AI Governance Library

Frontier Governance Framework

OpenAI's Frontier Governance Framework sets out how the company identifies, analyses and mitigates systemic risks from frontier models, and how it meets requirements under California's TFAIA and the EU General-Purpose AI Code of Practice.
Cover of Frontier Governance Framework

⚑ Quick Summary

Published by OpenAI, this Frontier Governance Framework (FGF) documents how the company assesses and mitigates systemic risks from its most capable models and how it meets baseline legal requirements under two regimes: California's Transparency in Frontier AI Act (TFAIA), under which the document serves as OpenAI's Frontier AI Framework, and the EU's General-Purpose AI Code of Practice, under which it summarises OpenAI's Safety & Security Framework for models covered by Regulation (EU) 2024/1689 (the EU AI Act).

The framework defines systemic risk to include foreseeable and material risks of severe harm, including risks that a model will materially contribute to greater than 50 fatalities or $1 billion of property damages or losses arising from a single incident. It sets out structured processes for risk identification and analysis, acceptance determinations, tier systems for cyber offense, CBRN, harmful manipulation and loss of control, safety mitigations, critical safety incident identification and response, security risk management, model reporting, input from external experts, allocation of responsibility for risk management, and framework change management.

Its main deliverable is a documented process: results are recorded in a Safety and Security Model Report (called Transparency Reports under the TFAIA) and published through system cards, with updates determined at least every six months for the most capable frontier models and a Framework Assessment completed at least every 12 months.

🧩 What’s Covered

The framework is organised into seven sections, with two subsections each in Sections 2 and 7.

  • Introduction (Section 1): states the legal baseline the FGF is designed to meet, naming the TFAIA Frontend AI Framework role and the EU General-Purpose AI Code of Practice role, the coverage of frontier models and "general-purpose models with systemic risk", the relationship to OpenAI's Preparedness Framework (PF), and references to ISO 42001, the NIST AI Risk Management Framework and Responsible Scaling Policies proposed by METR.
  • Systemic risk identification and analysis (2.1–2.2): defines systemic risk, sets the severe-harm threshold (greater than 50 fatalities or $1 billion of property damages or losses from a single incident), and lists four risk categories with descriptions: cyber offense, CBRN, harmful manipulation and loss of control. Risk analysis spans the model lifecycle and draws on evaluations, external research, expert consultation and post-release monitoring.
  • Risk acceptance determination and risk tiers (2.3–2.4): describes residual risk, safety margins, pre-deployment evaluations and capability thresholds, then sets out Tier 1–3 descriptions and examples for cyber offense, CBRN and loss of control, plus an explicitly exploratory note on harmful manipulation.
  • Safety mitigations and critical safety incident response (2.5–2.6): covers mitigation tailored to capability and distribution strategy, the AI Safety Incident Response Plan (AIRP) and a Cybersecurity Incident Response Plan, detection and triage channels, investigation, mitigation and response, and external reporting within required deadlines.
  • Security risk management (Section 3): describes an Information Security and Privacy Program aligned with ISO 27001, 27017, 27018 and 27701 and supported by SOC 2 Type II, with mitigations for unreleased model weights, interface access, insider threats and security assurance.
  • Model reporting (Section 4): explains the Safety and Security Model Report, six-monthly update determinations, three stated conditions under which an update is not considered necessary, and light touch evaluations at trigger points.
  • External experts and responsibility allocation (Sections 5–6): covers third-party evaluators, stress testing, expert opinions to the Safety Advisory Group, and assigns TFAIA compliance for US covered models to OpenAI OpCo LLC and EU provider responsibility to OpenAI Ireland Limited, whose board exercises systemic risk oversight.
  • Framework change management (Section 7): sets the update and approval process, reviewers who may propose updates, board oversight for material updates, a published changelog within 30 days, and a Framework Assessment at least every 12 months.

πŸ’‘ Why it matters?

For anyone who must show how frontier model risks are governed, the document is a worked example of translating statutory duties into operating processes: named risk categories, capability tiers, an incident response plan, board-level oversight and a published update cycle. It places legal baselines (TFAIA, the EU Code of Practice) alongside voluntary practice through the Preparedness Framework, and uses ISO 42001, the NIST AI Risk Management Framework and ISO 27001-series certification as reference points. Compliance teams, auditors and providers can compare what a major developer says it produces, when it reports and who is accountable.

❓ What’s Missing

The document as extracted carries no publication date, version number or effective date, so it cannot be placed in time or compared against later versions. Several areas are openly unfinished: harmful manipulation has no published tier descriptions, nuclear and radiological risks are not covered by a tier system, and loss-of-control tiers other than AI self-improvement are described as exploratory and subject to substantial change. No numeric capability thresholds are given, and the document notes that passing evaluations does not establish that a threshold has been reached. Process language is often permissive ("may solicit", "may from time to time"), and the appendices it cites sit outside the document.

πŸ‘₯ Best For

Compliance and legal teams mapping frontier model obligations under California's TFAIA or the EU AI Act and its Code of Practice; risk and safety staff designing tier-based capability assessment, acceptance and incident response processes; auditors and policy analysts comparing how a large developer documents systemic risk governance and accountability; and security teams reviewing provider controls.

πŸ“„ Source Details

Frontier Governance Framework, published by OpenAI. No individual authors are named. No publication year, version number, reference number or URL is printed in the extracted text, and the extraction carries no cover date or imprint page; the contents list runs Sections 1–7 with subsections 2.1–2.6 and 7.1–7.2. The document is in English and runs to 22 pages; the extracted text covers all 22 pages of the file, and page references follow the PDF pages rather than the printed folios.

About the author
Jakub Szarmach

AI Governance Library

Curated Library of AI Governance Resources

AI Governance Library

Great! You’ve successfully signed up.

Welcome back! You've successfully signed in.

You've successfully subscribed to AI Governance Library.

Success! Check your email for magic link to sign-in.

Success! Your billing info has been updated.

Your billing was not updated.