Direct comparison
5 Ways to Govern Frontier AI: CSET Compared
CSET compares five U.S. AI governance proposals on three structural questions: which risks matter, who is delegated, and whether the mechanisms would work.
Written and maintained by CASRAI Editorial Board
Last updated
Ask CASRAI · free to try
Ask about 5 Ways to Govern Frontier AI: CSET Compared
Ask your first 2 questions free below. Subscribers get 150 a day for $29 a month.
Ask CASRAI answers research-administration questions and cites the passages behind every claim. When our sources don't cover a question, it says so.
Answers draw on CASRAI's guides and dictionary plus the federal and funder documents we index: Federal Register, Grants.gov, Regulations.gov and UKRI.
Works on this site and inside Claude, Cursor and the AI tools you already use.
Everything CASRAI publishes — this page, the dictionary, the guides and the news — stays free to read, with no account and no card.
How do OpenAI's Approach to Frontier Risk, Zero Trust AI Governance (Civil Society), Frontier AI Regulation (Academia), SB-1047 (California), Mitigate AI-Enabled Extreme Risks (Federal) compare side by side?
The table below compares OpenAI's Approach to Frontier Risk, Zero Trust AI Governance (Civil Society), Frontier AI Regulation (Academia), SB-1047 (California), Mitigate AI-Enabled Extreme Risks (Federal) across 5 procurement-relevant dimensions, from origin and what it is through where it stands today (sept. 2026).
Side-by-side comparison
| Dimension | OpenAI's Approach to Frontier Risk | Zero Trust AI Governance (Civil Society) | Frontier AI Regulation (Academia) | SB-1047 (California) | Mitigate AI-Enabled Extreme Risks (Federal) |
|---|---|---|---|---|---|
| Origin and what it is | OpenAI's internal approach to frontier risk, published October 2023 in response to the UK AI Safety Summit's request for voluntary commitments. | Joint framework from three civil-society groups — the AI Now Institute, Accountable Tech, and the Electronic Privacy Information Center — published August 2023. | “Frontier AI Regulation: Managing Emerging Risks to Public Safety,” a preprint from 24 scholars across think tanks, universities, industry, and a multinational law firm, last revised November 2023. | California's Safe and Secure Innovation for Frontier Artificial Intelligence Models Act, introduced February 2024 by State Senator Scott Wiener; vetoed by Governor Newsom in September 2024. | “Framework to Mitigate AI-Enabled Extreme Risks,” a short congressional framework from Senators Romney, Reed, Moran, and King, unveiled April 2024. |
| Q1: Which risks matter, and who has primary oversight? | Catastrophic risk from frontier models; oversight sits almost entirely inside OpenAI itself. The only one of the five CSET flags as assuming industry, not government, should hold primary oversight. | Consumer-facing harms — discrimination, fraud, privacy, anticompetitive conduct — more than catastrophic risk; oversight sits with federal agencies (FTC and others) enforcing laws that already exist. | Severe risk to public safety from dangerous capabilities; oversight is government-led, through a regulator empowered to license and audit developers. | “Critical harm” (CBRN, mass-casualty cyberattacks, $500M+ in damages); oversight formally sits with the California Attorney General, with developers carrying civil liability for non-compliance. | CBRN risk specifically, framed as a national-security question; oversight goes to a new federal entity Congress would still have to create. |
| Q2: Who is delegated tasks, and can they do it? | OpenAI's own subteams (several since disbanded or renamed) plus an external red-teaming network — assumes the company itself has the internal capacity. | Federal agencies, Congress, and third-party auditors with full API/data access — assumes an independent auditing ecosystem that CSET notes is not yet mature. | AI ethics and safety experts, third-party auditors, and government regulators jointly convened to build and enforce standards — the widest delegation of the five. | State government agencies (including a new Board of Frontier Models), third-party auditors, and compute-cluster operators, each with a defined statutory role. | A new or repurposed oversight entity that does not yet exist, plus compute providers screening customers — the framework itself doesn't specify which. |
| Q3: Would the mechanisms actually work? | Leans on watermarking, content provenance, and preventing model-weight theft — techniques CSET notes are only partly mature and not independently verified at scale. | Leans on mandatory disclosure and independent audits rather than technical fixes; doesn't assume model-leakage prevention is solved, unlike three of the other four. | Leans on voluntary-then-mandatory safety standards plus licensing — the proposal CSET calls most explicit about its own preconditions (auditor resourcing, time for rigorous work). | Leans on a compute threshold as a proxy for risk, third-party audits, and a literal kill switch — the only one of the five assuming developers can fully shut a model down and compute providers can fully cut access. | Leans on compute-threshold reporting and customer screening, like SB-1047, but specifies no consequences for non-compliance — the shortest and least specific of the five. |
| Where it stands today (Sept. 2026) | Superseded in practice — OpenAI's Preparedness Framework has been updated since 2023, and the Superalignment team named in the original proposal has been disbanded. | Still a standing civil-society position paper; no legislative vehicle has adopted it directly. | Still an unadopted preprint; its three-pillar structure (standards, visibility, compliance) visibly influenced later state and EU proposals. | Dead as introduced — vetoed September 2024 — but CSET notes it predates and is “related to” SB 53, California's narrower transparency law that did pass in 2025. | The original authors, plus Senator Maggie Hassan, turned it into the Preserving American Dominance in AI Act; that bill has not passed. |
Common questions
Common questions about OpenAI's Approach to Frontier Risk vs Zero Trust AI Governance (Civil Society) vs Frontier AI Regulation (Academia) vs SB-1047 (California) vs Mitigate AI-Enabled Extreme Risks (Federal)
Did any of these five proposals actually become law?
