GCS Regulatory Briefing
AI Governance & Frontier Regulation

OpenAI Asked Parliament to Regulate OpenAI

G
Jonathan Garzon
Founder & CEO, Garzon Cyber Solutions
14 September 2026 · 8 min read
GCS Regulatory Briefing cover: OpenAI Asked Parliament to Regulate OpenAI. Dark brand panel with the headline in white and red, a standfirst explaining that OpenAI told UK lawmakers to legislate for frontier labs while sparing smaller firms, and four stat chips: 14 September the date of the evidence session, zero enforcement powers at the AI Security Institute, 27 million pounds committed to the Alignment Project, and three models withheld at a government's request in June.

On Monday 14 September, OpenAI's head of policy in Europe told a committee of MPs and peers that the United Kingdom should legislate now for the handful of companies building the most advanced AI systems. That includes OpenAI. The company's position, as Tom Duff Gordon put it to the committee and as reported by The Guardian, is that the government should use the current political window rather than wait, and that the rules should fall on frontier labs rather than on smaller firms building products on top of existing models.

It is an unusual thing for a company to ask for, and it is being read as a technology firm inviting its own regulation. That reading is not wrong. It is just incomplete, and the incomplete part is the one that matters to anybody running a business that uses AI rather than building it.

14 Sep
OpenAI tells UK lawmakers to legislate now for frontier labs
0
Enforcement powers held by the UK AI Security Institute
£27m+
Committed to the Institute's Alignment Project, including roughly £5.6m from OpenAI
3
Models withheld from public release at a government's request in June

What was actually said

The committee is a parliamentary human rights committee, and it was taking evidence on whether existing law is ready for advanced AI. Its own view, stated the same day, is that it is not. The risks it named are worth writing down because they are not abstract: public face scanning, sexually explicit deepfakes, workplace monitoring, and decisions that affect people's rights taken without meaningful human oversight.

Against that backdrop OpenAI argued for a threshold. Regulate the small number of organisations training frontier models. Do not impose the same burden on a startup building a customer service tool on top of somebody else's model. The distinction is defensible on its face. A company spending hundreds of millions on a training run is not in the same risk category as one calling an API.

It is also, unavoidably, a company proposing the boundaries of the category it sits in. That is not an accusation of bad faith. It is a structural observation, and it is the reason the argument deserves reading twice.

Why the carve out is not the relief it sounds like

The natural response from a UK business is that frontier rules are somebody else's problem. Most organisations are not training frontier models. Under OpenAI's proposal they would sit outside the heaviest obligations entirely.

That is true and it changes very little, for a reason that the committee's own list makes obvious. Every risk it named is a deployer risk, not a lab risk. Face scanning is done by the organisation that installs the camera. Workplace monitoring is done by the employer. A decision affecting someone's rights without human oversight is made by the firm that put the model in the loop, not by the firm that trained it.

None of that is governed by frontier AI rules. It is governed by law that already exists: UK GDPR, the Data Protection Act 2018, the Equality Act, employment law, and the sector rules of whoever regulates you. Being out of scope of a frontier AI Act does not move a single one of those duties, and nobody at that committee suggested it would.

So the honest summary is uncomfortable. The lightest touch outcome available to a UK deployer is that frontier labs get regulated and the deployer's own obligations stay exactly where they are. There is no version of this where the burden goes down.

What frontier rules actually push downstream

The framework OpenAI has been describing, in the UK and in its parallel arguments in the United States, covers testing standards, independent assessment, cybersecurity protection for model weights, and incident reporting.

Read that as a buyer rather than as a lab. Every one of those four becomes something a customer can ask for, and therefore something a procurement team eventually does ask for. Testing standards become evidence requests. Independent assessment becomes an attestation you are expected to hold. Incident reporting becomes a notification clause in a contract, and then a line in a supplier questionnaire, and then a question your own regulator asks about your supply chain.

This is the same pattern the Cyber Resilience Act is running in software and DORA is running in financial services. Obligations land on a small number of large suppliers, and then propagate outwards as contractual and evidential demands on everyone who buys from them. The organisations that feel it first are not the labs. They are the mid sized firms with no AI governance function and a growing list of AI features they did not deliberately procure.

GCS infographic titled Who The Rules Reach. Three stacked panels. The frontier lab carries testing standards, independent assessment, security of model weights and incident reporting. The supplier inherits all four and passes them on as contract clauses and attestations. The deployer gets none of the above and every duty it already had. A red panel beneath lists what remains yours whatever the Act says: UK GDPR and the Data Protection Act 2018, employment and equality law, and your own sector regulator.
Obligations land on a small number of large suppliers, then propagate outwards as contractual and evidential demands. Source: Garzon Cyber Solutions assessment, September 2026.

The risk that belongs on the register today

There is a second story running underneath the regulatory one, and it has had far less attention.

In June, OpenAI limited the release of its GPT-5.6 models at the request of the US administration, offering them first to a small group of partners whose participation had been shared with the government. The company was plain about how it felt: "We don't believe this kind of government access process should become the long-term default." It complied anyway, and it complied with a request rather than a legally binding order. Around the same period, export controls on Anthropic's most capable models led that company to cut off almost all customer access to them.

