OpenAI may have violated California's AI safety law at least three times this year, according to a new analysis from the Midas Project, a nonprofit watchdog focused on AI safety. The claims center on the company's failure to publish required risk assessments for recent model releases, including GPT-5.6 preview in June, GPT-5.6 in July, and last week’s debut of GPT-6 Astra.
California's Transparency in Frontier AI Act, also known as SB 53, was signed into law in September 2025 and took effect at the start of this year. It requires the largest AI developers to publish safety frameworks explaining how they evaluate and mitigate AI risks, and to follow the policies they set for themselves. OpenAI published its Frontier Governance Framework in May, saying it would assess each new model across four categories: cyber offense, chemical, biological, radiological, and nuclear risk; harmful manipulation; and loss of control.
But since publishing that framework, OpenAI has not assigned risk tiers for any of its major releases, according to the Midas Project's analysis. The watchdog says there is no section in the system cards for those models that corresponds to the four categories laid out in the framework, and no mention of the tiers OpenAI said it would use. The penalty for not complying with the law can be up to $1 million per violation, scaled by severity.
OpenAI said it is 'confident' in its compliance with SB 53. A company spokesperson said the company invests heavily in evaluating emerging risks and developing safeguards, and publicly shares findings through its system cards and safety frameworks. OpenAI also said its Preparedness Framework remains the foundation of its approach to the most serious risks from advanced AI, and that the Frontier Governance Framework explains how those practices align with regulatory requirements.
The dispute highlights a basic problem for regulators and investors alike: a company cannot publish a rulebook and then treat it as optional. Capital rewards clear rules, and so does the public. When a firm says one thing in its governance documents and another in its release process, it invites scrutiny, fines, and the kind of regulatory risk that can slow product momentum and raise costs.
The market has already voted on AI ambition, but Washington and Sacramento are now asking a harder question: who is accountable when the systems grow more powerful than the paperwork that governs them? For free enterprise to keep its credibility, the answer has to be simple — the rules that are published must be the rules that are followed.


