OpenAI publishes rules for outside testers. No tester is signed up yet
Ten days after Sam Altman said OpenAI would match Anthropic's embedded evaluators, OpenAI published four priorities and seven principles. The post names no partner and sets no access terms.
Outside testers can now look at OpenAI models during training. The fine print adds a window to fix things first.
On September 22, 2026, OpenAI published a framework titled Priorities and principles for effective third party assessments. It lets outside groups assess OpenAI models during training, evaluation and deployment, not only before a release. Bloomberg first reported it. It follows Dario Amodei's September 12 essay proposing embedded evaluators, and Sam Altman's reply on X the same day: "we will do the same." We covered that exchange when it happened.
The framework sets four priority areas, per The Next Web and Resultsense: safety cases from training through deployment; safeguard testing, including grey-box jailbreak testing and cyber and bio defenses; capability evaluations under OpenAI's Preparedness Framework; and independent investigation of misalignment incidents. The last one ties back to this summer, when METR and Redwood Research staff investigated the Hugging Face incident on site.
Seven principles and one open question
- Scope and claims agreed and pre-registered in advance.
- Access proportionate to the claims, within legal, security and IP limits.
- Methods and uncertainty explained.
- Conflicts of interest disclosed by assessors.
- Findings specific and actionable.
- Findings kept separate from interpretation.
- Publication handled responsibly.
The open question is publication. Resultsense reports that assessors keep editorial independence, but the lab gets a reasonable period to fix issues before findings go out and can request redactions, which Resultsense says makes the process closer to a commissioned audit. Forkast argues that a real independence guarantee is missing. The post names no partner and sets no access terms. Bloomberg reports OpenAI is in talks with METR and Redwood Research. Government testers such as the UK AI Security Institute are outside its scope. We could not check OpenAI's framework page directly, so this summary relies on those reports.
Amodei's version went further: evaluators with desks, badges and company laptops, access matching Anthropic's internal risk teams, and publication without Anthropic's editorial control, with redactions only for narrow categories such as security-sensitive material.
Why a build studio cares
This is the argument we have about every audit. Pre-registered scope is good practice: fix the scope before anyone opens the code, so the findings cannot quietly redraw it. A window to fix issues before a report goes out is normal in client work too. The difference is who the report is for. A buyer's audit serves the buyer, so the vendor does not get to edit it. An assessment the lab can delay and redact serves the lab first. The test for any audit, ours included: who can change the findings before the reader sees them, and does the reader know?
Next step: read The Next Web's summary and Amodei's essay side by side. If the only review of software you bought is one the vendor commissioned, write to us at hello@gattyworks.com.