For years, a significant part of the American tech industry has viewed regulation as an obstacle to be kept as far away from innovation as possible. On September 9, OpenAI took a different tone: according to Chris Lehane, the company’s Head of Global Affairs, the time has come to work with Congress on mandatory national artificial intelligence safety requirements, calibrated to system capabilities.

The position is significant not because it suddenly turns a private company into a regulator, but because it makes explicit an issue that is now hard to ignore. As models become more capable, voluntary safety relies on the choices of the very companies competing to reach the market first. OpenAI also backs four California proposals concerning independent evaluations, standards for auditors, youth protection, and AI-enabled biological risks.

Regulating capabilities, not just companies

The most compelling principle is the idea of tying obligations to actual capabilities. Such a framework could avoid treating a small vertical application and a frontier model in the same way, focusing oversight and liability where the potential impact is greatest. Yet the hardest part remains: defining technical thresholds that do not become obsolete within a few months and establishing bodies capable of independently evaluating them.

There is also an obvious incentive problem. Large companies can absorb compliance costs that are far more burdensome for smaller competitors. Effective regulation must therefore reduce risks without inadvertently becoming a barrier to entry that benefits incumbents.

AI policy comes of age

The debate is shifting from broad principles to the concrete infrastructure of oversight: testing, auditors, incident reporting, liability, and public enforcement powers. This is where it will be decided whether safety will remain a corporate promise or become a verifiable condition for operating.

Sources