The Midas Project alleges that OpenAI violated California’s Transparency in Frontier Artificial Intelligence Act, known as SB 53, at least three times in 2026. The allegations concern risk-tier disclosures for GPT-5.6 preview, GPT-5.6 and GPT-6 Astra. OpenAI disputes the claim, says it is confident in its compliance and points to the relationship between its two safety frameworks.
The dispute was reported on September 14, 2026, after the Midas Project dated its latest analysis September 10. It is a regulatory allegation, not a California government finding.
What the Midas Project alleges
The Midas Project says OpenAI did not publish the risk tiers that its Frontier Governance Framework describes for GPT-5.6 preview, GPT-5.6 and GPT-6 Astra. The framework reportedly uses three levels, from Tier 1 through Tier 3, with different safeguards attached to each level.
The watchdog’s allegation covers four risk categories:
- Cyber offense
- Chemical, biological, radiological and nuclear risks
- Harmful manipulation
- Loss of control
The last category is at the center of the dispute. In this context, loss of control concerns the possibility that an AI system could act beyond effective human supervision. The Midas Project argues that OpenAI’s public disclosures did not provide the relevant risk-tier assessments for the three models.
OpenAI says it invests in emerging-risk evaluations and safeguards and publishes findings through system cards and safety frameworks. The company also says it is confident in its compliance with SB 53.
What SB 53 requires
California Governor Gavin Newsom signed SB 53 on September 29, 2025. The law took effect at the beginning of 2026 and applies to covered frontier-AI developers.
SB 53 establishes obligations that include publishing governance frameworks, reporting certain critical safety incidents, protecting whistleblowers and maintaining civil penalties for noncompliance. The law was authored by California state senator Scott Wiener.
The central legal question is not simply whether OpenAI published a safety document. It is whether the company followed the commitments and disclosures required by the law and by the framework it published. The Midas Project says those obligations include carrying out the framework’s own risk-tier commitments. OpenAI presents its frameworks as complementary parts of its compliance approach.
The two OpenAI frameworks are not interchangeable
GPT-6 Astra’s reported cyber designation illustrates why the framework distinction matters. OpenAI classified Astra as “critical” for cyber risk under its separate Preparedness Framework. That label addresses cyber risk; it is not the same as a publicly disclosed loss-of-control tier under the Frontier Governance Framework.
| Framework | Role in the dispute | Risk categories or focus | GPT-6 Astra reference |
| Frontier Governance Framework | OpenAI framework that the Midas Project treats as relevant to SB 53 commitments | Cyber offense, CBRN risks, harmful manipulation and loss of control | The Midas Project alleges that the relevant public risk tier was missing for Astra |
| Preparedness Framework | OpenAI framework for managing serious advanced-AI risks | Includes the cyber-risk evaluation cited in the dispute | Astra was reported as “critical” for cyber risk |
OpenAI says the Preparedness Framework remains the foundation of its approach to serious advanced-AI risks, while the Frontier Governance Framework explains how those practices align with regulatory requirements. That position differs from the Midas Project’s reading of the company’s obligations, which treats the published commitments as requirements OpenAI must follow.
The model releases at the center of the dispute
The allegation follows three reported releases during 2026:
- GPT-5.6 preview: reported as released in June 2026.
- GPT-5.6: reported as released in July 2026.
- GPT-6 Astra: reported as launched on September 3, 2026.
The latest allegation also follows a separate dispute involving GPT-5.3-Codex. In February 2026, the Midas Project alleged that the model lacked safeguards required under OpenAI’s cyber-risk policy. OpenAI disputed that interpretation.
The chronology matters because SB 53 was already in effect when these model releases occurred. OpenAI published its Frontier Governance Framework in May 2026, before the three releases named in the latest allegation.
Why the Astra classification matters
A cyber-risk label answers a narrower question than a loss-of-control assessment. A model can receive a “critical” cyber designation under one framework while the regulatory dispute focuses on whether another framework required a separate assessment in a different category.
That is why GPT-6 Astra’s cyber classification does not, by itself, settle the Midas Project’s allegation. The two frameworks use different labels and address different risk dimensions. The disagreement is about how those commitments fit together under SB 53—and whether OpenAI met them for the models named by the watchdog.
The California law gives the state a civil-penalty mechanism for noncompliance. The current dispute, however, remains between the Midas Project’s allegation and OpenAI’s compliance position.