OpenAI’s Push on Regulation Could Change How CX Teams Buy and Govern AI

AI regulation could change how CX teams select, deploy and govern AI, with vendor transparency, security and risk controls under scrutiny

6
Security, Privacy & ComplianceNews

Published: August 24, 2026

Nicole Willing

AI regulation is becoming a procurement and governance issue for customer experience teams, as leading model developers are starting to engage with regulation more directly, but they also want a say in how those rules are written.

OpenAI Global Affairs has suggested that lawmakers should amend California’s Transparency in Frontier AI Act (SB 53), offering a glimpse of what could be coming. The company is backing a model of “compatible” state laws that could eventually form the basis of a national framework, while calling for requirements around risk assessment, transparency, incident reporting and cybersecurity.

For CX organizations adopting AI across customer service, sales and employee support, those rules could influence which models they buy, what vendors must disclose and how businesses monitor AI once it is in use. As regulation takes shape, CX leaders will need to understand not only what an AI platform can do, but how its provider manages the risks around it.

OpenAI Pushes for a More Consistent AI Regulatory Framework

“States are playing an important role in building a national framework for frontier AI safety,” OpenAI wrote.

“Our approach—which we call ‘reverse federalism’—is based on a simple idea: as Congress continues to debate federal legislation, states can move in a compatible direction around core protections that can ultimately become the foundation for a national standard.”

The message marks a shift from earlier industry arguments that warned state-level AI rules could slow innovation, create compliance headaches, or encourage companies to develop elsewhere.

OpenAI’s position is more pragmatic, preferring rules that are consistent across jurisdictions and focused on practices that frontier AI developers already say they follow.

OpenAI praised California’s SB 53, which came into effect on January 1, calling it “an important foundation for frontier AI safety in California” and part of “a common framework emerging across leading states.”

The company said the law’s “requirements around risk assessment, transparency, incident reporting and security reflect core protections we believe should apply consistently to developers of the most capable AI models.”

Consistency is becoming a central concern for the major AI developers.

Companies operating across the U.S. could face a complex compliance environment with different state requirements covering model testing, safety disclosures, incident reporting, cybersecurity and audits. OpenAI’s preferred approach of “reverse federalism” would see states move first, but broadly in the same direction, giving Congress a framework it could eventually formalize nationally.

The company also argues that harmonization should leave room for safety requirements to evolve.

“Harmonization does not mean freezing safety requirements in place,” OpenAI wrote. “Frontier AI is moving quickly, and policymakers and developers should be able to incorporate lessons from real-world events into stronger safeguards that are part of a common framework.”

Security and Incident Reporting Move Up the Agenda

The discussion is becoming increasingly operational, with regulators looking at how companies monitor models during training and evaluation, detect dangerous behavior, respond to incidents and protect the systems and environments used to develop advanced models.

OpenAI has called for amendments to SB 53 covering some of those areas. It said California should strengthen the legislation by expanding safeguards, including “requiring monitoring of frontier models under training or evaluation for potential serious incidents, namely conduct that could bypass a third party’s security controls and compromise the third party’s confidential information.”

It also supports “strengthening cybersecurity protections throughout the model-development lifecycle, specifically to prevent frontier models from circumventing internal security controls.”

The emphasis on monitoring, cybersecurity and incident response points to a broader change in AI governance. The conversation is becoming focused on the controls surrounding models and the evidence companies can provide when something goes wrong.

Kfir Fleischer, VP of Cyber Research & Product at Dream, told CX Today that recent incidents, such as OpenAI models breaching Hugging Face, have reinforced the need for that approach.

“The safest models in the world spent the last few weeks explaining how and why they got into networks nobody authorized, completely unintentionally. Those are the models with sophisticated supervision.”

“The threat facing government surfaces is even larger from open-weight models without professional supervision,” Fleischer said. “Zero trust for governments isn’t a judgment on model owners. It’s a decision about what governments refuse to depend on. Countries must assume every credential is stolen and assume every model is jailbroken. Then they must build a sovereign national AI stack that holds.”

The security angle is becoming harder for policymakers to separate from the wider AI debate. If advanced models can identify or exploit cybersecurity weaknesses, lawmakers will expect developers to demonstrate how they detect incidents, contain risks and investigate what happened.

Anthropic Backs Regulation While Warning Against Federal Delays

OpenAI is not alone in supporting regulation for frontier AI. Anthropic has also backed state-level rules while arguing that federal legislation remains preferable.

Anthropic endorsed SB 53 in September 2025, stating: “We’ve long advocated for thoughtful AI regulation and our support for this bill comes after careful consideration of the lessons learned from California’s previous attempt at AI regulation.”

The company acknowledged the tension between state and federal regulation, while warning against waiting indefinitely for Washington to act.

“While we believe that frontier AI safety is best addressed at the federal level instead of a patchwork of state regulations, powerful AI advancements won’t wait for consensus in Washington,” Anthropic wrote.

For the major model developers, a single federal framework would be easier to manage than dozens of different state regimes, but slow federal action leaves states with room to establish their own rules.

Anthropic opted to engage with California’s proposal. It praised SB 53’s “trust but verify” approach and highlighted requirements for developers to publish safety frameworks, issue transparency reports, report critical safety incidents, protect whistleblowers and face penalties when they fail to meet their own commitments.

“These requirements would formalize practices that Anthropic and many other frontier AI companies already follow,” the company said.

There is a commercial dimension to this position. Companies that already invest in safety frameworks, system cards, red-teaming and responsible scaling policies may find compliance easier when competitors face the same baseline requirements.

“Without it, labs with increasingly powerful models could face growing incentives to dial back their own safety and disclosure programs in order to compete,” Anthropic stated.

“But with SB 53, developers can compete while ensuring they remain transparent about AI capabilities that pose risks to public safety, creating a level playing field where disclosure is mandatory, not optional.”

The debate now extends beyond whether companies should disclose risks. It also raises questions about how much authority regulators should have over potentially dangerous systems.

OpenAI has focused heavily on harmonization, national standards and avoiding “mission creep”, arguing that state laws should concentrate on core protections while highly technical national security decisions remain with federal authorities.

Anthropic has taken a somewhat broader position in its policy work, arguing that “transparency alone is no longer sufficient” and that governments may need legal authority to “block or deter dangerous deployments.”

That difference could become important as policymakers decide how far AI regulation should go. Requirements for disclosure and risk management are one thing. Giving governments powers to restrict specific models or deployments is another.

For now, there is considerable overlap between the major labs’ positions. They support risk assessments, incident reporting, cybersecurity controls, independent evaluation and whistleblower protections. They also want rules focused on the most capable models and enough flexibility for safety practices to evolve as the technology changes.

At the same time, the companies are pushing back against broad state rules, highly prescriptive technical requirements and obligations that could complicate deployment or access for enterprise and government customers.

OpenAI’s SB 53 intervention is also an attempt to influence what a future national framework could look like.

What CX Teams Should Ask AI Vendors About Regulation

For enterprises and customer experience teams adopting frontier AI, governance will increasingly form part of vendor due diligence.

Buyers should ask model providers how they conduct risk assessments, whether they publish safety reports or system cards, how models are monitored during evaluation and deployment, what constitutes a reportable incident and what controls protect model weights, training environments and customer data.

AI developers are becoming more receptive to regulation while making clear what they want that regulation to look like. As regulation develops, CX leaders will also need to understand how changes to model governance could affect automated decisions, agent-assist tools, customer-facing agents and the data those systems can access.

Security and Compliance
Featured

Share This Post