P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

OpenAI asks the US to lead global AI standards; the US already holds the ISO AI committee's secretariat

OpenAI wants a US-led, CAISI-centred effort to write global standards for frontier AI and recursive self-improvement. The gap it names is real, but the post sets no timetable, no convenor and no route into the bodies whose AI standards already carry legal weight.

By Parminder Kumar Sharma · · 15 min read

Editorial illustration for the briefing: OpenAI asks the US to lead global AI standards; the US already holds the ISO AI committee's secretariat

The committee OpenAI wants the US to lead is already run from Washington

OpenAI's post Building standards for the next phase of AI, published on 21 September 2026, argues that "the United States should lead an effort" to develop global technical standards for frontier AI, including for recursive self-improvement (RSI), the process in which AI systems do more of the work of building their successors. The one formal international standards body the post names is ISO, and its link points to the page for ISO/IEC JTC 1/SC 42, the joint ISO and IEC subcommittee on artificial intelligence.

That page lists the subcommittee's secretariat as ANSI (United States). SC 42 was created in 2017, has 44 published standards and 49 under development, and has 59 participating and 25 observing member countries, 84 in total. The management system standard most UK organisations know, ISO/IEC 42001:2023, is one of its products. In the formal machinery of international AI standards, the United States already holds the administrative chair.

That fact does not make OpenAI's proposal redundant, and it does not show bad faith. It establishes something narrower: the post is not asking for the US to take a seat it lacks. It is asking for a different route, through the Center for AI Standards and Innovation (CAISI) inside NIST and a network of government AI institutes, to standards on a subject the existing bodies have not addressed: how to measure, oversee and report on AI that increasingly builds AI. What the post does not establish is who would convene that effort, on what timetable, with what money, or how its output would reach the formal bodies whose standards carry legal weight in Europe and in procurement.

What OpenAI actually proposes

The post is about 1,700 words (1,678 by our count of the body text) and uses the word "standard" or "standards" 18 times. It sets out one goal and two "essential" aspects, while saying it expects the concept "to evolve substantially over time". Read in full, it asks for the following.

1. A mechanism for complementary national and international frontier standards. The suggested route is to "leverage the emerging network of AI safety institutes" to facilitate standard setting "through the CAISI and national industry bodies". The focus would be frontier models and developers "as measured by capability benchmarks", and benefit-risk management for automated AI research, including RSI. The resulting standards would cover capability measurement and evaluation, risk assessment and "safeguard sufficiency".

2. Common measurements and incident reporting protocols. OpenAI lists three candidate areas: evaluation of RSI-relevant progress, including "the amount of autonomous research happening within an AI company"; human oversight of automated AI research, including which processes should trigger immediate human review; and incident classification, tracking, reporting and response, "such as common incident severity levels and reporting thresholds".

Alongside the standards, it wants critical infrastructure operators and governments to establish "secure channels of communication" to share national security concerns, vulnerabilities and threats, and it calls US-China dialogue in these areas "a positive step".

It also draws limits. The standards "would not be licenses, mandatory prerelease review, or approval requirements for AI models", and national governments "would decide whether and how to incorporate these standards into their own legal systems". They should be developed transparently, consult open-weight and closed developers, academics and independent experts, and not "advantage particular companies, countries, or business models". The post says the challenges apply to open and closed models alike, and that any lab pursuing automated AI research "must take accountability for doing so safely".

What the post asks of government, and what it leaves out. Source: OpenAI, Building standards for the next phase of AI, 21 September 2026, read in full.

TopicStated in the postNot stated
Who leadsThe United States, working with other countriesWhich US office convenes it, or how other countries join
VehicleAI institute network, CAISI and national industry bodiesHow output enters ISO/IEC SC 42 or CEN-CENELEC JTC 21
ScopeFrontier models by capability benchmark; RSIWhich benchmarks, or what threshold makes a model frontier
Legal forceNot licences or mandatory prerelease reviewAny enforcement, audit or conformity route
IncidentsCommon severity levels and reporting thresholdsWho reports, to whom, and how fast
TimetableNoneAny date, milestone or budget
ChinaUS-China dialogue would be positiveWhether China takes part in writing the standards

Bloomberg's report of the same day framed the post as OpenAI pushing the US to lead an effort to set global AI standards. We could not read the full Bloomberg article, which is paywalled; a search-engine summary of the article also says the post addressed access to compute capacity. The post we read does not use the word "compute", so we have not repeated that point.

Which bodies it names, and how closely they match the record

The post lists countries whose AI safety institutes it would build on: Australia, Canada, Germany, France, Kenya, Japan, Korea, Singapore, India and the United Kingdom. It then says the US can build on CAISI's creation of the International Network for Advanced AI Measurement, Evaluation, and Science in 2024.

