OpenAI is staring down accusations that it violated California’s landmark AI safety law multiple times this year, including with the rollout of its newest and most powerful model. The allegations come from the Midas Project, a nonprofit watchdog, and they center on a particularly awkward omission: risk assessments for the exact kind of danger OpenAI itself has been warning the world about.
The Midas Project’s analysis, dated September 10, 2026, claims OpenAI failed to publish a required loss-of-control risk assessment for its GPT-5.6 and GPT-6 Astra models. That’s the scenario where an AI system effectively slips its leash and operates beyond human oversight.
What SB 53 requires and where OpenAI allegedly fell short
California’s SB 53, formally known as the Transparency in Frontier Artificial Intelligence Act, was signed into law in September 2025 and took effect on January 1, 2026. The statute requires frontier AI developers to publish safety frameworks that address risks with potentially catastrophic outcomes. That includes scenarios involving significant loss of human life, major financial damage, and, critically, loss-of-control events where AI systems act autonomously in harmful ways.
OpenAI developed its own Frontier Governance Framework in alignment with SB 53’s requirements. That framework explicitly calls for a loss-of-control risk tier to be included in the system card for every covered model.
According to the Midas Project, the system cards for both GPT-5.6 and GPT-6 Astra omit this loss-of-control risk tier entirely. The watchdog also flagged a prior incident from February 2026 involving the GPT-5.3-Codex model, which allegedly failed to implement necessary misalignment safeguards. That brings the total to at least three alleged violations in a single year.
GPT-6 Astra, released on September 3, 2026, carries a “Critical” cybersecurity capability tier, the highest classification in OpenAI’s own framework. Models at that level are supposed to trigger heightened development safeguards. The Midas Project’s core argument is that a model deemed critical for cybersecurity risk should absolutely be accompanied by a thorough loss-of-control assessment, not released without one.
OpenAI pushes back
OpenAI has denied the allegations, asserting strict compliance with SB 53. The company has expressed confidence in the testing and governance processes it applies to its models, though the specific counterarguments to the Midas Project’s analysis remain general rather than point-by-point.
The Midas Project describes itself as “working to ensure that AI benefits everybody, not just the companies developing it.” The specificity of its allegations, referencing OpenAI’s own framework language and mapping it against the published system cards, gives the claims more substance than a typical advocacy broadside.
What’s at stake for the AI industry
If the allegations hold up, OpenAI could face civil penalties under SB 53. California’s law was designed with enforcement teeth, and a finding against the world’s most prominent AI company would set a significant precedent for how seriously regulators intend to police the industry.
Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

1 week ago
74





English (US) ·