OpenAI published its Frontier Governance Framework this week. On the surface it is a document about how OpenAI manages the safety of its own most capable AI systems. In practice, it is the clearest public picture yet of what formal AI risk management looks like when it is built to satisfy real legal requirements.
The two laws this document responds to are the EU AI Act's Code of Practice for general-purpose AI models, and California's Transparency in Frontier AI Act. The EU rules became enforceable in August 2025. Companies that sign on to the EU Code of Practice get a simpler path to proving compliance; those that do not sign still have to meet the underlying legal requirements, just without a clear roadmap. Non-compliance with the EU AI Act can mean fines up to €35 million or 7% of global annual revenue.
For most business operators reading this, the legal exposure lands at the AI vendor level, not directly on your organisation. But that gap is narrowing. Regulators now expect businesses that deploy AI to have documented oversight, clear records of what the AI can and cannot do, and defined human intervention points. The EU Act's Code of Practice explicitly requires AI providers to share documentation with the downstream businesses that integrate their models, so the compliance chain runs directly to you.
The framework defines what counts as a serious risk in concrete terms: an event causing more than 50 fatalities or $1 billion in property damage from a single incident. That threshold sounds extreme, and in everyday business use it is. But codifying it forces both OpenAI and any enterprise using its systems to build safeguards proportionate to real harm, not just theoretical discomfort.
The risk categories OpenAI has defined, covering cyber attacks, dangerous content in scientific domains, manipulation of human behaviour, and loss of human control over an AI system, are the same categories regulators are watching globally. For a company running automated customer communications, a claims-processing workflow, or a procurement analysis tool, the manipulation category is the one to watch. OpenAI's document acknowledges this area is still being worked out and relies mainly on monitoring after deployment rather than blocking things in advance. That is an honest position, but it also means the burden of checking outputs sits with the operator.
The security baseline OpenAI describes is worth benchmarking against your own AI vendor contracts. It includes independent third-party testing, a formal incident response plan, encryption of stored and transmitted data, multi-factor authentication, and annual reviews of the governance framework itself. These are not exotic requirements. They are the same controls your legal and IT teams would ask for from any critical supplier.
One detail that often gets lost in the broader AI governance conversation: the EU framework requires OpenAI to update its safety reports every six months for its most capable models, and immediately if a model's abilities change materially. For enterprises, this means your AI vendor's risk profile is not static. A tool that passed your procurement review last year may have different capabilities today.
The broader picture is that AI governance is moving from something companies do voluntarily to something regulators will check. In 2026, the question is not whether to build governance structures around your AI use, but whether the ones you have are documented well enough to withstand scrutiny. OpenAI publishing its internal framework gives compliance teams, procurement managers, and operations directors a concrete reference point for what that documentation should contain.