NEWS / SEP.2026
OpenAI proposes AI audits with a negotiated scope
On 22 September 2026, OpenAI published a proposed framework for external technical audits of AI models. The lab and the assessor would jointly define their scope, with findings that could be disclosed publicly or restricted to oversight bodies.

OpenAI proposes AI audits with a negotiated scope
On 22 September 2026, OpenAI published four priorities and seven principles for external technical assessments of AI models. The proposal, authored by Lama Ahmad, describes the assignments that private or nonprofit organizations could undertake and the conditions under which they would examine labs’ safety evidence.
OpenAI is in talks with several independent assessors, PYMNTS reports. These parties are not named in the framework. These discussions concern a proposed arrangement, with no announcement of newly signed contracts or findings from a new audit. The proposed assignments would last anywhere from a few weeks to several months and would generally be independent of a launch.
This framework for external assessments comes the day after OpenAI’s proposal for global standards to oversee AI R&D. The 21 September text on international standards addresses how they would be organized across labs and countries. The 22 September publication specifies the work expected of technical assessors.
From safety evidence to misalignment incidents
The first area concerns safety cases. These documents bring together verifiable claims and evidence intended to demonstrate that an activity’s risks are sufficiently controlled. They must also make their assumptions, uncertainties and residual risks explicit. Assessors could divide different parts of this review among themselves according to their expertise.
The second area concerns safeguards. OpenAI wants assessors to test protections against circumvention and dangerous actions, with partial access to internal mechanisms. For agents, the proposed tests cover access controls, environment isolation and systems capable of detecting or containing a harmful action, among other things.
The third area concerns reviewing capability and misalignment evaluations. Here, misalignment refers to behaviors that fall outside the intended objectives or oversight. The fourth envisages investigations into critical misalignment incidents to understand their causes and the associated failures.
OpenAI’s stated aim is to enable external experts to challenge its assumptions, identify risks that may have been missed and draw their own conclusions about the protections. For organizations deploying AI agents, precise findings could help identify the necessary fixes.
The lab and the assessor would choose the questions
The proposed process begins with a scope agreed between the lab and the assessor, as The Next Web explains. The safety claims to verify would be defined and preregistered before testing, specifying whether they come from the lab or the assessor.
Defining the claims in advance would make it harder to redefine them after the results. However, this preregistration does not require a public registry. A finding will need to be read in light of the risks, conditions and limitations associated with the initial questions.
Assessors should receive access proportionate to these questions, within legal, security and intellectual property constraints. They should make their methods, criteria and uncertainties explicit. Reports would distinguish direct observations from their interpretation and indicate what the assessment covers, as well as its exclusions.
The seven principles supplement these requirements with assessors’ expertise and independence, protection of sensitive information, findings that enable remediation, and responsible publication. Their value would be to make an audit interpretable by linking each finding to what was actually examined.
Public disclosure could be partial
The Next Web notes that the arrangement’s specific funding is not specified. Nevertheless, OpenAI calls for the disclosure of conflicts of interest, particularly financial ones, and stipulates that payment arrangements must not influence the findings.
A reasonable remediation period before publication is proposed where appropriate, with no set duration. The lab could also request the redaction of sensitive information. The text affirms the assessor’s editorial independence and describes no general veto right for the lab.
OpenAI also envisages confidential reports addressed to oversight bodies. Full public disclosure of findings and exclusions is therefore not guaranteed. The assessor could flag substantial redactions and explain their effect on its findings, without being required to publish everything.
In our view, common criteria and sufficiently detailed reports could make it easier to compare safety assurances when businesses and public administrations procure AI. Requirements for expertise, security and resources could also favor the best-resourced assessors. These consequences remain conditional.
A first public report under this framework would allow scrutiny of the assessor’s identity, disclosed funding, access actually obtained and excluded questions. Its significance would also depend on the remediation period, redactions and their impact on the findings, as well as any disagreements with the lab.