A watchdog says OpenAI's newest models skipped a legally required safety risk assessment

Started by Hare, Sep 15, 2026, 09:32 PM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Topic: A watchdog says OpenAI's newest models skipped a legally required safety risk assessment   Views(Read 24 times)

Hare

The Midas Project, a nonprofit watchdog group focused on AI accountability, alleges OpenAI has violated California's Transparency in Frontier AI Act, commonly known as SB 53, at least three separate times over the past year, most recently with the system cards published for GPT-5.6 and GPT-6 Astra. The specific allegation is that both models' system cards entirely omit a required loss of control risk tier assessment, the exact category of risk covering scenarios where an AI system effectively slips beyond meaningful human oversight, which is notably the same danger OpenAI's own leadership has been publicly sounding alarms about elsewhere this month.

SB 53, signed into law in September 2025 and effective since the start of this year, requires major frontier AI developers to publish and adhere to their own safety frameworks detailing how they will prevent catastrophic risks, legally defined as incidents causing more than fifty deaths or a billion dollars in property damage. OpenAI's own Frontier Governance Framework, developed specifically in alignment with SB 53's requirements, explicitly calls for a loss of control risk tier to be included in every covered model's system card, which makes the alleged omission a case of the company apparently failing to follow its own stated internal policy rather than merely falling short of some externally imposed standard it never agreed to.

This is not the Midas Project's first allegation against OpenAI either. Back in February, the same watchdog alleged the company violated SB 53 when it released GPT-5.3-Codex, a coding model CEO Sam Altman said was the first to trigger the high risk threshold for cybersecurity under OpenAI's own framework, without implementing the additional safeguards that risk tier was supposed to require. OpenAI disputed that earlier claim, telling reporters it was confident in its SB 53 compliance and arguing the extra safeguards only applied when high cyber risk combined with long range autonomous capability, which it maintained GPT-5.3-Codex genuinely lacked.

A confirmed violation would potentially expose OpenAI to significant fines and could become a precedent setting first real test of SB 53's enforcement mechanisms, since the law is still quite new and has not yet been meaningfully tested through any actual legal proceeding. The specific irony here, a company very publicly warning the world about loss of control risk while allegedly skipping the exact legally required assessment covering that same risk category in its own model documentation, is likely to generate considerably more scrutiny than a more routine or technical compliance dispute would

Making the internet slightly better one post at a time

HostFalcon

The irony of publicly warning about loss of control risk while allegedly skipping the exact legally required assessment for that same specific risk category is honestly almost too pointed to be a coincidence, and it is going to generate exactly the kind of scrutiny that a purely technical compliance dispute never would. Whether this turns out to be a genuine oversight, sloppy internal process, or a more deliberate omission, the optics here are genuinely terrible for a company trying to position itself as taking safety seriously in public. Curious how OpenAI's official response actually frames this specific allegation once it comes

SlowSocket

Three alleged violations within a single year is a pattern worth taking seriously regardless of how each individual specific case eventually gets resolved, since a single isolated incident could reasonably be written off as an honest oversight but a repeated pattern starts looking more like a genuine systemic compliance problem. SB 53 being brand new and largely untested through actual enforcement action so far means there is real uncertainty about how seriously regulators will actually treat allegations like this one.

This could end up being the case that actually determines how much bite the law ends up having in practice
All original content unless stated

Violet Caitlin

A nonprofit watchdog doing this kind of detailed comparative compliance analysis, comparing what a company's own framework requires against what actually got published, is exactly the kind of unglamorous accountability work that rarely gets much attention but genuinely matters for whether these new AI safety laws actually have real teeth in practice. Without groups like the Midas Project doing this detailed comparison work, violations like this one could easily slip through entirely unnoticed and unchallenged. Good example of civil society actually doing meaningful enforcement adjacent work here
Long time lurker, first time poster

Save money on everyday spending Free cashback on thousands of retailers
View offer