracks the Illinois statute specifically rather than the three in common.

Strengthening CAISI

The institutional proposal centres on the Center for AI Standards and Innovation, with a phased approach. "Before CAISI can take on significant new responsibilities, policymakers must ensure that it has the resources, authorities, and institutional support necessary to succeed." The stated aim is to build CAISI into "the world's premier institution for frontier AI evaluation, standards development, independent assessment certification, and coordination across government and with international partners."

OpenAI frames its recommendations as "guiding principles for institutional design rather than prescribing every implementation detail," noting outcomes "will ultimately depend on how it is designed, resourced, and executed in practice," and cautions that policymakers "should be realistic about the challenges of building a new institution."

Five foundational measures are proposed:

  • Authorize CAISI and appropriate funding. Establish it "as a permanent institution with clear statutory authorities and sufficient funding to conduct frontier model evaluations, develop safety standards, certify third-party assessors, and coordinate with national security and scientific agencies, as well as with international partners."
  • Elevate CAISI's authority. The CAISI Director "should report directly to the US Secretary of Commerce or another senior Cabinet-level official," with the White House coordinating staffing, resources and operational support across departments.
  • Flexible hiring authorities. Adopt authorities "similar to those used by CHIPS for America," permitting rapid technical recruitment and competitive compensation, plus temporary tours of duty for outside researchers.
  • Mobilize national security expertise and data. Direct national security and scientific agencies to support evaluations and "immediately make available personnel and data related to cyber, CBRN, and other national security domains."
  • Secure access to classified compute. CAISI "should have access to classified computing environments capable of conducting frontier model evaluations," via dedicated infrastructure, interagency partnerships or agreements with agencies or commercial providers.

Mandatory pre-release evaluation

Once CAISI has sufficient capacity, "policymakers should require the most capable frontier models to undergo a CAISI evaluation before public release," assessing capabilities, safeguard effectiveness and "the resulting risk profile of the deployed system."

The limiting principle

The blueprint's most consequential provision is a constraint on the agency it proposes:

"CAISI's role should be to conduct evaluations and recommend mitigations — not to approve or block deployments. Developers should remain responsible for deployment decisions, publicly disclose evaluation findings and how they responded, and remain accountable through transparency and reporting requirements."

Two further limits protect deployment velocity. Requirements "should be narrowly targeted at the most capable systems and should allow for iterative deployment by establishing clear thresholds for when subsequent model versions require reevaluation." And evaluations must complete "within a defined statutory timeline": "if CAISI fails to complete an evaluation within the defined time period due to bandwidth, hardware, personnel, or other constraints, developers should be permitted to deploy without penalty."

Companies would "remain free to share models with trusted third-party evaluators, independent researchers, red-teamers, and testing partners before or alongside CAISI review," on the stated rationale that "a strong evaluation ecosystem requires multiple sources of expertise rather than a single institutional gatekeeper."

This is the sharpest divergence from Anthropic's framework, which contemplates an Agency able to fine, prohibit further deployment, and in extreme cases restrict access to already-deployed models — with safeguards against overreach rather than a categorical bar. OpenAI locates accountability in disclosure and reporting; Anthropic locates it in enforceable remedies.

Independent technical assessments and the assessor ecosystem

Deployment-triggered evaluation alone "may not provide governments with sufficient visibility into how frontier capabilities evolve over time." CAISI is therefore asked to develop standards for independent technical assessments, run "a certification process for qualified third-party assessors," and help build an assessment ecosystem "including by using AI itself." Developers above specified capability thresholds would be required to undergo periodic assessments by CAISI-certified organizations, with findings provided to CAISI. To build that ecosystem CAISI should be authorized "to provide grants, cooperative agreements, and other forms of support to emerging assessment organizations, academic centers, and technical institutions."

The stated initial priorities for these assessments are RSI progress, "highly capable internal deployments, frontier model security, internal monitoring practices, and the effectiveness of associated safeguards." See Rogue Internal Deployment and Independent Verification Organizations (IVOs).

Recursive self-improvement as an urgent priority

RSI recurs throughout the document as the organizing risk. It "exacerbates the fundamental governance question of whether humans can retain the ability to understand, guide, and shape the trajectory of advanced AI: making it potentially the most consequential frontier safety issue of the coming decade," while "policymakers currently have limited visibility into RSI progress, whether safeguards are keeping pace, or what indicators should inform future policy decisions." The document asks CAISI to "work with frontier developers, academic researchers, national security agencies, and international partners to rapidly develop methodologies, benchmarks, and indicators for measuring RSI," and states: "we encourage CAISI to treat RSI as an urgent priority." Frontier developers "should share appropriate RSI-related measurements with CAISI," with certified assessors periodically evaluating those measurements under CAISI methodologies.

Whole-of-government resilience

The third part argues that institutions alone are insufficient: "No evaluation process, assessment regime, or single organization can eliminate every risk." Five measures are proposed.

Legal certainty for safety collaboration and international coordination. Policymakers should "provide legal certainty that allows frontier developers to collaborate on safety-related issues, including sharing threat intelligence, evaluation methodologies, incident learnings, and best practices" — an antitrust-clearance ask. Democratic nations should develop compatible frameworks, trusted information-sharing channels and coordinated incident responses, with priority on "shared approaches for evaluating and responsibly communicating progress toward RSI, where a lack of shared measurements and transparency could intensify competitive pressures." The network of AI safety institutes is named as the vehicle for "confidence-building measures needed for governments to assess whether agreed safeguards are being implemented effectively."

Protect America's compute advantage. Strengthen export controls, "close known loopholes," and invest in compute, energy and infrastructure. The document frames this as a safety measure as well as an economic one: "Maintaining leadership in advanced compute is not only an economic and national security priority—it's also a frontier safety strategy." See Export Controls (AI) and Compute Governance.

Restrict adoption of unevaluated frontier systems. Federal agencies "should prohibit the use of frontier AI systems that have not undergone a recognized safety evaluation on government-owned systems and devices," and should bar procurement of products relying on unevaluated frontier models in sensitive contexts. Evaluations "should assess systems as deployed, including associated safeguards and controls, rather than the underlying model in isolation."

Scale defense faster than offense. Investment in "AI-enabled biodefense, cybersecurity, critical infrastructure protection, and rapid response systems," with OpenAI's own Cyber Action Plan cited as illustrating how AI can help "trusted defenders identify threats earlier, respond faster, and protect critical systems more effectively."

Prepare for future resilience challenges. The document points back to Industrial Policy for the Intelligence Age for "AI trust infrastructure, model-containment playbooks, safety systems for emerging cyber and biological risks, and new approaches to international coordination," and asks agencies to assess the feasibility, costs and implementation challenges of those proposals.

The closing section states that "democratic societies have a narrowing window to build the institutions needed to govern increasingly capable AI systems before frontier capabilities outpace existing frameworks," and characterizes the framework as "not intended to be the final word."

Provenance

Retrieved from OpenAI's content delivery network at cdn.openai.com, nine pages, PDF internal document title "Frontier safety blueprint." Independently cited under the same title, URL and date by Haug Partners LLP's AI regulation update, and linked by Kapoor and Narayanan (normaltech.ai, August 5, 2026) as evidence of leading labs' stated RSI goal.

Two OpenAI documents named in the text — "Industrial Policy for the Intelligence Age" and "OpenAI's Cyber Action Plan" — are cited by the blueprint as prior company publications.

Relationships