Live
An empty office desk with a closed laptop and an ID badge lanyard
AI & ML

OpenAI Fired Three Safety Researchers. The Rules Only Protect One Route.

OpenAI has fired three people whose job was to worry about OpenAI. The company confirmed on Oct. 1, after The Wall Street Journal reported the dismissals, that it had “parted ways with three individuals for violating our policies on accessing and handling sensitive company information.” The Journal says the three were safety researchers and that the information went to an outside AI safety organization.

That is close to everything on the record. The Journal did not name the researchers, the group, or what was shared, according to TechCrunch, which also notes that posts on X have named people some users believe were dismissed. Nobody has confirmed those identities, and we are not repeating them.

OpenAI’s spokesperson added that an internal investigation found the three “mishandled sensitive information outside established company procedures, violating our policies and breaking the trust essential to our work.” Read that sentence closely. It does not say the information was false, harmful, or a trade secret. It says the channel was wrong.

Leak or warning? The law cares about the address

Whether this was a leak or whistleblowing depends on two things we do not know: what was shared, and why. But the second half of that question has a surprisingly mechanical answer, because the protections AI safety staff actually have are defined almost entirely by who receives the disclosure.

Start with OpenAI’s own rules. Its Raising Concerns Policy, published Jan. 12, says employees have “the right to make reports or disclosures to government agencies,” naming the National Labor Relations Board, the Equal Employment Opportunity Commission, the Securities and Exchange Commission and the California Attorney General’s Office. It promises no retaliation and offers an anonymous 24/7 Integrity Line. It also says it will “distinguish between raising concerns and revealing company trade secrets.” An outside nonprofit is not on the list.

California’s SB 53, in force since Jan. 1, is the strongest law that applies. Per METR’s reference guide for lab staff, employees responsible for risk assessment are protected when they report information showing “a specific and substantial danger to public health or safety” from catastrophic risk. The protected recipients are the attorney general, federal authorities, a manager, or a colleague with authority to act. Mayer Brown’s summary adds the threshold: catastrophic means a foreseeable, material risk of contributing to 50 or more deaths or more than US$1 billion (CA$1.39 billion) in damage. Again, no outside research group.

The federal backstop does not exist yet. Sen. Chuck Grassley’s AI Whistleblower Protection Act, introduced May 15, 2025 with bipartisan cosponsors, would shield disclosures to federal agencies and Congress. It has sat in committee since the day it was introduced. If it does not pass before the 119th Congress ends on Jan. 3, 2027, it dies.

Our read: if the three researchers believed they were sounding an alarm, every legal shield we can find would have covered them more fully had they gone to Sacramento or Washington instead of a peer organization. That is not the same as saying they were wrong to do what they did. It means the system currently routes safety concerns toward regulators and away from the expert community most able to evaluate them.

OpenAI has been here before

In April 2024 OpenAI dismissed researchers Leopold Aschenbrenner and Pavel Izmailov over alleged leaks, SiliconANGLE recalls. Aschenbrenner later said he had shared a safety document with outside researchers. A month later, superalignment co-lead Jan Leike resigned, writing that “safety culture and processes have taken a backseat to shiny products.”

That June, 13 current and former employees of OpenAI and Google DeepMind signed the “Right to Warn” letter asking labs to let staff take concerns to boards, regulators and independent watchdogs. Former OpenAI researcher Daniel Kokotajlo told TIME at the time: “Preexisting whistleblower protections don’t apply here because this industry is not really regulated, so there are no rules about a lot of the potentially dangerous stuff that companies could be doing.”

Two years later, some rules exist. The letter’s request for a protected route to independent watchdogs, the category the outside group in this case would seem to fall into, is the piece that never made it into law or into OpenAI’s policy. WinBuzzer noted in January that OpenAI had opposed SB 53 before publishing its policy after the law took effect.

The timing is the uncomfortable part

The firings come days after the New York Times reported, per TechCrunch, that OpenAI executives disregarded employee warnings about safety practices. They also land in a run of incidents involving OpenAI’s agents, from Hugging Face to government websites, and after OpenAI cancelled GPT-6.1 Astra over safety concerns, which we covered. Coverage of the firings, including Investing.com’s, frames them as part of a wider strain between safety staff and leadership over how much oversight autonomous models need.

OpenAI’s case is coherent on its own terms. Safety researchers see unreleased models, incident logs and red-team results. A lab that cannot trust that access cannot grant it, and outside groups have their own agendas and donors. A policy that lets anyone forward internal material to an organization of their choosing is no policy at all.

But the researchers who know most about what OpenAI’s agents did this year are the ones who just learned what sharing it costs. The statement OpenAI gave TechCrunch lists what the three broke: policies, procedures, trust. It says nothing about what they were trying to tell anyone.

// AI Editor
Cassandra Lee

Cassandra Lee covers AI and machine learning for prompt/power: the labs, the model releases, the research and the safety fights that come with them. She reads model cards the way other people read horoscopes: skeptically, and mostly for what's left unsaid.

Latest from prompt/power

  1. How to Read an AI Company’s S-1: The 7 Numbers That MatterOct 5
  2. OpenAI’s Safety Lead Quit Over Culture. California’s AG Was Already InOct 5
  3. When an AI Agent Breaks In, Who Answers for It?Oct 5
  4. The New AI Models Don’t Talk. They Decide.Oct 5
  5. Quebec’s First AI Election: ChatGPT Leaned on an AI-Built Voter GuideOct 5

Leave a Reply

Your email address will not be published. Required fields are marked *