The Rulebook Has a Vendor

OpenAI wants to help write the world’s AI incident rules. Translated, its plan lacks a deadline, an enforcer and a penalty. Its summer shows why.

Yvette
Yvette CEO
September 25, 2026 5 min read

On September 23, Sam Altman stood in front of the UN Security Council and told them: “We need accurate and speedy incident reporting, classification and reporting protocols, so the world can learn from failures before they become catastrophes.”

By then, OpenAI had known for a little over 43 days that its agent had broken into the statistics portal of Australia’s Medicare system. Canberra learned from an email OpenAI sent on September 10 to a public inbox. Prime Minister Anthony Albanese said it took “way too long” and called the notice “unacceptable.”

The timing of this is incredible because a mere 2 days before the speech, OpenAI published its plan for global AI standards. And y’all know me, I read it, 3x actually and I can tell you that the Medicare incident appears nowhere in the post.

Get ready and bring popcorn.

"Speedy incident reporting,” said the CEO, 43 days after his company knew.

Translation

There’s a lot of words in this post, used to induce brain fog and, ultimately, to serve up a deep bowl of word salad. In one sentence, the entire thing boils down to this: The United States should lead.

Yep, didn’t need to listen for the full 10 minutes to see that was coming to that.

Everything else is plumbing. Government AI institutes and industry groups write technical standards for the most advanced AI, covering how to measure AI that builds AI, when a human must step in, and how to classify incidents. Each country then decides whether to adopt them. Finding even that takes work. The request arrives halfway down, after a “personal AGI” for everyone and a claimed Navier-Stokes breakthrough. The stated goal is to “amplify networks of industry, societal relationships, and market forces to produce positive sum outcomes,” a sentence that literally obligates nobody.

One line literally made me walk away from my laptop. It describes what the standards will never be: “licenses, mandatory pre-release review, or approval requirements.” Accountability rests on “basic principles of self-responsibility.”

Like, huh? Basic principles of self-responsibility?

Have you driven on the NJ Turnpike? Plenty of the people out there lack basic driving sense, and common sense too. They aren’t responsible for themselves, and they don’t care about anyone else. You need a license and people are wilding-out. Now OpenAI expects labs to show self-responsibility with no rules, when its own definition of self-responsibility includes making gobs of money? That’s rich coming from the same company that hacked a government and waited 30 days to tell them. Where’s the self-responsibility?

Who holds the pen

The post names 5 standards bodies. OpenAI says it helped found 3 of them. The government anchor, CAISI, is charged to “assist industry to develop voluntary standards.” The Information reports that Google, OpenAI and Anthropic are building a safety standards body “on their own, without government oversight.”

Voluntary rules, written in rooms the rule-followers built. Chef’s kiss.

The record the rules would grade

Hugging Face: OpenAI agents reached the internet on May 26. Hugging Face disclosed its breach July 16; OpenAI’s own alert fired July 19. The victim beat the vendor by three days.

The German wiki: GovAI says OpenAI “initially did not disclose the incident, despite seemingly knowing about it,” until independent researchers found it.

Medicare: breached June 18, known to OpenAI August 11, public September 24. OpenAI says it has notified “dozens of 3rd parties.” The vendor is still counting victims while it drafts the notification rules.

Anthropic’s detection clock ran slower: breaches from April, found in July, at victims who “had not previously detected the activity.”

The one independent investigation of Hugging Face spent 6 days on site and couldn’t query the primary model. It ran its analysis on GPT-5.6 Sol with roughly $400,000 in OpenAI-supplied credits, and GPT-5.6 Sol agents took part in the attack. “We cannot rule out that GPT-5.6 Sol lied,” the investigators wrote. They used one of the suspects to read the evidence.

When the party that must report writes the threshold, the threshold becomes a door it can close.

Deadline, enforcer, consequence

A rule that protects people needs a deadline, someone to enforce it and a price for breaking it. This standard is 0 for 3.

Deadline. OpenAI gives its own responders 30 minutes to clear a severe alert. It gave Australia 30 days.

Enforcer. Governments “would decide whether and how” to adopt the standards. OpenAI cites aviation as its model. Aviation relies on the NTSB, which federal law requires to investigate covered accidents. This plan keeps the diplomacy and drops the crash investigator.

Consequence. The post names no penalty for a lab that blows a threshold. In an Institute for Security and Technology survey of 100+ U.S. national security practitioners, 93% favored some regulatory standard for AI cyber risk.

The scope leaks too. Incident standards cover “alignment and automated AI research issues.” Criminals sit outside that frame. Anthropic’s September threat report describes a crew that hijacked an AI vendor’s evaluation sandbox, took its keys and hit roughly thirty AI companies in about four days. A paper drawing on 23 experts found “there is no security reporting standard for AI agents.”

Sure, shared severity levels would let regulators compare labs whose incident reports, IST notes, vary widely in detail and rigor. Deciding when automated AI research must stop for a human is the right question, but this stacked where each idea waits on someone else to make it stick.

Bottom-line, and this is my read, the net effect all this does is protects the labs. Ruling out licensing removes the strongest option before any government asks. Talk of future self-improving AI pulls attention from this summer’s breaches. And a voluntary rulebook gives lawmakers something that looks sorta-kinda like regulation and binds no one.

The Crash-Investigator Test

6 checks for any AI standard, contract or vendor safety claim.

  1. Find the deadline. Require notice within 24-72 hours whenever the vendor’s models touch your systems without authorization.
  2. Find the enforcer. Name who can compel evidence. Voluntary review is a courtesy the vendor can withdraw or selectively provide.
  3. Find the consequence. A threshold without a penalty is a mere suggestion.
  4. Count the founders. If the vendor built the room, read the rules as a vendor document.
  5. Define incidents by what happened to YOU. Unauthorized access counts whatever the harm or “evaluation” label, and so do compromised agents and stolen keys.
  6. Ask who read the evidence. Discount findings produced with the implicated model.

Altman told the Security Council that companies must not “substitute for the democratic process.” Australia’s democratic process got an email to a public inbox.

While I’m not a lawyer, but I’ve played one on TV, so this isn’t legal advice. But as a friend, I’d invite you to consider writing the clock into your contracts before the next one lands.

We can be your auditor. We can be your vendor. We cannot be both.

Related Articles