The operational lesson is separate from the politics. Model availability is now a variable that governments can move, at short notice, for reasons that have nothing to do with you and through a process you have no standing in. If a critical workflow in your business depends on one model from one provider, you have a continuity exposure that no contract with that provider can fix, because the provider is not the one making the decision.

Very few risk registers carry that. Most carry AI as a data protection risk and an accuracy risk. Concentration and availability belong next to them, and they are the ones that would actually stop work tomorrow.

What leaders should do now

  • Separate what you build from what you buy, and write the list down. Frontier rules, when they arrive, will apply to a category. You cannot tell whether you are in it if nobody can say which models the business trains, tunes, or merely calls. Most organisations discover at this point that the answer differs by department.
  • Inventory the AI that arrived inside products you already owned. Procured AI is usually governed. The exposure sits in features switched on inside a CRM, a service desk or an HR platform, because nobody treated those as an AI decision and nobody owns the list.
  • Put concentration and availability on the risk register. Name the models that a revenue generating or customer facing process depends on. For each, answer two questions: what happens if it is withdrawn at two weeks' notice, and how long would switching take. If nobody can answer, that is the finding.
  • Get ahead of the evidence requests rather than waiting for them. Testing, independent assessment and incident reporting are coming to you as questionnaire lines and contract clauses well before they arrive as law. Firms that can answer from a maintained control set will close deals that firms scrambling each time will lose.
  • Check the deployer duties you already have. Automated decision making, monitoring and profiling are governed today by UK GDPR and employment law. No future AI Act will relieve them, and a regulator asking about them will not wait for one.
GCS infographic titled Five Decisions Available This Quarter. A numbered checklist. One, separate what you build from what you buy and write the list down. Two, inventory the AI that arrived inside products you already owned. Three, put concentration and availability on the risk register. Four, get ahead of the evidence requests. Five, check the deployer duties you already have.
Five decisions an executive can take before any legislation is published. Garzon Cyber Solutions, September 2026.

Three questions for the board

  • Which AI models does a revenue generating process in this business depend on, and what happens if one of them becomes unavailable at two weeks' notice for reasons outside our control?
  • Where in this organisation does a model influence a decision about a person, whether a customer, a candidate or an employee, and who is accountable for that decision today under the law we are already subject to?
  • If a customer asked us next month to evidence how we test, assess and report incidents on the AI in our product, what could we send them without starting a project?

The strategic takeaway

The instinct on reading that a frontier lab has asked to be regulated is to file it under somebody else's problem. It is the wrong instinct, and the committee sitting opposite OpenAI that day made the case better than any vendor could. The harms that most concerned it were not caused by training runs. They were caused by ordinary organisations deploying capable systems into decisions about people, under laws that already apply and are already enforceable.

Regulating the frontier is a reasonable thing to do and it is coming. It will not make the deployer's position easier, and the firms treating it as a reason to wait are spending the only cheap preparation time they will get.

Confidence note

Confirmed. That OpenAI's head of policy in Europe, Tom Duff Gordon, told a UK parliamentary human rights committee on 14 September 2026 that the government should legislate now for the most advanced AI developers, and that OpenAI's position is that rules should fall on frontier labs rather than smaller companies, as reported by The Guardian and TechBooky. That the committee warned existing law is not ready and named face scanning, explicit deepfakes, workplace monitoring and decisions affecting rights without proper human oversight. That the UK AI Security Institute tests advanced models and does not hold the enforcement powers of a full regulator. That OpenAI limited the release of its GPT-5.6 models in June 2026 at the US administration's request and stated it does not believe such a process should become the long-term default, per Cybersecurity Dive and OpenAI's own blog post. That export controls led Anthropic to cut off most customer access to its most capable models. That OpenAI and the UK Government signed a memorandum of understanding covering a technical information sharing programme with the AI Security Institute and security research collaboration, and that OpenAI committed roughly £5.6m to the Institute's Alignment Project, with total funding above £27m.

Assessed. That frontier obligations will propagate to deployers as contractual and questionnaire requirements is our assessment, drawn from the observed pattern under the Cyber Resilience Act and DORA. It is not something any UK body has stated as policy. The characterisation of model availability as a continuity risk is likewise our reading of the June episodes rather than a position taken by any of the companies involved.

Not known. Whether the UK government intends to legislate in this session, what any threshold would be, which body would enforce it, and whether the AI Security Institute would be given statutory powers. No bill has been published at the time of writing. The committee's report had not been issued when this was written, and the evidence session is not the same thing as its conclusions.

Which of your revenue processes would stop if one model became unavailable?

Garzon Cyber Solutions is built to put questions like this on the risk register with an owner, map the controls to what regulators, customers and insurers actually ask for, and place the people who keep the answer current. Cybersecurity, compliance and talent, delivered in that order, as one capability.

Start the Conversation →
Subscribe to GCS Insights
AI Governance Regulation Supplier Risk UK GDPR Board