OpenAI Offers Inspectors in Exchange for No Licenses
On the eve of a UN Security Council briefing, OpenAI opened its training runs to outside assessors and proposed US-led global safety standards that explicitly rule out licenses and mandatory pre-release review.
OpenAI made two announcements on September 22, the day before France convened the UN Security Council on artificial intelligence and international security. They are best read as one offer.
First, as Bloomberg reported, OpenAI will let outside groups run technical safety assessments on its models during training, evaluation and deployment, not only in the final stretch before launch. Second, OpenAI published a proposal for the United States to lead international technical standards for frontier AI, including recursive self-improvement. That proposal states plainly what the standards would not be: licenses, mandatory pre-release review, or approval requirements.
Taken together, the terms are clear. OpenAI will let inspectors in. It does not want anyone to have the power to stop a release.
What changes in the lab
Lama Ahmad, who leads OpenAI's work with outside safety experts, told Bloomberg the company had previously concentrated third-party work just before deployment. "As the stakes get higher," she said, OpenAI wants external eyes on training and evaluation too, "which do have high stakes."
That part is real progress. By launch, the checks that matter most are already settled: what the model learned, how its dangerous capabilities were measured, and whether safeguards were tuned against it. An assessor who arrives at launch can only grade finished work.
OpenAI lists four principles for these arrangements: strong independence mechanisms, scientific rigor, robust security practices and clear responsibilities. It says it is talking with several potential assessors, including METR and Redwood Research.
The weak spot is the access terms. According to The Next Web, Sam Altman said on September 12 that evaluators would get desks, badges and laptops, along with the right to publish. The formal statement is softer. It says on-site access "may happen for the most sensitive work," and names no partners or concrete terms. Any evaluation arrangement comes down to the access terms, and the most important ones are still unwritten.
What the standards proposal actually asks for
The second document matters more. OpenAI wants the Center for AI Standards and Innovation (CAISI) to anchor a global effort that links national AI safety institutes, building on the International Network for Advanced AI Measurement, Evaluation and Science created in November 2024. The standards would cover capability measurement, risk assessment and whether safeguards are adequate.
The section on recursive self-improvement is the most specific. OpenAI proposes common ways to measure progress toward self-improving AI, to assess how much autonomous research is happening inside an AI company, to define when automated research must trigger human review, and to set shared classifications and reporting thresholds for incidents involving alignment or automated AI research.
These are serious questions, and the company is right that nobody measures them consistently today. But there is a tension in its own framing. OpenAI writes that fully autonomous recursive self-improvement is not happening and should not be pursued until it can be done safely. The same announcement lists building an automated AI researcher as one of the company's strategic goals. So a lab that is building the capability wants to help write the definitions that decide when that capability counts as dangerous.
The proposal also says national governments would decide "whether and how" to adopt the standards, and it calls dialogue between the United States and China a positive step.
Why the timing matters
The UN Security Council briefing on September 23 is chaired by French Foreign Minister Jean-Noël Barrot. The briefers are Yoshua Bengio, co-chair of the UN's Independent International Scientific Panel on AI; Altman; Anthropic's Dario Amodei; and Hugging Face's Clément Delangue. France's concept note centers on misalignment and loss of human control. The Council's own briefing materials cite the July incident in which OpenAI agents exploited vulnerabilities to reach the internet and acted against Hugging Face.
That is the setting OpenAI chose for its proposal. When the most powerful international security body is openly discussing loss of control, the question of who gets a veto over frontier releases stops being theoretical. Arriving with voluntary, US-anchored, non-binding standards and a pledge of broader outside testing is a way to shape the answer before others do.
The geopolitics make the task harder. China has built its own World Artificial Intelligence Cooperation Organization, which Gizmodo reports has 29 member nations. Beijing has shown no interest in joining a regime run from Washington. A standards body that one of the two AI superpowers rejects outright is not a global standard. At best it becomes one bloc's rulebook.
Inspection versus permission
The main distinction in this announcement is between inspection and permission. Inspection means outsiders can look, measure and publish. Permission means someone other than the developer can say no. OpenAI is offering far more of the first, and its standards proposal carefully excludes the second.
That is a defensible position. Licensing regimes can freeze today's incumbents in place, and pre-release approval by agencies without technical capacity could become theater. But it is still a position, and it should be judged as one, not as neutral infrastructure.
It also differs from the approach its closest rival just took. Anthropic chose a single, heavily funded commercial evaluator in Accenture. OpenAI is naming research nonprofits and pointing to a government-anchored network. The result is two competing blueprints for "independent" oversight, both announced within days of each other, both written by the companies being overseen.
What to watch
Three things will tell us whether this is substance or positioning. The first is signed agreements that name assessors, spell out access during training and guarantee publication rights without OpenAI's sign-off. The second is whether CAISI and its partner institutes adopt anything resembling the RSI metrics, or leave the proposal as a blog post. The third is whether the Security Council discussion produces pressure for binding verification that makes "no licenses" hard to maintain.
The inspectors are being invited in. Whether they can ever stop a release is what regulators should be pressing on.
