OpenAI Publishes Governance Framework as AI Regulation Tightens Across States and Globally
OpenAI has released its Frontier Governance Framework, detailing its safety and security practices in response to emerging regulations in California, the EU, and elsewhere.

Framework addresses regulatory requirements
On Thursday, OpenAI unveiled its Frontier Governance Framework, offering insight into the company's approach to safety and security alongside its strategy for complying with evolving state and international AI regulations. The document outlines the company's methods for addressing cyber threats, managing risks, and responding to incidents, along with other security considerations.
The framework was developed in response to California's Transparency in Frontier AI Act, which mandates that model developers disclose their risk management procedures. OpenAI also referenced the EU AI Act's General-Purpose AI code of practice, which places the burden on AI developers to reduce potential harms and requires them to submit technical documentation for evaluation by European authorities.
According to OpenAI, the framework will continue to develop over time, drawing guidance from international and domestic AI risk management standards. "We are committed to safely developing and deploying highly capable AI models, which create significant benefits and also bring new risks," the company stated in the framework document.
Regulatory landscape shifts despite withdrawn executive order
Shortly before Memorial Day, OpenAI and other AI companies prepared for a potential executive order from the Trump administration that would have created a voluntary AI model review mechanism. However, Trump cancelled the order on the day of its planned signing, stating to reporters in the Oval Office that he "didn't want to do anything to get in the way of" what he characterized as the nation's competitive advantage over China in artificial intelligence.
The proposed order would have permitted federal agencies to conduct voluntary reviews of AI models prior to public release, marking a departure from the Trump administration's typically deregulatory stance on technology.
Anthropic's April demonstration of its advanced model, Mythos, which exposed multiple cybersecurity vulnerabilities and deficiencies, likely influenced discussions about establishing a federal review mechanism, according to Samir Jain, vice president of policy at the Center for Democracy and Technology. In response to these concerns, OpenAI launched Daybreak, its cybersecurity program.
"It may have made the national security agencies both more interested in being involved in this debate and having more of a voice," Jain said.
State and international regulations continue advancing
Despite the withdrawal of the executive order, AI companies are confronting regulatory requirements at both state and international levels.
While the EU's code of practice cannot directly govern how American firms operate their AI systems, international companies will need to satisfy specific compliance requirements to do business in Europe once the act becomes fully operational in August 2027. OpenAI became a signatory to the voluntary code of practice the previous summer.
OpenAI has detailed in its governance framework the technical and organizational measures it employs to address risks as outlined in California's AI legislation. California joins Colorado, which became the first state to enact comprehensive AI legislation in 2024. Illinois lawmakers are awaiting the governor's approval on an AI bill that would impose similar oversight requirements as California and Colorado, while also mandating independent audits of model safety.
On Friday, the National Institute of Standards and Technology announced it would broaden the scope of an AI-focused consortium established two years prior and seek additional participants. Without federal regulation in place, Anthropic's Mythos demonstration may have underscored the importance of greater openness regarding AI models, Jain noted.
"Anthropic's newest model made more concrete some of the risks, and particularly national security risks, that the AI models potentially are raising," he said.
Enterprise procurement may shift toward regulated vendors
As AI regulation becomes more prevalent, chief information officers should monitor developments closely, according to Dion Hinchcliffe, vice president and practice lead at The Futurum Group.
"Large enterprises already favor vendors that can demonstrate disciplined testing, red-teaming, and operational safeguards before models reach production, so even a voluntary federal review framework could actually accelerate AI procurement toward vendors with mature governance and slower, more predictable release engineering," Hinchcliffe said.
OpenAI indicated it will maintain an ongoing risk assessment process to determine whether its models pose a danger of severe harm, and will integrate input from academic researchers, industry organizations, U.S. government officials, and other regulatory bodies.


