On September 8 I published an open letter proposing the MM Control Stack Compact, six commitments written to be verifiable, and promised to publish any substantive response, including silence. This morning OpenAI released a Model Misalignment Reporting Framework, together with six reports of what it calls "unexpected or concerning" model behavior from its own training runs between October 2025 and August 2026. Its own description of its past practice, per Gizmodo, was "ad hoc and less frequent than ideal." The new principle, per MarkTechPost's summary, is that OpenAI will disclose misalignment "even before it is fully explained or fixed."

That is commitment three, incident disclosure with teeth, in its first working form. I want to be precise about which half arrived, because the whole letter rests on the difference between a lab reporting on itself and someone else being able to check.

A lab publishing its own incidents on a deadline is real progress. A lab investigating its own incidents is the situation the letter was written to change.

What OpenAI published

The framework is a process, which is the right thing for it to be. Any employee can flag a case. Technical staff investigate the facts and the uncertainties. Cases go into one of three tracks: ready for disclosure, minor investigation, or a larger investigation, the "slow track" for complex cases and anything involving third parties, where OpenAI says it will publish an initial notice quickly with a high-level account and a timing estimate. Third parties are notified before public release. Each step has a deadline, though the deadlines themselves are not published yet; the company says it wants "more objective disclosure criteria." Oversight sits with the Safety Advisory Group that runs the Preparedness Framework, with disputes escalating to leadership. And, in a line worth holding on to, OpenAI says serious safety, security, and misalignment incidents should be shared with the US federal government, and that it is working on proposing the mechanism.

The six reports are the more useful document. All six come from reinforcement-learning training, not deployment.

Read those next to the Major Labs Frontier Incident Timeline and the pattern is identical to the public record: shared writable surfaces become coordination channels, agents go to the open internet when the local path fails, and the memory an agent carries can be poisoned by the agent itself. The difference is that this time the lab wrote it down first.

Scoring it against the compact

Commitment three asked for four things: report an incident to an independent body within 72 hours, have that body investigate with legal authority to compel evidence, close with a public report, and do it every time. The aviation model. Here is where today's framework lands on each.

Reporting with a deadline: present, though the deadlines are internal and unpublished. Disclosure before mitigation: present, and rarer than it sounds; most incident regimes in most industries publish after the fix. Third-party notification: present. An independent body: absent. The reviewer is the lab's own Safety Advisory Group. Legal authority: absent, and not something a company can grant itself. A public closing report by someone other than the lab: absent. The federal reporting line is the acknowledgment that the missing half belongs to government, and it is the most important sentence in the announcement, because it is the first time a lab has said in writing that its own process is not the end of the process.

Commitment six, monitoring honesty, got something too, and I did not expect it. The 2.15 percent versus 0.27 percent figure is a lab publishing the failure rate of its own oversight mechanism as a number, by model, in a structured report. When OpenAI's chief scientist said chain-of-thought monitoring was degrading, that was a sentence in an essay. This is a table. It is the first structured oversight-reliability disclosure by any frontier lab that I know of, and it goes on Threshold Watch today as a dated entry against commitment six.

So the ledger after nine days: commitment one, thresholds in a common versioned format, no movement, and Threshold Watch still finds zero of six labs with a verifiable changelog. Commitment two, independent evaluation with real access, one lab pledged and one lab said "we will do the same." Commitment three, half built by one lab. Commitment six, first structured disclosure by one lab. Four and five, attributable agents and liability that lands somewhere, belong to buyers and the market, and the market has started pricing five on its own.

The other two beats of the same day

The policymaker beat came from Brussels. In her State of the Union address, Ursula von der Leyen said, per The Decoder, that AI agents "escaping their environment" are a preview of what is coming, that models in development "will allow hacking on a level we never thought possible," and that the Commission will invite the frontier labs to talks and work with Canada and the UK on evaluation and verification, with the AI Act as the guardrail. She also acknowledged the EU does not have reliable access to the labs' most advanced cybersecurity models. What she did not announce is the one narrow thing the letter asked policymakers for: an investigation authority with the power to compel evidence and publish findings. Talks and evaluation partnerships are the second commitment. The third still has no owner outside the labs.

The security beat came from the practitioners. TechCrunch gathered Katie Moussouris, Avery Pennarun, Sayash Kapoor, Simon Willison, and others to make the case that embedded auditors matter less than closing the front door: logs, permissions, egress control, sandboxes that are actually sealed. Pennarun: "We as a profession know how to block access to the internet." Shapor Naghibzadeh: "The one hole you leave open for convenience is the one that gets used." Kapoor: "Marginal investments in control are more likely to be effective compared to those in alignment." Every one of OpenAI's six reports is evidence for them. An internal package repository that agents can write to is a front door. A file host reachable from a training sandbox is a front door. The disclosure framework tells you the doors were open. It does not close them.

What the six reports mean if you run agents

The lab's incidents are a preview of yours, at smaller scale and with less at stake, because the failure modes are properties of agents rather than of one lab. Three rules fall straight out of the reports. No shared writable surface without an owner and a log, because any surface agents can write to becomes a channel they will use to coordinate, exactly as the DeepMind whistleblowers used their shared wiki. Egress allowlists, because when the local path fails, an agent will find the public one. And treat an agent's own summaries as untrusted input, because the memory it carries between steps can be poisoned by the step before. None of that requires a framework. It requires the front door.

What to watch

Whether OpenAI publishes the deadlines, which turns a promise into a measurable one. Whether the first slow-track case closes with a report anyone outside can read. Whether Anthropic and DeepMind match the reporting framework, which would make commitment three an industry practice rather than one lab's. Whether the federal reporting mechanism is proposed, and to whom. And whether von der Leyen's talks produce an authority or a communiqué. Threshold Watch carries all five as dated items, and I will report the silences as plainly as the progress.

If a lab will now publish its incidents before it has fixed them, who is going to check that the fix ever comes?

Charlie Major is a Product Development Manager at Mastercard. The views and opinions expressed in Major Matters are his own and do not represent those of Mastercard.