In August 2025, a California family sued OpenAI and its CEO, alleging the CEO overruled staff who wanted more safety testing before a launch; both deny it.1 Whether an executive answers personally for such a call turns on state tort law and facts no outsider can see. Congress should require a record of who decided, executive attestations, and personal liability for leaders who knowingly direct or conceal serious violations.
The Problem
A handful of executives decide how products used by hundreds of millions of people behave: when to launch, how much testing is enough, what a chatbot may say to a child. ChatGPT alone reports more than 800 million weekly users.2
The rewards for shipping first arrive at once; the costs arrive years later, and they land on the company. A rule that punished job titles would be unjust. A rule that lets deliberate decisions dissolve into an org chart is no rule at all. The gap shows up in three places:
- Warnings get overruled. OpenAI's postmortem says expert testers found that an April 2025 ChatGPT update "felt" slightly off; the company shipped it anyway, called that "the wrong call," and rolled it back days later. The account says "we decided" and names no one.3
- Approvals stay hidden. Meta's internal rules allowing chatbots to engage children in "romantic or sensual" conversations were reportedly approved by its legal, policy, and engineering staff, including its chief ethicist.4 A Senate subcommittee chairman then had to demand documents to learn "who approved these policies."5
- Nobody signs for safety. Sarbanes-Oxley makes a public company's CEO and CFO certify every quarterly and annual report, with up to 20 years in prison for willfully false certification.6 No federal law asks anyone to certify the safety testing behind a chatbot.
Why legislation: American law already ties authority to responsibility. In United States v. Park (1975), the Supreme Court held that a grocery chain's president could be convicted over rodent-infested warehouses the president had the "responsibility and authority" to fix after FDA warnings.7 The FTC required Mark Zuckerberg to certify Facebook's privacy compliance personally in 2019,8 and Britain's Online Safety Act makes named senior managers criminally liable, with up to two years in prison, for failing to prevent false reports to the regulator.9 No U.S. law applies this principle to AI safety. People who decide how millions of Americans are treated should answer for their knowing choices.
The Solution
A four-step staircase: each step stands alone, and each step up adds personal accountability. Scope: consumer chatbot providers above 10 million monthly U.S. users and the officers with material authority over their launches and safety. Corporate liability stays in place; whistleblower protections are addressed separately.
Step 1 — Write down who decided. Record material safety escalations, launch approvals, and overrides, with the name of the person who signed each. Give designated safety staff direct access to the board, and protect good-faith reports to regulators. OpenAI now promises to "explicitly approve model behavior for each launch";3 the law should record who approved it.
Step 2 — Make leaders sign. Each year, the CEO and the responsible safety officer attest that required testing and reviews occurred and that material findings were disclosed accurately. They certify the process, not a guarantee that nothing will go wrong. The FTC imposed quarterly personal certifications on Facebook's CEO in 2019.8
Step 3 — Hold knowing decision-makers liable. Create civil liability for an officer with material authority who knowingly directs a statutory safety violation, deliberately conceals a serious risk, or recklessly ignores a documented violation they had the power and duty to fix. Reasonable reliance on competent experts, genuine corrective action, and lack of authority are defenses. Approving a launch that later causes an unforeseeable injury is no violation.
Step 4 — Make the penalty personal. For proven misconduct, courts may impose civil penalties and bar individuals from running covered AI providers, as securities law lets courts bar fraudsters from serving as public-company officers10 and as the FTC's Drizly order follows that company's CEO to future employers.11 Companies may not reimburse penalties for knowing concealment, though they may advance defense costs until wrongdoing is proven. Personal damages require proof of causation.
Where to start: Step 1 is the floor; it asks only for a paper trail. Step 2 is the heart of the proposal.
Administration and enforcement: The FTC and state attorneys general enforce after an 18-month phase-in, with individual notice and judicial review. Any criminal penalty, such as Sarbanes-Oxley's for willfully false certification, should be debated separately and limited to intentional conduct; negligence stays civil.
Risks and Mitigations
- Scapegoating: A company could offer up a junior safety officer, and a title alone proves nothing. Liability requires knowledge, conduct, and authority, and corporate liability remains; courts will still have to sort out who truly decided.
- Talent flight: Personal exposure could deter capable people from safety roles. Attestations cover process, penalties are proportionate, and reliance on experts is a defense; some chilling will remain.
- Proof: Knowledge is hard to prove. Step 1's records make it provable, but enforcement still depends on investigators with access, expertise, and time.
Similar Bills
Fit measures similarity to this proposal's mechanisms: High = direct precedent; Partial = useful component with material differences; Related = adjacent approach.
