OpenAI’s 15-Member Security Council Test: Sam Altman’s New CEO Job
If your CEO is briefing a 15-member UN Security Council about your product, you are no longer running a normal company. You are running critical infrastructure whether you like it or not.
If your CEO is briefing a 15-member UN Security Council about your product, you are no longer running a normal company. You are running critical infrastructure whether you like it or not.
That is where Sam Altman has taken OpenAI. On Wednesday, during the UN General Assembly gathering in New York, Altman is due to brief an open Security Council meeting on artificial intelligence and international security. The meeting is being convened by France, which holds the Council presidency for September, and chaired by French foreign minister Jean-Noël Barrot.
Forget the usual corporate theatre. This is not another panel at Davos where executives say “innovation” 14 times and everyone claps before lunch. The bloke running OpenAI is being asked to explain the risks of his industry to the same body responsible for war, peace and international security.
That should make every founder and board member sit up a bit straighter.
Sam Altman has crossed the line from founder to public institution
OpenAI says Altman will discuss what it is doing to make AI safe, the need for shared safety standards and international coordination. Fair enough. Those are sensible things to say.
But the substance is bigger than the speech.
A company becomes politically important long before it becomes legally classified as infrastructure. It happens when governments conclude that its product can alter military capability, election integrity, cyber-security, financial markets, labour markets or the flow of information at scale.
AI now lands in all of those buckets.
The Security Council first discussed AI risks in 2023. This week’s meeting comes after a very different few months: major AI executives have publicly entertained slowing frontier development, while OpenAI has disclosed new safety incidents involving its systems. Axios reported this month that OpenAI had disclosed six new AI safety incidents, and that security experts argued basic cyber controls could have prevented some of the failures.
That is the management problem in one ugly little package. The capability race is getting faster. The consequences of mistakes are getting broader. And the public is not inclined to accept “we moved fast” as an excuse when the product can be used to break into systems, manipulate people or create national-security headaches.
Altman is not merely selling software anymore. He is selling trust in the judgement of OpenAI’s leadership.
And trust, unlike software, does not scale cheaply.
The CEO job has changed before most boards noticed
A lot of boards still hire and assess CEOs as if the job is mostly capital allocation, product strategy, sales execution and keeping the senior team from setting fire to the place.
Those things still matter. Obviously.
But for a small group of companies — AI labs, chipmakers, cloud platforms, social networks, defence-tech firms, payment networks, biotech businesses and some energy operators — there is now another job description:
Can this person manage sovereign risk?
Not lobby it away. Manage it.
That means dealing with governments that are customers, regulators, critics, strategic partners and potential adversaries all at once. It means answering uncomfortable questions before a product disaster, not after one. It means having enough technical command to know when an engineer is minimising a real risk — and enough backbone to slow or stop a release when the commercial team is screaming.
It also means your CEO cannot simply be the company’s best fundraiser or best salesperson.
This is the overlooked point in the Altman story. The question is not whether Sam Altman gives a polished speech at the UN. I’d expect him to. The question is whether OpenAI has built an operating system that can make hard calls when the person with the loudest commercial incentive wants to keep charging ahead.
That is a governance question, not a communications question.
Safety only counts when it can beat revenue in a meeting
Every company says it takes risk seriously. Most mean they take risk seriously until it interferes with the quarter.
The test is brutally simple: who has the power to say no?
If the safety team can identify a serious issue but cannot delay a launch, reduce access, impose controls or escalate directly to an independent board, then the company does not have a safety system. It has a safety-themed content department.
This is why the timing matters. Reports about AI-related incidents, combined with calls from executives for coordinated safeguards, have changed the conversation. It is no longer just academics and regulators warning about hypothetical harms. The builders themselves are admitting that the technology is moving into territory where ordinary product-management habits may not be enough.
Good. They should.
I have built businesses and I understand the temptation. When you have momentum, capital, talent and a market going berserk for what you make, a delay feels like weakness. You convince yourself the next release will solve the last release’s problem. You tell yourself competitors will eat your lunch if you pause.
Sometimes that is true.
But there is a more expensive mistake: shipping something that makes governments decide your industry cannot be trusted to govern itself. Once that happens, you do not get light-touch rules. You get prescriptive rules written by people who may understand politics well and your product poorly.
Founders hate that outcome. They should hate causing it even more.
Regulation is not the risk. Being unprepared for it is.
The lazy founder response to regulation is that it kills innovation. Sometimes it does. Bad regulation can absolutely protect incumbents, choke startups and create paperwork jobs for people who have never built anything.
But pretending regulation is optional is not a strategy. It is adolescent thinking with a cap table.
The smart move is to build a company whose internal controls are better than the rules that are likely to arrive. That gives you three advantages.
First, you see risks earlier. If incidents are tracked properly, independently reviewed and reported to the people with authority, they are less likely to become existential surprises.
Second, you have credibility. When a regulator, customer or partner asks how you manage risk, you can show them a real process instead of handing them a 48-page PDF full of words like “commitment” and “framework.”
Third, you create a moat. Serious controls are annoying and expensive. That is precisely why most competitors will skimp on them until forced. If your business can move quickly without acting like a drunken backpacker with a flamethrower, you become easier for large customers and governments to trust.
That does not mean OpenAI or any other frontier lab should be handed a gold star for asking for standards. Companies can use regulation as a way to raise barriers against smaller competitors. That risk is real.
But the answer is not no rules. The answer is rules that focus on demonstrable capability, real-world misuse and accountability — not box-ticking designed by the incumbent with the best lobbying firm.
The contrarian view: this could make Altman stronger, not weaker
Most people see a CEO appearing before the Security Council and assume it is a liability. More scrutiny. More political exposure. More chance of saying something stupid on the world stage.
That is true.
But there is another side. If Altman can demonstrate that OpenAI has genuine safety discipline, transparent incident handling and a willingness to accept external accountability, the company may strengthen its position with enterprise customers and governments.
Big institutions do not buy cutting-edge technology just because it is clever. They buy it when they believe it will still be usable, supportable and defensible when something goes wrong.
For the AI industry, that is becoming the sale.
The winner may not be the company with the flashiest demo. It may be the one whose leadership can credibly say: we know what this system can do, we know where it fails, we have controls around it, and we will tell you when those controls fail.
That is not sexy. Neither is insurance. Both become very interesting when the downside arrives.
What this means for you
You do not need to run OpenAI to take the lesson.
1. Put a real stop button in your business. Identify the decisions that can cause irreversible damage — security, customer money, safety, legal exposure, reputation — and make crystal clear who can halt them. Give that person authority, not just a title.
2. Make bad news travel faster than good news. Ask your leadership team: what gets hidden because it is embarrassing, inconvenient or bad for this month’s numbers? Build a direct route for those issues to reach you and the board.
3. Stress-test the CEO, not just the strategy. Your next leader must be able to explain the business to staff, customers, investors, regulators and critics without changing the facts to suit the room. That is now a core operating skill.
4. Treat trust as an asset with a balance sheet. You can burn it in one reckless launch. You earn it through repeated evidence that you do what you say when it costs you something.
5. Do the boring controls before the crisis forces them on you. The firms that look slow today may be the ones still allowed to move tomorrow.
Sam Altman going to the UN Security Council is not just an AI story. It is a warning for every ambitious operator.
Build something powerful enough and eventually the world will ask whether you deserve to be trusted with it. Have a better answer than a press release.