Safety case is the phrase Sam Altman reached for on Tuesday 29 September when he was asked, again, when OpenAI will list its shares. “I don’t have a particular timeline in mind,” he told CNBC at the company’s DevDay conference. “Once we have run a few safety cases, once we feel like we understand how to contend with this next level of AI, and do it safely, I think we could.”
Hours later, in a question-and-answer session with reporters after his keynote, he said the same thing in plainer words. OpenAI has “got to be able to make confident safety claims” before it goes public, The Verge reported, and he does not want “additional pressure” from Wall Street while that work is unfinished.
Seventeen days earlier Altman had ruled out 2026. Now there is no date at all, only a condition. This article looks at that condition: what a safety case is, who in the industry already writes them, what OpenAI’s own published documents call the same thing, and how anyone outside the company could tell when the bar has been met.
Table of contents
- What Altman Said About the Safety Case and the IPO
- From “Not 2026” to No Date: How the Safety Case Replaced the Timetable
- What a Safety Case Actually Is
- Who Already Writes a Safety Case, and What OpenAI Calls It
- Why a Safety Case Is Harder to Make to Investors
- What an OpenAI Safety Case Would Need to Contain
- How to Tell Whether the Safety Case Has Been Made
- What the Safety Case Means for Organisations Using OpenAI
- Safety Case FAQ
- References
What Altman Said About the Safety Case and the IPO
Altman made the point three times in one day, to three audiences. The wording shifts, but the structure is the same each time: safety evidence first, listing second.
| Where | What he said | Source |
|---|---|---|
| CNBC interview, before the keynote | “Once we have run a few safety cases… I think we could” | CNBC transcript |
| Reporters’ Q&A, after the keynote | “We have got to be able to make confident safety claims” | The Verge |
| Same Q&A | Listing during “a new kind of safety requirement seems ill-advised” | The Verge |
| Same Q&A | Scale “without people debating what percentage chance we’re going to do all these bad things” | Financial Times, via Gizmodo |
The Wall Street argument
Altman’s stated worry is about incentives. Going public could mean having to “disappoint Wall Street supporters in the names of safety or whatever else,” he said. He would prefer not to “barrel, all guns blazing, towards an IPO.” On CNBC he put it as a matter of focus: “I really think this is the time to put safety and mission first.”
The hedge
He left himself room. “I think it’s great when companies are public,” he told reporters, adding: “I think it’s also kind of bad for the world if OpenAI waits too long to go public.” So the safety case is a gate, not a refusal. The question is who decides when it has opened.
What “pacing” means
Altman would not call any of this a slowdown. “Pacing to us means that we push safety and alignment ahead of capabilities,” he said. On CNBC he described the model cancelled the day before as “a little bit worse on a few of the evals we look at”, a decision taken in “the abundance of caution category”. We covered that decision in the GPT-6.1 Astra cancellation.
From "Not 2026" to No Date: How the Safety Case Replaced the Timetable
The statement matters because of what it replaced. For three months the question was which year. Now it is which document.
| Date | Statement | Condition attached |
|---|---|---|
| 8 June 2026 | OpenAI announces a confidential S-1 | “We have not decided on timing yet” |
| 19 August 2026 | CFO Sarah Friar: “will be a public company in 2027” | Sooner “if our business continues to inflect” |
| 12 September 2026 | Altman to Fortune: “I would say not 2026” | Safety and alignment work |
| 29 September 2026 | Altman: no particular timeline | “A few safety cases” and “confident safety claims” |
The first three rows are from our report on the OpenAI IPO delay. The fourth is new, and it is different in kind. A year can be missed. A condition that the company defines, measures and judges for itself cannot.
What the delay costs
Waiting is not free. OpenAI’s $122 billion round in March valued it at $852 billion, and Amazon’s $50 billion commitment included $35 billion contingent on an IPO or on OpenAI reaching AGI, FinanceFeeds reported. Rival Anthropic is still heading for a listing, which AFP says could come as early as November. Elon Musk’s SpaceX, which owns xAI, listed in June in what The Verge calls the biggest IPO in history.
What a Safety Case Actually Is
The term is not Altman’s invention, and it has a precise meaning in engineering.
The engineering definition
The UK Ministry of Defence’s Defence Standard 00-56 defines a safety case as “a structured argument, supported by a body of evidence, that provides a compelling, comprehensible, and valid case that a system is safe for a given application in a given environment.” The idea comes from industries where failure kills people. A 2024 paper from the Centre for the Governance of AI notes that safety cases “are already common in other safety-critical industries such as aviation and nuclear power.”
Three words in that definition do the work. It is an argument, so it can be challenged. It rests on evidence, so it can be checked. And it applies to a given environment, so it expires when the system or its use changes.