The network's own members do not match that list. NIST's February 2026 announcement names ten: Australia, Canada, the European Union, France, Japan, Kenya, the Republic of Korea, Singapore, the United Kingdom and the United States. The UK AI Security Institute's blog gives the same ten, confirms that the body was "formerly the International Network of AI Safety Institutes", and says the UK holds the role of Network Coordinator in 2026. Germany and India appear in OpenAI's list but not in the network's membership; the European Union is a member but is not in OpenAI's list.

OpenAI's list of AI safety institutes compared with the network's published membership. Sources: OpenAI post; NIST, 13 February 2026; UK AISI, 12 February 2026.

Country or blocIn OpenAI's listNetwork member
Australia, Canada, France, Japan, Kenya, Korea, Singapore, UKYesYes
United StatesImplied as leaderYes
European UnionNoYes
GermanyYesNot listed
IndiaYesNot listed
ChinaNoNot listed

This is more than pedantry. The network renamed itself away from "safety" and now describes its focus as the science of AI evaluation. The UK's own body is the AI Security Institute, which is how NIST's CAISI page names it. OpenAI's post still calls the whole set "AI safety institutes". A comforting label is not a mandate: the network's published description is evaluation science, not standard setting, and the output NIST announced in February 2026 was a list of key practices and open questions on automated evaluations.

The other bodies the post names are the Frontier Model Forum, the Agentic AI Foundation, the Open Secure AI Alliance and the Appia Foundation. None of them is a formal standards development organisation in the ISO, IEC, CEN or ETSI sense. They are industry groups. OpenAI's own June 2026 post on Appia says OpenAI helped found Appia, the Frontier Model Forum and the Agentic AI Foundation. The Open Secure AI Alliance, launched by NVIDIA on 27 July 2026, lists more than 100 inaugural partners; our reading of that list found neither OpenAI nor Anthropic in it.

Two routes to AI standards. Left, OpenAI's proposal: a US-led effort through CAISI and the AI institute network, with industry groups, producing voluntary standards on capability measurement, RSI oversight and incident severity that governments may adopt. Right, existing bodies: ISO/IEC SC 42 with an ANSI secretariat and ISO/IEC 42001, and CEN-CENELEC JTC 21 whose standards give presumption of conformity once cited in the Official Journal. A band lists what the post does not state.
Drawn from OpenAI's post of 21 September 2026, the ISO SC 42 committee page, CEN-CENELEC and JTC 21 pages, and the AI Standards Hub.

What already exists, and what it does not cover

UK readers do not start from a blank page. Four pieces of existing work matter most, and each has a different legal status.

Existing AI standards work compared with OpenAI's proposal. Sources: ISO, NIST, CEN-CENELEC, JTC 21, EUR-Lex Regulation (EU) 2026/1744, AI Standards Hub. The last column is our reading of each scope statement.

WorkStatus on the recordAddresses RSI or frontier autonomy
ISO/IEC 42001:2023 (SC 42)Published December 2023; certifiable AI management system requirements; 51 pagesNot in its stated scope
NIST AI RMF 1.0Released 26 January 2023; voluntary; being revised under the White House AI Action PlanNot in its stated scope
CEN-CENELEC JTC 21Set up 1 June 2021; EN 18286 quality management expected July 2026; risk management prEN 18228 at enquiry to 30 July 2026Not in its stated scope
UK AI Standards HubTuring, BSI and NPL partnership backed by DSIT; tracks standards and supported ETSI EN 304 223 on AI cyber securityNot in its stated scope

The fair reading is that OpenAI has found a real gap. ISO/IEC 42001 specifies requirements for an AI management system within an organisation. The NIST AI RMF is a voluntary framework for managing AI risk to individuals, organisations and society. The European harmonised standards from JTC 21 exist to give companies a legal presumption of conformity with the AI Act's requirements for high-risk systems, covering risk management, transparency, human oversight, cybersecurity and quality assurance. None of their scope statements mentions recursive self-improvement, the share of research done autonomously inside a lab, or what automated research should trigger human review. That is inference from published scopes, not from reading every clause of every standard, but it is consistent across all four.

The European record is also a warning about speed. JTC 21 was established on 1 June 2021. Its July 2026 update described EN 18286 on quality management as the first expected publication, with risk management and cybersecurity drafts still at public enquiry until 30 July 2026. The EU then amended its own law. Regulation (EU) 2026/1744, the Digital Omnibus on AI, published in the Official Journal on 24 July 2026, moved high-risk obligations for Annex III systems from 2 August 2026 to 2 December 2027, a delay of 487 days, and for Annex I systems to 2 August 2028. Its recitals cite "the delayed availability of standards" as a reason.

