AI Policy · September 22, 2026 · 8 min read
OpenAI’s Global AI Standards Proposal Puts Self-Improvement and Oversight in Focus
OpenAI called for international standards and coordination on advanced AI risks, while acknowledging that voluntary proposals still need independent oversight.
Status: OpenAI’s proposal was published September 21, 2026 and reviewed September 22. It is a company policy proposal, not a binding standard or adopted international agreement.
The proposal
OpenAI has called for international cooperation on safety standards for advanced AI, including alignment research, common evaluation approaches and safeguards around highly automated AI research. Coverage of the proposal highlights recursive self-improvement: systems that might contribute to improving future systems with less direct human involvement.
OpenAI said fully autonomous recursive self-improvement is not happening today and should not be pursued unless it can be done safely. That caveat matters. The article should not imply that AI systems are already autonomously redesigning themselves beyond human control. The immediate policy question is how to evaluate emerging capabilities and preserve human oversight as research tools become more capable.
!Policy and technology discussion
Why shared standards are appealing
When developers use incompatible benchmarks and disclosure practices, governments, customers and researchers cannot compare risk claims easily. Shared technical standards could define what must be tested, how results are reported, what incidents require notification and how evaluations are independently reviewed.
OpenAI’s proposal points toward building on existing AI safety institutes rather than creating every function from scratch. That could reduce duplication and make it easier to exchange methods. However, national institutes differ in their mandates, resources and independence. Coordination requires transparent processes, not just a list of institutions.
Standards also do not automatically enforce themselves. They can be voluntary guidance, conditions in procurement contracts, regulatory obligations or components of international agreements. Each path has different incentives and legal force. A proposal becomes operational only when responsibilities, coverage and consequences are defined.
!Research team planning technical standards
Who writes the rules?
An AI developer has useful technical knowledge and a direct stake in how standards are designed. That is not a reason to exclude the company, but it does mean its recommendations should be identified as recommendations from an interested participant. The same scrutiny should apply to governments, standards bodies, researchers and civil society.
Credible standards need a process for public comment, conflicts disclosure, independent testing, revision and appeal. They should also include smaller developers and countries with less compute access. A framework built only around frontier labs could miss risks from deployment, integration and local context.
The hardest standards problem is deciding which claims are independently verifiable. A company may publish a benchmark result but withhold the test set, model configuration or failure cases. Full disclosure can create security or privacy harms, yet no disclosure can reduce evaluation to trust. Third-party access under controlled conditions is one possible compromise.
Recursive improvement: a capability to govern carefully
The term covers a spectrum. AI may assist developers with routine coding, help researchers analyze experiments or propose changes to training. That is different from a system independently choosing objectives, modifying critical parts of itself, deploying the changes and repeating the cycle without meaningful human control.
Policy should specify the capability being discussed. Vague claims about “self-improving AI” can generate fear without helping operators decide what to test. A practical evaluation would ask what actions the system can take, what resources it can access, whether changes are reversible, what approvals are required and whether a human can understand why the system changed.
Organizations can govern current AI-assisted research by separating recommendation from execution. Use restricted test environments, version control, signed approvals and independent evaluation before model changes reach production. Preserve the ability to roll back and compare against a stable baseline.
What an operational standard might contain
A useful standard could define capability tiers, test protocols, reporting thresholds, model-change documentation and minimum safeguards for automated research. It should include ordinary failure modes as well as extreme scenarios: data leakage, security misuse, unreliable tool execution, hidden delegation and failures of oversight.
Evaluation should be tied to deployment context. A model used for public drafting has different stakes from one given privileged access to research infrastructure. Standards should specify the relationship between test results and actual controls, instead of treating a benchmark score as a universal safety certification.
The NIST AI Risk Management Framework, OECD AI Principles and EU AI Act information provide existing points of reference. Their presence does not resolve every frontier risk; it shows why proposals should explain how new standards complement current governance rather than duplicate it.
What companies and buyers can do now
AI providers can publish clearer model cards, capability evaluations, incident processes and update histories. Buyers can require notice of material changes, security documentation, incident reporting and independent evaluation rights. Both can preserve escalation channels and ensure a human can stop a consequential workflow.
For AI agents, define whether the system can run code, access credentials, change files, create other agents or modify evaluation tasks. Record who approved those permissions. A capability test should be repeated after important model or tool changes.
Actus can monitor standards proposals and compare them with an organization’s AI inventory. Its role should be to surface possible changes for human review, not to determine legal obligations or certify a system as safe.
The central question
OpenAI’s proposal puts international cooperation and self-improvement risk into a current policy discussion. It is a starting position from one developer, not proof of consensus. The meaningful test is whether the proposal evolves into standards that are independently testable, publicly accountable and connected to enforceable responsibilities.
