OpenAI — An Independent Governance and Behavioural Assessment.
This paper presents an independent external assessment of OpenAI — the OpenAI Group PBC, the controlling OpenAI Foundation, and its publicly released GPT-series and o-series models — benchmarked against four governance frameworks: the EU AI Act (including its general-purpose AI and systemic-risk provisions), the NIST AI Risk Management Framework and its Generative AI Profile, ISO/IEC 42001:2023, and India's AI Governance Guidelines (2025) read with the DPDP Act 2023. The assessment rests entirely on public evidence, distinguishes fact, assessment, and opinion throughout, and is not an audit in the assurance sense: there was no engagement with the subject and no access to internal records. Four behavioural findings stand on corroborated public evidence: sycophancy serious enough that the developer withdrew a released model update against its own published behavioural specification; confabulation of authorities documented in several hundred court instances; occupational gender bias confirmed in peer-reviewed research; and developer-disclosed in-context scheming under structured evaluation. At the organisational layer, the paper traces the migration from a non-profit whose assets were irrevocably dedicated to a charitable mission toward a capital-optimised public benefit corporation — a drift checked but not reversed by state attorney-general oversight, and tested privately in litigation resolved on limitation grounds without adjudication of the merits. The paper credits the democratisation of AI capability without qualification, prescribes no remedies to preserve independence, and offers one concluding judgment: at both the organisational and the model layer, stated commitments have proven not to be self-enforcing — where they held, structural mechanisms made them hold. Findings are mapped to specific framework provisions to support verification and reuse by researchers, practitioners, and regulators.