In brief: Sam Altman says society should accept some harm in exchange for broadly accessible AI. At the same time, OpenAI calls even small risks of losing control over highly capable systems unacceptable. This is not a complete contradiction, but it exposes two risk classes that OpenAI treats differently.
What Altman is willing to accept
In a Politico interview published on 4 October and reported by Reuters, Altman distinguishes OpenAI from Anthropic. He rejects a world in which one lab keeps powerful AI tightly restricted to eliminate hacks, scams and other misuse. In his view, the expected social benefits and users' agency justify some residual risk, supporting OpenAI's preference for lighter regulation.
This is broader than a technical release decision. Altman gives no measurable harm threshold and does not say who defines or bears acceptable losses. His argument is initially a political trade-off between access and misuse.
OpenAI's other red line
At the UN Security Council on 23 September, Altman drew a much stricter boundary around control and catastrophic risk. Even probabilities of 0.1 or one percent were unacceptable, he said; models should not be trained without strong evidence that they can remain under human control. He also warned against concentrating the most powerful systems in one company or country.
OpenAI's safety-case proposal, published five days later, fits that distinction. It calls for evidence covering alignment, containment and monitoring, automatic pauses, and a complete inventory of residual risks before frontier training runs. The document still describes these rules as an aspirational framework and says parts are being implemented. Pandorex's recent report also documents the internal dispute over whether OpenAI's iterative approach remains adequate as capabilities grow.
Pandorex Analysis
The defensible reading is that OpenAI seeks to prevent existential or uncontrollable system risk while accepting limited harm from ordinary use to preserve access. The critical boundary between those categories remains undefined. A cyberattack that begins as routine misuse can reach critical infrastructure or software supply chains and cross into the second class.
The real test is therefore not the provocative wording alone, but whether OpenAI publishes auditable thresholds: which incidents stop training or deployment, which residual risks are accepted, and who can independently challenge that decision? Without those details, the distinction is politically intelligible but operationally incomplete.
