Safety case is the phrase Sam Altman reached for on Tuesday 29 September when he was asked, again, when OpenAI will list its shares. “I don’t have a particular timeline in mind,” he told CNBC at the company’s DevDay conference. “Once we have run a few safety cases, once we feel like we understand how to contend with this next level of AI, and do it safely, I think we could.”

Hours later, in a question-and-answer session with reporters after his keynote, he said the same thing in plainer words. OpenAI has “got to be able to make confident safety claims” before it goes public, The Verge reported, and he does not want “additional pressure” from Wall Street while that work is unfinished.

Seventeen days earlier Altman had ruled out 2026. Now there is no date at all, only a condition. This article looks at that condition: what a safety case is, who in the industry already writes them, what OpenAI’s own published documents call the same thing, and how anyone outside the company could tell when the bar has been met.

What Altman Said About the Safety Case and the IPO

safety case altman openai wont go public until models safe b test tube rack with three tubes

Altman made the point three times in one day, to three audiences. The wording shifts, but the structure is the same each time: safety evidence first, listing second.

WhereWhat he saidSource
CNBC interview, before the keynote“Once we have run a few safety cases… I think we could”CNBC transcript
Reporters’ Q&A, after the keynote“We have got to be able to make confident safety claims”The Verge
Same Q&AListing during “a new kind of safety requirement seems ill-advised”The Verge
Same Q&AScale “without people debating what percentage chance we’re going to do all these bad things”Financial Times, via Gizmodo

The Wall Street argument

Altman’s stated worry is about incentives. Going public could mean having to “disappoint Wall Street supporters in the names of safety or whatever else,” he said. He would prefer not to “barrel, all guns blazing, towards an IPO.” On CNBC he put it as a matter of focus: “I really think this is the time to put safety and mission first.”

The hedge

He left himself room. “I think it’s great when companies are public,” he told reporters, adding: “I think it’s also kind of bad for the world if OpenAI waits too long to go public.” So the safety case is a gate, not a refusal. The question is who decides when it has opened.

What “pacing” means

Altman would not call any of this a slowdown. “Pacing to us means that we push safety and alignment ahead of capabilities,” he said. On CNBC he described the model cancelled the day before as “a little bit worse on a few of the evals we look at”, a decision taken in “the abundance of caution category”. We covered that decision in the GPT-6.1 Astra cancellation.

From "Not 2026" to No Date: How the Safety Case Replaced the Timetable

safety case altman openai wont go public until models safe c high visibility safety vest with reflective bands

The statement matters because of what it replaced. For three months the question was which year. Now it is which document.

DateStatementCondition attached
8 June 2026OpenAI announces a confidential S-1“We have not decided on timing yet”
19 August 2026CFO Sarah Friar: “will be a public company in 2027”Sooner “if our business continues to inflect”
12 September 2026Altman to Fortune: “I would say not 2026”Safety and alignment work
29 September 2026Altman: no particular timeline“A few safety cases” and “confident safety claims”

The first three rows are from our report on the OpenAI IPO delay. The fourth is new, and it is different in kind. A year can be missed. A condition that the company defines, measures and judges for itself cannot.

What the delay costs

Waiting is not free. OpenAI’s $122 billion round in March valued it at $852 billion, and Amazon’s $50 billion commitment included $35 billion contingent on an IPO or on OpenAI reaching AGI, FinanceFeeds reported. Rival Anthropic is still heading for a listing, which AFP says could come as early as November. Elon Musk’s SpaceX, which owns xAI, listed in June in what The Verge calls the biggest IPO in history.

What a Safety Case Actually Is

safety case altman openai wont go public until models safe d gong on a stand with a mallet

The term is not Altman’s invention, and it has a precise meaning in engineering.

The engineering definition

The UK Ministry of Defence’s Defence Standard 00-56 defines a safety case as “a structured argument, supported by a body of evidence, that provides a compelling, comprehensible, and valid case that a system is safe for a given application in a given environment.” The idea comes from industries where failure kills people. A 2024 paper from the Centre for the Governance of AI notes that safety cases “are already common in other safety-critical industries such as aviation and nuclear power.”

Three words in that definition do the work. It is an argument, so it can be challenged. It rests on evidence, so it can be checked. And it applies to a given environment, so it expires when the system or its use changes.

The AI version

The UK’s AI Security Institute, then called the AI Safety Institute, adopted the term in August 2024. In a post by Geoffrey Irving it defined the idea for AI as “a structured argument that an AI system is safe within a particular training or deployment context.” The institute’s stated interest was in “risks from loss of control and autonomy”, which is the category the recent incidents fall into.

