Sam Altman’s reported message to Washington is simple: do not make AI developers get government approval before releasing models. Reuters-syndicated coverage said the OpenAI chief planned to argue against model pre-approval during meetings with U.S. lawmakers. The policy question underneath is larger than one company’s lobbying line. It is whether frontier AI should be governed like a fast-moving software sector, a safety-critical technology, or something in between.

A pre-approval system would change the release cycle. Developers might need to submit safety evaluations, capability tests, security documentation, and mitigation plans before public deployment. Supporters would say that makes sense when models can write code, automate cyber tasks, influence users, or act through agents. Opponents would say that government review could slow beneficial tools, freeze smaller competitors out, and create a licensing regime captured by incumbents.

Altman’s position is not surprising. OpenAI depends on rapid product iteration, user feedback, and the ability to respond quickly to competitors. A mandatory approval queue could turn release timing into a political and bureaucratic process. It could also create uncertainty for enterprise customers waiting for new capabilities. In a global race, a U.S.-only approval regime might disadvantage domestic firms if foreign competitors face looser rules.

The counterargument is that voluntary commitments have limits. Frontier labs publish safety cards, run evaluations, and work with external testers, but the public often sees only the final claims. If a model causes meaningful harm, post-release fixes may arrive too late. Policymakers therefore ask whether some capabilities require evidence before deployment, especially when systems are integrated into critical infrastructure or national-security workflows.

Why builders care

NIST’s AI Risk Management Framework offers one middle path. It does not function as a licensing board, but it gives organizations a vocabulary for mapping, measuring, managing, and governing AI risks. Lawmakers could build on that kind of standard by requiring documentation, incident reporting, third-party audits, or post-deployment monitoring without requiring a blanket permission slip for every release.

The hardest design question is thresholding. A rule that covers every model update would be unworkable. A rule that covers only the most capable frontier systems might miss dangerous specialized models. Policymakers need criteria based on capability, deployment context, scale, autonomy, access to tools, and potential harm. Model size alone is a weak proxy because smaller systems can be powerful when connected to sensitive tools.