OpenAI has publicly backed California's Senate Bill 1119, legislation setting new safety requirements for how young people use AI, and is urging governor Gavin Newsom to sign it into law.

In a blog post published 31 August, OpenAI vice president of global policy Ann O'Leary said the company supports the bill's requirements that AI products determine a user's age, identify and address safety risks before launch, undergo independent audits, protect young people from harmful content including self-harm and sexually exploitative material, give parents tools to manage their children's use, connect young people with crisis-support resources, and limit targeted advertising and data collection. OpenAI said it wants these protections to apply automatically for users aged 13 to 17.

The company frames its position as consistent with its own ChatGPT for Teens product, which it says automatically places users the system estimates or who state they are under 18 into a restricted experience with built-in safeguards and parental controls that cannot be turned off. Teen-specific features cited by OpenAI include Quizzes, Learning Visualizations and Study mode, along with what it describes as "responsible" use of ChatGPT's memory feature to maintain safety context across conversations. OpenAI claimed nearly nine in ten teenage ChatGPT users turn to it weekly for learning, information or productivity.

OpenAI also pointed to its own Model Spec, its internal rules governing model behaviour, saying it has added an "Under-18 Principles" section prohibiting romantic engagement with minors, encouragement of emotional dependence, and claims by the model that it is human or sentient. The company separately said it has been involved in advocacy on a related bill, the Parents & Kids Safe AI Act.

The bill is backed by state senator Steve Padilla and assembly members Buffy Wicks and Rebecca Bauer-Kahan.


Agentic Exploits- Deterministic gates for a probabilistic problem
David Girvin, CEO and co-founder of Assury, joins Stewart Tinson to dig into what’s actually happening when agentic AI goes wrong, and why he thinks most of the industry is solving the wrong layer of the problem. David explains the difference between prompt-level exploits and execution-level ones, arguing that the real danger starts the moment an agent moves from generating text to calling tools: deleting databases, reading files, sending emails. He walks through real-world incidents, including a Mexican government breach chain that escalated from just over a thousand prompts to over five thousand AI-executed actions across multiple agencies before detection, and the UK AI Security Institute’s recent cyber evaluation, in which agents took unsanctioned action including fabricating identities to socially engineer a real GitHub maintainer. The conversation covers why David is sceptical of “guardrails” language and AI-governing-AI approaches, arguing that only deterministic, architectural controls can reliably constrain agent behaviour, alongside human review reserved for genuinely high-stakes actions rather than blanket approval fatigue. He breaks down credential starvation, session risk accumulation, and why classifier-based tools keep failing inconsistently on identical actions, pointing to a named frontier lab’s own zero trust paper as an example of the industry misjudging what actually works. Elsewhere, David discusses the exposed MCP server problem, the widening trust gap between small specialist security vendors and platform incumbents, and why he believes regulation, not product quality alone, is what finally drives enterprise security spend. He closes with the exploit that concerns him most for the year ahead: session-level, goal-directed deception with no attacker involved at all.
Share this post
The link has been copied!