Press Esc to close

OpenAI fires three safety researchers it says mishandled sensitive company information

Illustration of a grey folder holding a document, sealed with a white padlock whose shackle is cracked open, with small glowing squares of data drifting out of the gap against a dark background

Illustration: TechcityAuthority

OpenAI has fired three researchers who worked on safety after they allegedly shared confidential company information with an outside AI safety organization, according to The Wall Street Journal. Engadget called it an irony "almost too perfect to be believed," given how much heat OpenAI is taking over its own models misbehaving.

OpenAI isn't denying it. "We have parted ways with three individuals for violating our policies on accessing and handling sensitive company information," a spokesperson said, adding that an investigation "confirmed that these individuals mishandled sensitive information outside established company procedures." The company also told CBS News that its safety teams see internal insights that depend on deep trust.

The WSJ named the three as Jasmine Wang, Tomek Korbak and Mikita Balesni, AFP reported. OpenAI hasn't confirmed the names, and none of them has commented publicly. The BBC says it understands they weren't let go for raising safety concerns. Still unknown: what was shared, and with whom.

One group sits close to this story, though. After OpenAI's agents hacked Hugging Face in July, two staffers from METR, a research nonprofit that measures whether AI systems could cause catastrophic harm, and Redwood Research's Ryan Greenblatt spent six days inside OpenAI and published an independent report. METR says it took no payment for it. Korbak has said he was OpenAI's technical contact for that investigation:

To be clear, nobody has tied the firings to that work, and there's no indication that METR or Redwood was the group involved.

Here's what makes this awkward for OpenAI: it's actively asking for outside scrutiny. Last month it published principles for third-party safety assessments, saying it has given assessors "unprecedented levels of confidential data," while asking them for "enforceable confidentiality protections." OpenAI wants outsiders to see more, but through channels it controls. That's the line it says these three crossed, days after it shelved GPT-6.1 Astra over safety concerns. All three had also been outspoken on X; in September, Korbak wrote that he was "quite unhappy with much of what OpenAI does."

We've been here before. In 2024, OpenAI fired Leopold Aschenbrenner and Pavel Izmailov over alleged leaks. Aschenbrenner later said the "leak" was a safety brainstorming document he'd shared with three outside researchers. That May, Vox revealed exit paperwork that put departing staff's vested equity at risk unless they signed strict non-disparagement terms, which OpenAI then dropped. Then came the Right to Warn letter from current and former lab staff, and a whistleblower complaint to the SEC over OpenAI's NDAs.

What the law protects, and what it doesn't

The rules have changed since then. California's SB 53 whistleblower protections, in force since January 1, 2026, stop frontier AI developers from gagging or retaliating against employees responsible for assessing safety risks when they report a catastrophic-risk danger or a breach of the state's AI safety law. Big labs must also offer an anonymous internal reporting channel.

But the protected recipients are specific: the state attorney general, federal authorities, a manager, or a colleague with authority to investigate. An outside safety nonprofit isn't on that list.

That's the practical lesson for anyone on a lab safety team. If you're worried, SB 53 covers going to regulators or up the chain, not handing material to an outside group, even a safety-focused one. As TechCrunch notes, it's unclear whether the three raised concerns internally first. Until they speak, we're only hearing OpenAI's side, and this becomes a test of how much independent scrutiny OpenAI is really willing to accept.

Comments