The AI version
The UK’s AI Security Institute, then called the AI Safety Institute, adopted the term in August 2024. In a post by Geoffrey Irving it defined the idea for AI as “a structured argument that an AI system is safe within a particular training or deployment context.” The institute’s stated interest was in “risks from loss of control and autonomy”, which is the category the recent incidents fall into.
| Source | Date | How it defines the term |
|---|---|---|
| Defence Standard 00-56 | Long-standing | A structured argument, supported by evidence, that a system is safe for a given application and environment |
| Clymer and others | March 2024 | “A structured rationale that AI systems are unlikely to cause a catastrophe” |
| UK AI Security Institute | August 2024 | A structured argument that a system is safe within a training or deployment context |
| Buhl and others | October 2024 | Reports that argue a system “is safe enough in a given operational context” |
| Google DeepMind | February 2025 | “An assessable argument showing how severe risks… have been minimised to an acceptable level” |
The four kinds of argument
The March 2024 paper, by Joshua Clymer and three co-authors, sorts the arguments a developer could make into four groups. The system is unable to cause a catastrophe. Control measures are strong enough to stop it. The system is trustworthy despite being capable of harm. Or, for far more powerful systems, the developer defers to credible AI advisers.
That list explains why Altman’s condition is hard. After Hugging Face, the first argument is no longer available to OpenAI for its most capable systems. It has to make the second or the third.
Who Already Writes a Safety Case, and What OpenAI Calls It
Two of OpenAI’s closest rivals use the term in their published frameworks. OpenAI, until this week, did not.
Anthropic
Anthropic’s Responsible Scaling Policy includes commitments that “take the form of affirmative safety cases, which are structured arguments that the system is safe to deploy in a given environment.” In 2024 its alignment team published three sketches of what such a case might contain for more capable systems: one built on interpretability, one on AI control and one on analysing the incentives a system faces. The authors were candid: “it is not yet obvious how to make a safety case to rule out certain threats that arise once AIs have sophisticated strategic abilities.”
Google DeepMind
Google DeepMind’s Frontier Safety Framework, updated in February 2025, says that when a model reaches a critical capability level “we will also develop a safety case”. It adds a governance step: “The appropriate corporate governance body then reviews the safety case, with general availability deployment occurring only if it is approved.”
OpenAI
We searched three OpenAI documents for the phrase: the Preparedness Framework version 2, dated 15 April 2025, the GPT-6 Astra system card and the GPT-6.1 Sol addendum. It appears in none of them.
That does not mean OpenAI has nothing equivalent. The Preparedness Framework uses two other names. A Capabilities Report records whether a model reaches a risk threshold, and a Safeguards Report sets out why the protections are adequate. A footnote says the approach “parallels Anthropic’s updated RSP”. An internal Safety Advisory Group reviews both and makes recommendations, which leadership “can approve or reject”, with oversight from the board’s Safety and Security Committee.
So when Altman told CNBC that “the safety cases that we now use have to be held to a higher and higher standard”, he was using the industry’s word for a process his company documents under different labels. The vocabulary changed on Tuesday. Whether the documents change with it is the thing to watch.
Why a Safety Case Is Harder to Make to Investors
A safety case written for an internal committee and one made to public shareholders are different objects. The second carries legal weight.
Disclosure law
Under section 11 of the US Securities Act of 1933, a company, its directors and its underwriters can be held liable for material misstatements or omissions in a registration statement. A sentence in an S-1 saying the company’s systems are under control is therefore not marketing. If it proves untrue, it can be the basis of a claim by anyone who bought the shares.
That is one way to read Altman’s phrase “confident safety claims”. A prospectus can list risks at length without asserting that any of them is contained.
What Anthropic did instead
Anthropic took the listing route without waiting. Its draft prospectus, as we reported in our analysis of the Anthropic prospectus, gives about 80 of its 261 pages to risk and 48 to the business.
Those are two answers to the same problem. Anthropic discloses the danger and lets investors price it. OpenAI says it wants to be able to argue the danger is controlled before it asks for the money. The first is quicker. The second, if it is done properly, tells buyers more.
Liability is already in court
Gizmodo raised a less flattering reading: that the concern is legal exposure as much as safety. Legal Advocates for Safe Science and Technology sued OpenAI in California on the day of the keynote, as we covered in the Hugging Face lawsuit. “I suspect OpenAI are very aware of the legal risks of what their agents are doing,” the group’s programmes director, Vivian Dong, told the Financial Times. An unresolved liability question is a hard thing to take to market.
