AI regulation is becoming a procurement and governance issue for customer experience teams, as leading model developers are starting to engage with regulation more directly, but they also want a say in how those rules are written.
OpenAI Global Affairs has suggested that lawmakers should amend California's Transparency in Frontier AI Act (SB 53), offering a glimpse of what could be coming. The company is backing a model of “compatible” state laws that could eventually form the basis of a national framework, while calling for requirements around risk assessment, transparency, incident reporting and cybersecurity.
For CX organizations adopting AI across customer service, sales and employee support, those rules could influence which models they buy, what vendors must disclose and how businesses monitor AI once it is in use. As regulation takes shape, CX leaders will need to understand not only what an AI platform can do, but how its provider manages the risks around it.
OpenAI Pushes for a More Consistent AI Regulatory Framework
“States are playing an important role in building a national framework for frontier AI safety,” OpenAI wrote.
“Our approach—which we call ‘reverse federalism’—is based on a simple idea: as Congress continues to debate federal legislation, states can move in a compatible direction around core protections that can ultimately become the foundation for a national standard.”
The message marks a shift from earlier industry arguments that warned state-level AI rules could slow innovation, create compliance headaches, or encourage companies to develop elsewhere.
OpenAI’s position is more pragmatic, preferring rules that are consistent across jurisdictions and focused on practices that frontier AI developers already say they follow.
OpenAI praised California’s SB 53, which came into effect on January 1, calling it “an important foundation for frontier AI safety in California” and part of “a common framework emerging across leading states.”
The company said the law’s “requirements around risk assessment, transparency, incident reporting and security reflect core protections we believe should apply consistently to developers of the most capable AI models.”
Consistency is becoming a central concern for the major AI developers.
Companies operating across the U.S. could face a complex compliance environment with different state requirements covering model testing, safety disclosures, incident reporting, cybersecurity and audits. OpenAI’s preferred approach of “reverse federalism” would see states move first, but broadly in the same direction, giving Congress a framework it could eventually formalize nationally.
The company also argues that harmonization should leave room for safety requirements to evolve.
“Harmonization does not mean freezing safety requirements in place,” OpenAI wrote. “Frontier AI is moving quickly, and policymakers and developers should be able to incorporate lessons from real-world events into stronger safeguards that are part of a common framework.”
Security and Incident Reporting Move Up the Agenda
The discussion is becoming increasingly operational, with regulators looking at how companies monitor models during training and evaluation, detect dangerous behavior, respond to incidents and protect the systems and environments used to develop advanced models.
OpenAI has called for amendments to SB 53 covering some of those areas. It said California should strengthen the legislation by expanding safeguards, including “requiring monitoring of frontier models under training or evaluation for potential serious incidents, namely conduct that could bypass a third party’s security controls and compromise the third party’s confidential information.”
It also supports “strengthening cybersecurity protections throughout the model-development lifecycle, specifically to prevent frontier models from circumventing internal security controls.”
The emphasis on monitoring, cybersecurity and incident response points to a broader change in AI governance. The conversation is becoming focused on the controls surrounding models and the evidence companies can provide when something goes wrong.
Kfir Fleischer, VP of Cyber Research & Product at Dream, told CX Today that recent incidents, such as OpenAI models breaching Hugging Face, have reinforced the need for that approach.
“The safest models in the world spent the last few weeks explaining how and why they got into networks nobody authorized, completely unintentionally. Those are the models with sophisticated supervision.”
“The threat facing government surfaces is even larger from open-weight models without professional supervision,” Fleischer said. “Zero trust for governments isn’t a judgment on model owners. It’s a decision about what governments refuse to depend on. Countries must assume every credential is stolen and assume every model is jailbroken. Then they must build a sovereign national AI stack that holds.”
The security angle is becoming harder for policymakers to separate from the wider AI debate. If advanced models can identify or exploit cybersecurity weaknesses, lawmakers will expect developers to demonstrate how they detect incidents, contain risks and investigate what happened.
Anthropic Backs Regulation While Warning Against Federal Delays
OpenAI is not alone in supporting regulation for frontier AI. Anthropic has also backed state-level rules while arguing that federal legislation remains preferable.