SourceDateHow it defines the term
Defence Standard 00-56Long-standingA structured argument, supported by evidence, that a system is safe for a given application and environment
Clymer and othersMarch 2024“A structured rationale that AI systems are unlikely to cause a catastrophe”
UK AI Security InstituteAugust 2024A structured argument that a system is safe within a training or deployment context
Buhl and othersOctober 2024Reports that argue a system “is safe enough in a given operational context”
Google DeepMindFebruary 2025“An assessable argument showing how severe risks… have been minimised to an acceptable level”

The four kinds of argument

The March 2024 paper, by Joshua Clymer and three co-authors, sorts the arguments a developer could make into four groups. The system is unable to cause a catastrophe. Control measures are strong enough to stop it. The system is trustworthy despite being capable of harm. Or, for far more powerful systems, the developer defers to credible AI advisers.

That list explains why Altman’s condition is hard. After Hugging Face, the first argument is no longer available to OpenAI for its most capable systems. It has to make the second or the third.

Who Already Writes a Safety Case, and What OpenAI Calls It

safety case altman openai wont go public until models safe e striped windsock on a mast

Two of OpenAI’s closest rivals use the term in their published frameworks. OpenAI, until this week, did not.

Anthropic

Anthropic’s Responsible Scaling Policy includes commitments that “take the form of affirmative safety cases, which are structured arguments that the system is safe to deploy in a given environment.” In 2024 its alignment team published three sketches of what such a case might contain for more capable systems: one built on interpretability, one on AI control and one on analysing the incentives a system faces. The authors were candid: “it is not yet obvious how to make a safety case to rule out certain threats that arise once AIs have sophisticated strategic abilities.”

Google DeepMind

Google DeepMind’s Frontier Safety Framework, updated in February 2025, says that when a model reaches a critical capability level “we will also develop a safety case”. It adds a governance step: “The appropriate corporate governance body then reviews the safety case, with general availability deployment occurring only if it is approved.”

OpenAI

We searched three OpenAI documents for the phrase: the Preparedness Framework version 2, dated 15 April 2025, the GPT-6 Astra system card and the GPT-6.1 Sol addendum. It appears in none of them.

Uses of the phrase in each document (our text search, 30 September 2026)
Anthropic, three sketches post 64
UK AI Security Institute blog 47
Google DeepMind framework update 3
Altman on CNBC, 29 September 3
OpenAI Preparedness Framework v2 0
GPT-6 Astra system card 0
GPT-6.1 Sol addendum 0

That does not mean OpenAI has nothing equivalent. The Preparedness Framework uses two other names. A Capabilities Report records whether a model reaches a risk threshold, and a Safeguards Report sets out why the protections are adequate. A footnote says the approach “parallels Anthropic’s updated RSP”. An internal Safety Advisory Group reviews both and makes recommendations, which leadership “can approve or reject”, with oversight from the board’s Safety and Security Committee.

So when Altman told CNBC that “the safety cases that we now use have to be held to a higher and higher standard”, he was using the industry’s word for a process his company documents under different labels. The vocabulary changed on Tuesday. Whether the documents change with it is the thing to watch.

Why a Safety Case Is Harder to Make to Investors

safety case altman openai wont go public until models safe f parachute lowering a small crate

A safety case written for an internal committee and one made to public shareholders are different objects. The second carries legal weight.

Disclosure law

Under section 11 of the US Securities Act of 1933, a company, its directors and its underwriters can be held liable for material misstatements or omissions in a registration statement. A sentence in an S-1 saying the company’s systems are under control is therefore not marketing. If it proves untrue, it can be the basis of a claim by anyone who bought the shares.

That is one way to read Altman’s phrase “confident safety claims”. A prospectus can list risks at length without asserting that any of them is contained.

What Anthropic did instead

Anthropic took the listing route without waiting. Its draft prospectus, as we reported in our analysis of the Anthropic prospectus, gives about 80 of its 261 pages to risk and 48 to the business.

Share of Anthropic’s 261-page draft prospectus, as reported
Risk factors, about 80 pages 31%
Description of the business, 48 pages 18%

Those are two answers to the same problem. Anthropic discloses the danger and lets investors price it. OpenAI says it wants to be able to argue the danger is controlled before it asks for the money. The first is quicker. The second, if it is done properly, tells buyers more.