Sources and verification
- OpenAI: AI policy and standards proposals
- Coverage of OpenAI’s proposal and RSI position
- NIST AI Risk Management Framework
- OECD AI Principles
- European Commission: AI Act
A proposal is a starting point, not an international rule
OpenAI's proposal adds to a crowded and still unsettled debate about how countries should coordinate on advanced AI. The company can offer technical experience and a view of risks it sees from building models, but it is also a commercial actor with interests in how standards are written. That makes independent scrutiny central: a proposal should be assessed by what it asks governments and companies to do, how compliance would be evaluated, and who has authority to challenge the underlying evidence.
The language around self-improving systems can draw attention because it describes a pathway in which an AI system contributes to improving future systems. The term can cover very different degrees of automation, from code assistance in a research workflow to systems capable of planning and executing experiments with limited human intervention. Policymakers need operational definitions and measurable thresholds. Without them, a discussion may turn on dramatic labels rather than capability, access, and demonstrated performance.
International standards can help when they set common expectations for testing, incident reporting, documentation, and secure deployment. They can also become ineffective if they are purely voluntary, too vague to compare, or designed around one country's regulatory assumptions. Strong governance must specify how risk is assessed, how disagreements are recorded, and how a system changes oversight level when capabilities or use cases change.
What oversight could mean in practice
An effective oversight system might use several layers. Developers could evaluate models before release and publish summaries of the methods and limitations. Independent evaluators could test high-impact capabilities under controlled access. Regulators could require additional evidence for uses that affect safety or fundamental rights. Governments could coordinate incident reporting and response where a system's effects cross borders. These layers serve different purposes and should not be collapsed into a single certification stamp.
Evaluation itself is a moving target. Benchmarks can measure known tasks but fail to predict behavior in new environments. Red-team exercises can reveal weaknesses yet depend on the scenario and evaluator expertise. Real-world monitoring can catch issues after deployment but may expose users to harm if systems are launched before safeguards are ready. Standards should therefore require a combination of evidence and a plan to revisit decisions as systems change.
Independent assessment also depends on access. External reviewers need enough information to reproduce tests or challenge conclusions, while providers may have legitimate concerns about leaking model weights, personal data, or exploitable vulnerabilities. A credible framework can define tiers of access, confidentiality rules, and procedures for communicating serious findings. A provider's own safety report is useful evidence, but should not be treated as the final word on its own performance.
The hard part is governance of incentives
A global framework must account for the fact that companies face pressure to release products quickly, win customers, and attract investment. If safety obligations are vague or unevenly enforced, responsible providers may bear costs while competitors ignore them. Common reporting requirements and clear thresholds can reduce that imbalance, but only if authorities have enough technical capacity and firms cannot satisfy the rule through paperwork alone.
Smaller organizations and countries also need a workable route to compliance. If standards are costly, opaque, or shaped only by the largest labs, they could entrench existing market power. Shared testing infrastructure, open evaluation methods, and technical assistance can help broaden participation. At the same time, a framework should not assume that openness alone resolves risk: some information may need controlled access, and open publication of dangerous capabilities may create new misuse opportunities.
International coordination can begin with a limited set of concrete tasks rather than a grand treaty. Governments could agree on common incident categories, formats for reporting serious failures, and channels for urgent technical warnings. They could compare evaluation procedures for a defined class of high-capability systems and publish where methods diverge. Progress on these pieces would make it easier to decide whether more binding measures are justified.
Questions to ask of the proposal
Readers evaluating any corporate proposal should ask who defines the relevant risk thresholds, who audits compliance, and what happens when an assessment finds a serious gap. They should look for protections against conflicts of interest, a process for hearing affected communities, and an explicit account of costs and unintended effects. They should also separate governance of powerful general-purpose models from rules for ordinary software and narrow applications.
The timeline matters. A framework that applies only after a system has already been widely deployed may miss the period when safeguards are easiest to implement. Conversely, restrictions based on speculative capability claims can be hard to enforce and may block beneficial research without reducing the most serious risks. A tiered approach can tie obligations to demonstrated capability, deployment context, and access while allowing evidence to update the classification.
Finally, standards require institutions. An international statement is durable only if organizations have resources to maintain evaluation methods, review reports, coordinate across jurisdictions, and explain decisions. That means governance will involve technical agencies, lawmakers, standards bodies, researchers, and civil society—not only model developers and diplomatic representatives.
The proposal is best read as an invitation to debate the shape of oversight, not proof that global rules have been settled. Its value will depend on how precisely it defines the risks, whether independent experts can scrutinize its assumptions, and whether governments turn principles into measurable, fair procedures. Claims about legal effect or international consensus should wait for official texts and concrete follow-up.
Governance & Safety
Policy, evaluation, security and the control frameworks that make AI deployments defensible to auditors, customers and regulators.
Browse Governance & Safety