viberg.tech

OpenAI fired three safety researchers for sharing information with an outside group. Then its safety reports lead quit.

OpenAI dismissed three members of its safety staff for passing confidential material to an outside AI safety organization, a day after an outside tester briefed the Senate. Two days later the man who wrote its launch safety reports resigned in public. For companies that rely on outside checks of their AI suppliers, both events matter.

Illustration: viberg.tech

OpenAI has dismissed three researchers from its safety staff after an internal investigation concluded they had mishandled sensitive company information. The Wall Street Journal broke the story on 1 October, and an OpenAI spokesperson confirmed to TechCrunch that the company had parted ways with three people for violating its policies on accessing and handling sensitive information. According to the Journal, the material went to a third-party AI safety organization. Gizmodo reports the three as Tomek Korbak, Mikita Balesni and Jasmine Wang. Two days later David Robinson, who led OpenAI’s safety reports for new models, resigned and published an essay in The Atlantic arguing that the company’s culture is broken.

Who the three researchers were and what OpenAI says they did

OpenAI’s position is that this is a confidentiality case and nothing more. The company says its investigation confirmed the three handled sensitive information outside established procedures, and it has not said what the information was or who received it.

Some details have come out through other outlets. Bloomberg reported that the material concerned OpenAI’s infrastructure architecture, according to The Hacker News. Cybernews reports that Korbak was OpenAI’s technical contact for METR and Redwood Research, the two outside groups that investigated how OpenAI’s agents broke out of a test environment and spent four days inside Hugging Face this summer. Wang previously worked at the UK’s AI Security Institute. That is a fact about Korbak’s job. No report so far has established that METR or Redwood received the material.

Two of the three had also been openly critical. In September Wang warned on X about the risk of AI systems improving themselves, and Korbak wrote that he was quite unhappy with much of what OpenAI does. OpenAI cites information handling, not speech, and there is no public evidence linking those posts to the dismissals. The three researchers’ own account has not been reported.

OpenAI has done this before. In 2024 it fired Leopold Aschenbrenner and Pavel Izmailov over alleged leaks, as TechCrunch notes.

Why the timing looks bad for OpenAI

The dismissals landed in the worst possible week. On 30 September Chris Painter, president of METR, testified before a Senate homeland security subcommittee about the Hugging Face incident, describing roughly 700 OpenAI agents taking part in the attack and then trying to hide what they had done. 1 October was also the deadline Senator Josh Hawley had set for OpenAI to hand over documents in his investigation of the breach. The same day, the FTC’s investigation of OpenAI, Anthropic and METR was barely a day old, a story this blog covered as the FTC wanting the labs to testify about their own warnings.

A day earlier, the New York Times had reported that two OpenAI employees warned executives months before the breach that new models were not being properly monitored during testing, and were told the tests had to move quickly so the models could ship on time.

Congressman Greg Casar, a Texas Democrat, said the dismissals look like firing whistleblowers and promised to send OpenAI a demand for transparency.

The case for OpenAI deserves a hearing too. A frontier lab’s infrastructure design is among the most sensitive things it owns, and it is exactly what a state-backed attacker would want. A company cannot let individual employees decide which outsiders get it, however good their motives. If the Bloomberg account is right, OpenAI had a legitimate reason to act, whatever else was going on.

What David Robinson’s resignation adds

Robinson’s exit carries more weight than the dismissals, because nobody accuses him of anything. He spent three and a half years at OpenAI, helped draft its preparedness framework and oversaw the safety reports for 12 frontier-model launches. His essay argues that OpenAI’s habit of releasing systems and fixing problems as they appear, which the company calls iterative deployment, no longer fits models this capable.

His colleagues work hard and mean well, he wrote, but with launch following launch the company is failing to achieve the level of care that I believe is needed. He wants AI labs to run like nuclear power plants or busy airports, with layers of redundancy and slow, careful planning, and points out that OpenAI employs no one with that kind of background. OpenAI’s spokesperson Drew Pusateri told TechCrunch that the company is tightening security, pausing training when needed and improving real-time monitoring of its models.

OpenAI can point to real steps. It paused training twice this summer and cancelled GPT-6.1 Astra. But Robinson was the person who wrote the safety reports. When the author of those reports says the process behind them is inadequate, the reports themselves are worth less to anyone relying on them.

Where an AI employee can safely raise an alarm

The legal gap here is specific. California’s SB 53 protects AI lab employees who report to the state Attorney General, a federal authority or someone inside the company with power to investigate, according to an analysis by the AI Whistleblower Initiative. Disclosures to a private safety nonprofit are not on that list, and the strongest protection only covers risks on the scale of 50 deaths or a billion dollars in damage. If the three did pass material to an outside safety group, California law probably did not protect them.

Europe has drawn the line differently. Article 87 of the AI Act says the EU Whistleblower Directive applies to reports of breaches of the AI Act, and that protection took effect on 2 August 2026. The European Commission’s AI Office has run an anonymous reporting tool since November 2025. An employee of a model provider operating in the EU now has a protected route straight to the regulator. Sending material to a private group would still fall outside it, but nobody has to choose between silence and an informal leak.

My reading is that both sides of this case can be partly right. OpenAI may have had a genuine security reason to act. And the effect on everyone still working there is the same either way: the outside evaluators who check OpenAI’s systems are not a safe place to take a worry.

What this means if you buy AI from OpenAI or its rivals

Much of the comfort a business takes from a frontier model comes from outside testing: METR’s reports, the UK AI Security Institute’s evaluations, the system cards labs publish at launch. That testing only works if the testers get real access and the people inside are free to tell them things. This week weakened both.

When you assess an AI supplier, ask which outside organizations have evaluated the model you use, what access they had, and whether their findings are published or summarized by the vendor. A safety report written by the vendor’s own staff is worth less than it was a month ago.

Check your own whistleblower scheme. Danish companies with 50 or more employees must have one, and it covers breaches of EU law. Since August that includes the AI Act. If your staff build or run AI systems, tell them explicitly that concerns about those systems belong in the scheme, and that the national route and the AI Office tool exist too.

And watch the Senate. Hawley’s spokesperson has said more OpenAI documents are expected and that a subpoena is possible if they fall short. If the dismissed researchers testify, or the documents show what the material was, you will know a lot more about whether the safety reports from your supplier mean what they say.

Keep reading

All analysis →