Federal
| Proposal or bill | Relevant provisions and fit | Fit |
|---|---|---|
| S. 1444 — Mind Your Own Business Act of 2021 Wyden (D-OR) Referred to committee · Apr. 29, 2021 · Expired with the 117th Congress |
Would require the CEO and chief privacy officer to certify annual data-protection reports, with fines tied to compensation and up to 20 years in prison for willfully false certification. Close attestation precedent for Step 2; privacy rather than safety, and criminal penalties this draft leaves to separate debate. | Partial |
| Sarbanes-Oxley Act §§302, 906 (15 U.S.C. §7241; 18 U.S.C. §1350) Enacted · July 30, 2002 |
CEOs and CFOs certify each periodic report; knowingly false certification carries up to 10 years and willfully false certification up to 20. Established model for Step 2's attestation; covers financial reports, not product safety. | Partial |
| S. 1010 — Corporate Executive Accountability Act Warren (D-MA) Referred to committee · Apr. 3, 2019 · Expired with the 116th Congress |
Would make executives of corporations with over $1 billion in revenue criminally liable for negligently permitting certain violations, up to one year for a first offense. Personal-accountability precedent for Step 3; its negligence standard and criminal penalty go beyond this draft. | Related |
State
| Proposal or bill | Relevant provisions and fit | Fit |
|---|---|---|
| California — SB 53, Labor Code §1107.1 Enacted · Sept. 29, 2025 (Ch. 138) |
Large frontier developers must offer an anonymous internal reporting channel and share employees' safety disclosures and the company's responses with officers and directors at least quarterly. Precedent for Step 1's escalation record; limited to catastrophic risk, with no attestation or personal liability. | Partial |
| California — Corporations Code §25504 Corporate Securities Law of 1968 · In force |
Makes controlling persons and principal executive officers jointly liable for certain securities violations unless they had no knowledge or reasonable grounds to believe the facts. Knowledge-based model for Step 3; securities law, not AI safety. | Related |
| Massachusetts — G.L. c. 149, §148 In force |
Deems a corporation's president, treasurer, and managing officers to be the employers responsible for its wage duties. Shows statutes can name the officers who answer; a wage duty with no knowledge element in the text. | Related |
What this adds: Congress has required executives to certify financial reports since 2002 and has proposed the same for privacy. This proposal carries the idea to AI safety: a decision record, process attestations, and personal liability limited to knowing or reckless misconduct, with defenses that protect honest judgment. No state law yet makes chatbot executives personally liable; the state rows are analogues.
Notes
-
Complaint ¶¶ 18, 92–94, Raine v. OpenAI, Inc. (Cal. Super. Ct. S.F. Cnty., dated Aug. 26, 2025), alleging the chief executive moved up GPT-4o's May 2024 launch and overruled safety staff; Defendants' Answer, No. CGC-25-628528 (Nov. 25, 2025), general denial on behalf of OpenAI and Samuel Altman. Allegations only. ↩
-
Rebecca Bellan, "Sam Altman says ChatGPT has hit 800M weekly active users," TechCrunch, October 6, 2025. Worldwide users. ↩
-
OpenAI, "Expanding on what we missed with sycophancy," May 2, 2025. The update rolled out April 24–25, 2025; OpenAI began a full rollback on Monday, April 28, 2025. ↩ ↩2
-
Sen. Edward J. Markey, letter to Mark Zuckerberg, September 8, 2025, p. 1, quoting and citing Jeff Horwitz, "Meta's AI rules have let bots hold 'sensual' chats with kids, offer false medical info," Reuters, August 14, 2025. Per the letter, Meta has since called the passage an error and revised the document only after Reuters reported it. ↩
-
Sen. Josh Hawley, Chairman, Senate Judiciary Subcommittee on Crime and Counterterrorism, letter to Mark Zuckerberg, August 15, 2025. ↩
-
15 U.S.C. § 7241 (Sarbanes-Oxley Act § 302); 18 U.S.C. § 1350(c) (§ 906): up to $1 million and 10 years for knowingly false certification, $5 million and 20 years for willfully false certification. ↩
-
United States v. Park, 421 U.S. 658 (June 9, 1975), reversing the court of appeals and reinstating the conviction of Acme Markets' president under the Food, Drug, and Cosmetic Act. ↩
-
Federal Trade Commission, "FTC Imposes $5 Billion Penalty and Sweeping New Privacy Restrictions on Facebook," July 24, 2019. Quarterly and annual certifications by the CEO and compliance officers; false certification exposes them to "individual civil and criminal penalties." ↩ ↩2
-
Online Safety Act 2023 (UK), ss. 103, 110(4), 113(2). Applies when the company gives false information in response to a regulator's information notice and the named manager failed to take all reasonable steps to prevent it. ↩
-
15 U.S.C. § 78u(d)(2), permitting courts to bar securities-fraud violators from acting as officers or directors of public companies when their conduct demonstrates unfitness. ↩
-
Federal Trade Commission, "FTC Takes Action Against Drizly and its CEO James Cory Rellas for Security Failures that Exposed Data of 2.5 Million Consumers," October 24, 2022. The order requires the CEO to implement a security program at future companies above 25,000 consumers; the Commission finalized it 4-0 on January 10, 2023. ↩