OpenAI Maps Frontier Safety Controls to California and EU Rules OpenAI published its Frontier Governance Framework on May 28, 2026, mapping its safety and security practices to California's Transparency in Frontier Artificial Intelligence Act and the European Union's Code of Practice for General-Purpose AI. The framework covers risk assessment, reporting, security, and incident response, but it is a governance disclosure, not a certification of compliance or a replacement for deployers' own controls. OpenAI Maps Frontier Safety Controls to California and EU Rules OpenAI published its Frontier Governance Framework on May 28, 2026, mapping parts of its model-safety program to California's Transparency in Frontier Artificial Intelligence Act and the EU AI Act's general-purpose AI Code of Practice. The document covers risk assessment, reporting, security and incident response, but it describes OpenAI's governance processes rather than certifying compliance or replacing deployers' own controls. OpenAI published a Frontier Governance Framework on May 28, 2026, to explain how its safety and security practices map to two regulatory regimes: California's Transparency in Frontier Artificial Intelligence Act and the European Union's Code of Practice for General-Purpose AI. This was a disclosure and governance document, not a new model release or a regulator's finding that OpenAI complies. From internal policy to regulatory evidence OpenAI says its existing Preparedness Framework remains the foundation for identifying and managing severe risks from advanced models. The newer document translates relevant parts of that approach into a public framework focused on legal obligations. It addresses risk assessment and mitigation for cyber offense, chemical, biological, radiological and nuclear risks, harmful manipulation and loss of control, along with model reporting, security-risk management, incident response, external expert input and policy updates. The framework also allocates responsibility between OpenAI entities. OpenAI OpCo LLC is identified for California compliance, while OpenAI Ireland Limited is identified as the provider responsible for obligations tied to the EU Code of Practice for models with systemic risk. Those statements explain OpenAI's intended governance structure; regulators still determine whether conduct satisfies applicable law. What practitioners should take from it The document makes provider-side controls easier to inspect during procurement and model-risk reviews. Teams can ask whether a vendor publishes capability assessments, incident procedures, security ownership and update commitments instead of relying only on general safety language. It does not transfer an enterprise deployer's responsibilities to the model provider. Organizations using OpenAI systems still need controls for approved use cases, sensitive data, access, logging, human oversight and incident handling. The practical value of the framework is therefore as evidence to evaluate and monitor, not as a substitute for an organization's own AI governance or as proof that every deployed system is compliant. Key Points - 1OpenAI published the Frontier Governance Framework on May 28, 2026, mapping its practices to California's frontier-AI law and the EU GPAI Code of Practice. - 2The framework covers severe-risk assessment, model reporting, security management, incident response, external input and responsibility across OpenAI entities. - 3It is a provider-side governance disclosure, not regulatory certification and not a replacement for deployer controls over data, access, logging, oversight and incidents. Scoring Rationale The framework gives procurement, risk and compliance teams concrete provider-side governance evidence across two major regimes, while its practical impact depends on implementation and regulatory assessment rather than publication alone. Sources Primary source and supporting public references used for this report. Practice interview problems based on real data 1,625 SQL & Python problems across 15 industry datasets — the exact type of data you work with. Try 250 free problems /problems