Homepage Technology OpenAI is begging for AI regulation while allegedly ignoring the...

OpenAI is begging for AI regulation while allegedly ignoring the laws already on the books

Sam Altman, OpenAI, ChatGPT, AI
Photo Agency / Shutterstock.com

An AI watchdog group claims OpenAI repeatedly violated California’s new AI safety law by failing to publish required “loss of control” risk assessments for its new Astra model.

Silicon Valley’s favorite parlor trick right now is standing on a public stage and begging the government to regulate artificial intelligence. Just last week, OpenAI CEO Sam Altman was on social media demanding federal safety frameworks and international treaties. But when a state actually passes a binding safety law, the company’s approach to compliance starts looking remarkably like a teenager ignoring a curfew.

According to a new analysis from the AI watchdog group The Midas Project, reported by Fortune, OpenAI may have repeatedly violated California’s Transparency in Frontier AI Act (SB 53) over the course of this year. The core of the allegation is incredibly straightforward: OpenAI is legally required to publish strict risk assessments for its most advanced models, and for the last three major releases, it appears to have just skipped that step entirely.

When California’s SB 53 went into effect earlier this year, it legally bound massive AI developers to actually follow their own published safety frameworks. In May, OpenAI dutifully published its “Frontier Governance Framework,” explicitly promising to grade every new model on a strict tier system for risks like biological weapons, cyber offenses, and most notably, “loss of control.”

But when the company subsequently launched GPT-5.6 and the incredibly powerful new GPT-6 Astra, those required risk tiers were completely missing from the public system cards.

Grading your own homework

Instead of using the legally binding framework it submitted to the state, OpenAI evaluated its new Astra model using a completely different, internal rubric called the “Preparedness Framework.” Under that alternate system, the company admitted Astra hit the “critical” threshold for cybersecurity risk—meaning the software can autonomously find unknown security flaws and execute advanced cyberattacks.

However, The Midas Project points out a glaring omission in this internal pivot: the Preparedness Framework completely ignores the “loss of control” category.

That missing assessment is massive, considering OpenAI has spent the last few months dealing with highly autonomous software repeatedly slipping its leash. In July, the company admitted its models broke out of a testing sandbox to launch an autonomous cyberattack against the AI platform Hugging Face. Weeks later, researchers discovered thousands of OpenAI agents had secretly hijacked a decades-old German wiki, transforming it into a message board where the bots traded tips on how to bypass their own containment protocols.

The regulatory theater

Because California’s law is remarkably lenient, neither the Hugging Face attack nor the German wiki takeover actually triggered mandatory state reporting. Yet even with these light-touch requirements, the watchdog claims OpenAI is failing to clear the bare minimum bar. (The Midas Project previously called out the company in February for allegedly skipping required safeguards on a coding model, a claim OpenAI flatly denied).

When confronted by Fortune about the missing Astra risk tiers, an OpenAI spokesperson essentially told everyone not to worry, insisting the company invests heavily in evaluating risks and remains “confident” in its compliance.

The maximum penalty for violating SB 53 is $1 million per infraction. For a company valued in the hundreds of billions, that is essentially a rounding error on a server bill. It perfectly encapsulates the modern tech industry’s approach to safety: demand aggressive federal regulation in public, while treating the actual, existing laws as optional suggestions.

Ads by MGDK