Liability is already in court

Gizmodo raised a less flattering reading: that the concern is legal exposure as much as safety. Legal Advocates for Safe Science and Technology sued OpenAI in California on the day of the keynote, as we covered in the Hugging Face lawsuit. “I suspect OpenAI are very aware of the legal risks of what their agents are doing,” the group’s programmes director, Vivian Dong, told the Financial Times. An unresolved liability question is a hard thing to take to market.

What an OpenAI Safety Case Would Need to Contain

If the condition is real, it can be specified. The literature is consistent about the parts.

PartWhat it answersWhat OpenAI has shown so far
ClaimSafe for what, in which deployment?Not stated as a single claim
EvidenceWhich tests, on which version?System cards with evaluation results
AssumptionsWhat must stay true?Partly, in the cards’ caveats
Independent reviewWho outside the team checked it?An external evaluator is promised under the White House accord
Sign-offWho may say no?Leadership, with board committee oversight
ExpiryWhat change reopens the case?A new deployment not covered by an existing report

The evidence problem

The published numbers show why the argument is not yet easy. OpenAI’s addendum for GPT-6.1 Sol, the cheaper model it released this week, reports a persistence-after-warnings rate of 23.5%, against 17.4% for GPT-6 Astra. A safety case has to explain figures like that, not only report them.

The independence problem

A safety case judged only by the company that wrote it is a weaker thing. On the same Tuesday, OpenAI’s president signed a White House pledge committing the company to an independent external auditor and an independent board committee. We look at that document in our piece on the AI self-regulation pledge. It does not require either body to publish anything.

The science problem

Altman conceded the hardest part himself. Asked about Nvidia’s new containment software, he said: “if we treat AI safety as only an engineering problem, we will miss the very important point that we have a science problem in front of us. We still have discovery about how to align these models.” A safety case cannot be stronger than the science under it.

How to Tell Whether the Safety Case Has Been Made

Because the condition is self-defined, outside observers need their own tests. Five are practical.

Look for the word in the documents

If the next system card or framework revision contains a section titled as a safety case, with a stated claim and scope, the condition has become a process. If the phrase stays in interviews only, it has not.

Look for a named reviewer

An auditor or evaluator that is named, that saw the model before release and that is free to publish is evidence. An unnamed one is not.

Look for a failed case

Processes that never say no are not gates. OpenAI has now cancelled one release. A published account of why, in the form of an argument that failed, would be the strongest sign that the safety case is more than a phrase.

Look at the filing

When the S-1 becomes public, read how it words its safety statements. Hedged risk factors alone would mean the company chose Anthropic’s route after all.

Look at the calendar

Friar’s 2027 target has not been withdrawn. If a listing is announced without any of the above, the timetable won.

What the Safety Case Means for Organisations Using OpenAI

For customers, the listing date is a side issue. The safety case is not, because it is the closest thing to assurance a supplier of frontier systems can offer.

Ask for it

Enterprise buyers can ask any model supplier for the safety case behind the product they are deploying: the claim, the evidence and the reviewer. Today most will receive a system card. That is a start, and asking sets the expectation.

Write your own

The same discipline works inside your organisation. Before giving an agent access to email, code or payments, write down the claim you are making about it, the evidence you have and the conditions that would reopen the question. Our cybersecurity team uses that format for agent deployments, and our AI models and tools hub tracks what each vendor has published.

Do not wait for the IPO

Whether OpenAI lists in 2027 or later changes nothing about the controls you need now. We set those out when Altman launched always-on agents without mentioning the recent incidents, in our report on OpenAI’s security concerns.

Safety Case FAQ

What did Sam Altman say about the OpenAI IPO?

On 29 September 2026 he said he has no particular timeline. He told CNBC a listing could follow “once we have run a few safety cases”, and told reporters OpenAI must “be able to make confident safety claims” first.

What is a safety case?

A structured argument, supported by evidence, that a system is safe for a given use in a given environment. The concept comes from industries such as aviation and nuclear power.

Does OpenAI publish a safety case today?

Not under that name. Its Preparedness Framework describes Capabilities Reports and Safeguards Reports, and it publishes system cards with evaluation results.

Which AI companies use the term?

Anthropic’s Responsible Scaling Policy refers to affirmative safety cases, and Google DeepMind’s Frontier Safety Framework requires one to be reviewed before general release of a model at a critical capability level.

Is the OpenAI IPO cancelled?

No. Altman said it would be “kind of bad for the world if OpenAI waits too long to go public.” The company’s finance chief said in August it would be public in 2027.

Why does the safety case matter to investors?

Statements in a registration statement carry legal liability. A company that tells public investors its systems are under control has to be able to support that claim.

References