What an OpenAI Safety Case Would Need to Contain
If the condition is real, it can be specified. The literature is consistent about the parts.
| Part | What it answers | What OpenAI has shown so far |
|---|---|---|
| Claim | Safe for what, in which deployment? | Not stated as a single claim |
| Evidence | Which tests, on which version? | System cards with evaluation results |
| Assumptions | What must stay true? | Partly, in the cards’ caveats |
| Independent review | Who outside the team checked it? | An external evaluator is promised under the White House accord |
| Sign-off | Who may say no? | Leadership, with board committee oversight |
| Expiry | What change reopens the case? | A new deployment not covered by an existing report |
The evidence problem
The published numbers show why the argument is not yet easy. OpenAI’s addendum for GPT-6.1 Sol, the cheaper model it released this week, reports a persistence-after-warnings rate of 23.5%, against 17.4% for GPT-6 Astra. A safety case has to explain figures like that, not only report them.
The independence problem
A safety case judged only by the company that wrote it is a weaker thing. On the same Tuesday, OpenAI’s president signed a White House pledge committing the company to an independent external auditor and an independent board committee. We look at that document in our piece on the AI self-regulation pledge. It does not require either body to publish anything.
The science problem
Altman conceded the hardest part himself. Asked about Nvidia’s new containment software, he said: “if we treat AI safety as only an engineering problem, we will miss the very important point that we have a science problem in front of us. We still have discovery about how to align these models.” A safety case cannot be stronger than the science under it.
How to Tell Whether the Safety Case Has Been Made
Because the condition is self-defined, outside observers need their own tests. Five are practical.
Look for the word in the documents
If the next system card or framework revision contains a section titled as a safety case, with a stated claim and scope, the condition has become a process. If the phrase stays in interviews only, it has not.
Look for a named reviewer
An auditor or evaluator that is named, that saw the model before release and that is free to publish is evidence. An unnamed one is not.
Look for a failed case
Processes that never say no are not gates. OpenAI has now cancelled one release. A published account of why, in the form of an argument that failed, would be the strongest sign that the safety case is more than a phrase.
Look at the filing
When the S-1 becomes public, read how it words its safety statements. Hedged risk factors alone would mean the company chose Anthropic’s route after all.
Look at the calendar
Friar’s 2027 target has not been withdrawn. If a listing is announced without any of the above, the timetable won.
What the Safety Case Means for Organisations Using OpenAI
For customers, the listing date is a side issue. The safety case is not, because it is the closest thing to assurance a supplier of frontier systems can offer.
Ask for it
Enterprise buyers can ask any model supplier for the safety case behind the product they are deploying: the claim, the evidence and the reviewer. Today most will receive a system card. That is a start, and asking sets the expectation.
Write your own
The same discipline works inside your organisation. Before giving an agent access to email, code or payments, write down the claim you are making about it, the evidence you have and the conditions that would reopen the question. Our cybersecurity team uses that format for agent deployments, and our AI models and tools hub tracks what each vendor has published.
Do not wait for the IPO
Whether OpenAI lists in 2027 or later changes nothing about the controls you need now. We set those out when Altman launched always-on agents without mentioning the recent incidents, in our report on OpenAI’s security concerns.
Safety Case FAQ
What did Sam Altman say about the OpenAI IPO?
On 29 September 2026 he said he has no particular timeline. He told CNBC a listing could follow “once we have run a few safety cases”, and told reporters OpenAI must “be able to make confident safety claims” first.
What is a safety case?
A structured argument, supported by evidence, that a system is safe for a given use in a given environment. The concept comes from industries such as aviation and nuclear power.
Does OpenAI publish a safety case today?
Not under that name. Its Preparedness Framework describes Capabilities Reports and Safeguards Reports, and it publishes system cards with evaluation results.
Which AI companies use the term?
Anthropic’s Responsible Scaling Policy refers to affirmative safety cases, and Google DeepMind’s Frontier Safety Framework requires one to be reviewed before general release of a model at a critical capability level.
Is the OpenAI IPO cancelled?
No. Altman said it would be “kind of bad for the world if OpenAI waits too long to go public.” The company’s finance chief said in August it would be public in 2027.
Why does the safety case matter to investors?
Statements in a registration statement carry legal liability. A company that tells public investors its systems are under control has to be able to support that claim.
References
Sam Altman says OpenAI won’t go public until its models are safe (The Verge)
Transcript: OpenAI CEO Sam Altman speaks with CNBC’s Kate Rooney (CNBC)
No OpenAI IPO until the AI stops going rogue, CEO Sam Altman says (Gizmodo)
Safety cases at AISI (UK AI Security Institute)
Safety cases for frontier AI (Buhl and others, arXiv)
Safety Cases: How to Justify the Safety of Advanced AI Systems (Clymer and others, arXiv)
Three Sketches of ASL-4 Safety Case Components (Anthropic)
Updating the Frontier Safety Framework (Google DeepMind)
Preparedness Framework, version 2 (OpenAI)
More AI coverage: explore Progressive Robot's AI Models, Tools & Releases hub — hands-on reviews, setup guides and benchmarks in one place.