+
Only indirectly. SB-1047 was vetoed in September 2024, though its themes carried into SB 53, the narrower California transparency law that did pass in 2025. The federal framework was later turned into the Preserving American Dominance in AI Act, which has not passed. OpenAI's proposal, the Zero Trust AI Governance framework, and the academic preprint were never legislative vehicles — they're a company policy, a civil-society position paper, and a research preprint, respectively.
How is this different from CASRAI's ten-jurisdiction AI law comparison?
+
Different format and different objects entirely. CASRAI's Frontier AI Law: 10 Jurisdictions Compared page lines up ten enacted or proposed statutes on the same three legal axes (binding vs. voluntary, centralized vs. sector-led regulator, tiered vs. uniform obligations). This page instead follows CSET's method: five stakeholder proposals — not all of them law, or even meant to become law — tested against three structural questions about risk, delegation, and mechanism effectiveness.
What's the one assumption literally all five proposals share?
+
That disclosures from AI companies about their own development are useful for governing AI — the only assumption in CSET's “which information or actions are useful” table held by all five, including OpenAI's proposal via its system-card commitment. Two other assumptions are shared by all five in a different table: that safety and risk-management frameworks or standards are necessary, and that information sharing between developers, users, and government actors is necessary.
Does NIKOLAI have a crosswalk row for CSET's report itself?
+
No, and this page doesn't claim one exists. Every NIKOLAI crosswalk row is a shadow mapping — CASRAI's own reading of how a lab's or regulator's own published framework lines up against a NIKOLAI element — and those only exist where an actual framework exists to map against (a Preparedness Framework, a Responsible Scaling Policy, statutory text like SB-1047 or SB 53). CSET is not that kind of source: it's a research organization's analytical framework for comparing other stakeholders' proposals, and it doesn't publish its own risk taxonomy or scope test as a framework a lab or regulator could adopt. There's nothing for a NIKOLAI crosswalk row to map against, so none exists.
What's the closest CASRAI-native parallel to CSET's “which risks matter” question?
+
NIKOLAI's own Risk domain element, in its N1 track (Actors, models and scope). It's CASRAI's independent, unendorsed reference dictionary asking a version of the same question natively: the element defines “the top-level category of catastrophic harm under which threat models, thresholds, and evaluations are grouped,” with CBRN, cyber offense, loss of control, and harmful manipulation as its controlled values — the same move as CSET's proposals committing (or not) to a bounded harm-category list rather than an undefined “catastrophic risk.” CASRAI's Who Counts as 'Frontier AI'? Eleven Scope Tests Compared guide is the closest parallel to the second half of that question — who has oversight, and under what if-then test does a framework apply at all.
Is RAND's model-weights report connected to this comparison?
+
Yes — it's the technical literature behind one of CSET's shared “which techniques are effective” assumptions. RAND's Securing AI Model Weights: Preventing Theft and Misuse of Frontier Models (Nevo, Lahav, Karpur, Bar-On, Bradley, and Alstott; May 30, 2024) catalogs 38 attack vectors against model weights and defines the five security levels that CASRAI's own NIKOLAI Security Level guide uses as its anchor. Note for anyone re-checking this citation: rand.org returns HTTP 403 to a default, non-browser fetch — that's a server-side block on the request type, not evidence the report doesn't exist. Fetched with a standard browser user-agent, the page resolves normally and confirms the title, all six authors, and the publication date exactly as cited here.
Going deeper