So a well-resourced bloc with a legal deadline took just over five years to produce its first harmonised AI standard, and still missed the date its own law set. OpenAI's post argues that RSI could speed up AI progress sharply. It offers no timetable, and consensus standards bodies are not built for speed. That tension is the most important thing the post leaves unaddressed.

Timeline from 2017 to 2028: SC 42 created 2017; JTC 21 June 2021; NIST AI RMF January 2023; ISO/IEC 42001 December 2023; AI institute network November 2024; OpenAI blueprint June 2026; EN 18286 expected July 2026; Digital Omnibus 24 July 2026; OpenAI post 21 September 2026; state visit 24 September 2026; EU high-risk dates 2 December 2027 and 2 August 2028. JTC 21 took just over five years; the post sets no timetable.
Dates from ISO, CEN-CENELEC, NIST, UK AISI, OpenAI, JTC 21, EUR-Lex and the White House schedule as reported in our US-China briefing.

OpenAI's commercial interest, stated plainly

Separating the method from any accusation matters here. OpenAI's argument for standards is coherent: fragmented national evaluations and incident definitions make evidence hard to compare, and standards give outsiders "a visible set of principles" that do not depend on any one lab's practices. Those are good reasons. It is still a company proposing rules for its own industry, and four features of the proposal line up with its interests.

It seeds the standards with its own documents. The post offers OpenAI's research acceleration report as "an initial contribution" to measuring autonomous research, and its misalignment reporting framework as "an early contribution" to incident classification. When we examined that framework last week, we found no published clock for reporting, and six reports that came 38 to 153 days after discovery. A standard that starts from a company's own framework tends to inherit its choices.

It favours venues it helped build. OpenAI's June post on Appia says OpenAI helped found Appia, the Frontier Model Forum and the Agentic AI Foundation, and takes part in SC 42 and the NIST-led AI consortium. Most of the non-government bodies the post names are ones OpenAI co-founded. Anthropic, which makes the tool used to research this piece, is also a Frontier Model Forum founder, so the same point applies to it.

It keeps international standards voluntary while seeking a single national rulebook. The standards would not be licences or mandatory prerelease review. OpenAI's own June 2026 blueprint for a US federal framework, which the post links to, goes further at home: once CAISI has the capacity, it says policymakers should "require the most capable frontier models to undergo a CAISI evaluation before public release", and should "preempt state laws that seek to regulate the same frontier safety risks". Put together, the position is mandatory evaluation by one US federal body, fewer state regimes, and voluntary standards abroad that each country chooses whether to adopt. That may be sound policy, but it is also the regime a US frontier lab would find easiest to comply with.

It scopes "frontier" by capability benchmarks. That confines the heaviest obligations to a small number of developers, which is defensible on risk grounds and also shapes who writes the rules. The post's own safeguard, that standards must not advantage particular companies or make it harder for new entrants and open-weight developers to compete, is welcome. It contains no mechanism to enforce it.

Where this meets the US-China talks

OpenAI calls US-China dialogue "a positive step" and says upcoming talks come "at an opportune time". Today we reported that after the 20 September consultations in New York, only Washington's account mentions a proposed notification mechanism for national security level AI incidents; Xinhua's readout gives AI one 14-character clause and names no mechanism. The state visit is on 24 September.

OpenAI's secure channels idea and the US proposal share a premise: governments need a trusted route to share AI security concerns. The proposal has a structural gap, though. The standards would be written through a network that does not include China, led by a body whose NIST page lists evaluations of models from Chinese developers, including GLM-5.3 from Z.ai, which NIST describes as PRC-based, DeepSeek V4, and a joint assessment with the UK of Kimi K3. OpenAI says the challenges apply equally to open-weight models, and several of the open-weight models CAISI has assessed come from Chinese developers. A global standard on RSI and incident thresholds that the main open-weight competitor has no part in writing would be a standard for the US and its partners. The post does not say how it would be anything more.

What changes for UK organisations

Today, nothing binding. The post is a policy proposal with no timetable, and no government has adopted it. The UK does hold relevant roles: it is the network's 2026 coordinator, BSI represents the UK in international standardisation, and the AI Standards Hub is a DSIT-backed partnership between the Alan Turing Institute, BSI and the National Physical Laboratory. The Hub also supported ETSI EN 304 223, a European baseline for AI cyber security whose journey, the Hub says, began with the UK's AI Cyber Security Code of Practice, and which has since been adopted as a European Norm.

For a UK security or GRC lead, the useful point is that frontier RSI standards, if they ever arrive, would govern the few labs building frontier models. Your obligations come from the standards and laws that already exist: ISO/IEC 42001 if you certify, the NIST AI RMF if your US customers expect it, ETSI EN 304 223 for AI cyber security, and the AI Act's revised dates if you place systems on the EU market. The part of OpenAI's proposal that could reach you sooner is incident severity levels and reporting thresholds, because suppliers will start referring to them in contracts once any draft exists.

Take this with you

What to do, in the order worth doing it

  • Do not record an OpenAI or US-led frontier standard as a control, mitigation or assurance source in any risk register; none exists yet.
  • Map your AI governance to ISO/IEC 42001 and the NIST AI RMF now, and note that the AI RMF is being revised.
  • If you place AI systems on the EU market, reset plans to the new dates: 2 December 2027 for Annex III high-risk systems and 2 August 2028 for Annex I.
  • Track EN 18286 on quality management and prEN 18228 on risk management through BSI, and check whether each has been cited in the Official Journal before relying on it.
  • Review ETSI EN 304 223 against your AI cyber security controls.
  • Write your own AI incident severity levels and reporting thresholds, including for supplier model incidents, rather than waiting for a frontier protocol.
  • In supplier due diligence, ask frontier AI providers which published standards they certify to today and ask for the certificate scope, not a statement of alignment with emerging standards.
  • If you want a say in any standard this proposal produces, register with the AI Standards Hub and your BSI mirror committee now.

The question that exposes the gap

OpenAI is right that nobody has yet written down what good practice looks like for AI that builds AI, and right that incident definitions which conflict across countries help nobody. The United States also already holds the secretariat of the ISO committee that writes AI standards, has a NIST framework in revision and has an evaluation body. What the post does not supply is the missing piece: a timetable, a convenor, and a route into the bodies whose standards carry legal weight.

So the question for OpenAI, and for any government tempted to adopt its framing, is this: if the standard is written through a US body chartered to secure US dominance of AI standards, starts from OpenAI's own frameworks and excludes the country behind many of the open-weight models it is meant to cover, what makes it global, and who, apart from the labs, will be able to check that it is being met?

Sources

  1. PrimaryBuilding standards for the next phase of AI, 21 September 2026: full text read in browser; proposals, named bodies, limits, word countsOpenAIaccessed 2026-09-21
  2. PrimaryHelping build shared standards for advanced AI, 23 June 2026: OpenAI's standards memberships and founding rolesOpenAIaccessed 2026-09-21
  3. PrimaryDemocratic Governance of Frontier AI: a blueprint for a federal framework, 2 June 2026: mandatory CAISI evaluation and state preemptionOpenAIaccessed 2026-09-21
  4. PrimaryISO/IEC JTC 1/SC 42 committee page: secretariat, creation date, standards and member countsISOaccessed 2026-09-21
  5. PrimaryISO/IEC 42001:2023 standard page: scope, publication date, pages, committeeISOaccessed 2026-09-21
  6. PrimaryAI Risk Management Framework page: release date, voluntary status, revision under the AI Action PlanNISTaccessed 2026-09-21
  7. PrimaryCenter for AI Standards and Innovation page: functions including international standards remit and model evaluationsNISTaccessed 2026-09-21
  8. PrimaryInternational Network for Advanced AI Measurement, Evaluation, and Science, 13 February 2026: founding date and ten membersNISTaccessed 2026-09-21
  9. PrimaryNetwork blog, 12 February 2026: former name, members, UK coordinator role in 2026UK AI Security Instituteaccessed 2026-09-21
  10. PrimaryJTC 21 artificial intelligence page: establishment date, role in harmonised standards and presumption of conformityCEN-CENELECaccessed 2026-09-21
  11. PrimarySignificant milestone for European AI standardization, 9 July 2026: EN 18286 expected publication and enquiry datesCEN-CENELEC JTC 21accessed 2026-09-21
  12. PrimaryRegulation (EU) 2026/1744, Digital Omnibus on AI: new high-risk application dates and reasonsEUR-Lexaccessed 2026-09-21
  13. PrimaryAbout the AI Standards Hub: partners, DSIT support, missionAI Standards Hubaccessed 2026-09-21
  14. PrimaryWorking towards a European baseline for secure AI: EN 304 223, and its adoption as a European NormAI Standards Hubaccessed 2026-09-21
  15. PrimaryFrontier Model Forum site: founding membersFrontier Model Forumaccessed 2026-09-21
  16. PrimaryOpen Secure AI Alliance announcement, 27 July 2026: inaugural partner listNVIDIAaccessed 2026-09-21
  17. PrimaryOur briefing on the 20 September US-China talks and the proposed AI incident notification mechanismpk-sharma.comaccessed 2026-09-21
  18. Reported byOpenAI pushes US to lead effort to set global standards for AI, 21 September 2026: paywalled, read via search summary onlyBloombergaccessed 2026-09-21

Share this briefing

Know someone who owns this problem? Send it to them.

Related briefings

The briefing, in your inbox

Practitioner analysis of cyber and AI security news. No vendor noise.

One email per briefing. Unsubscribe any time.