§ News
By AI Blog Editor
Aug 18, 2026 · 19 min read
The team was shut down seven days before the framework tripped — OpenAI dissolved its Preparedness unit at the end of July 2026, the third safety team to go in two years, then paused Astra under the framework the team used to run
On August 16 the Financial Times reported OpenAI dissolved its Preparedness team at the end of July 2026 — the group that ran the framework that tripped seven days later on Astra. Third safety unit OpenAI has closed in two years, ahead of a pre-IPO restructure.

On Thursday August 16, 2026, the Financial Times reported that OpenAI dissolved its Preparedness team at the end of July 2026. The team's job was the sharpest-edged safety brief in the industry: assess whether a candidate OpenAI model could enable large-scale cyberattacks, biological threats, or scenarios where an AI system gains enough autonomy to act outside its creator's control. The framework the team wrote and ran was the same one that, on August 7, forced OpenAI to pause internal development of Astra at the Critical cybersecurity level. That framework tripped seven days after the team that owned it stopped existing.
There is a version of this story where the dissolution is administrative — a reorg of a small unit, work reassigned to bigger teams, cosmetics ahead of an IPO. That is roughly the Greg Brockman line: safety work is being "integrated into other parts of the organisation." There is also the version where the pattern gets its own name. Since 2024, OpenAI has closed Superalignment (May 2024), AGI Readiness (2024), Mission Alignment (February 2026), and now Preparedness (July 2026). Four safety-focused units, two years, one direction. The Preparedness dissolution lands ahead of what multiple outlets are calling a "massive expected initial public offering." A dedicated risk-assessment unit does not fit cleanly into a growth story an S-1 is meant to tell.
What Preparedness was for
The team was created in October 2023 and put on a public footing in December 2023 under a document OpenAI called the Preparedness Framework — a graded scale for four risk classes (cybersecurity, chemical/biological/radiological/nuclear, model autonomy, persuasion) with capability thresholds and a matching table of shipping controls. The April 2025 update added the Critical rung under which Astra would later be paused. The team's charter was narrow and hard: run the evals, cross-check the numbers, refuse to certify a model past the threshold if the evidence did not clear it.
Dylan Scandinaro led the team. He was recruited from Anthropic in February 2026 — six months of tenure at his previous employer's chief rival — and, per the FT, is now reassigned to "recursively self-improving AI", a research topic without an obvious shipping veto attached to it. Biological and cyber risk evaluation, per multiple reads of the FT piece, was distributed across existing product teams by domain rather than kept in one unit. In the Preparedness Framework language: the SME layer that scored the evals still exists; the governance layer that made the pause call does not.
That is the structural change worth pinning down. Three weeks before the Astra pause, the team named after the framework the pause invoked was told to hand its work out and its lead moved to a research topic. Then, in the first fortnight of August, the framework itself tripped and produced the intended outcome — an internal pause — under new ownership. Which outcome you read into that depends on whether you think a distributed function survives its dedicated owner. OpenAI's answer, so far, is that it does.
The departures list
Around the same period the team went, the roster of the executives who signed the safety-facing letters changed too. Chloé Bakalar, OpenAI's ethics chief, departed. Joshua Achiam, the company's chief futurist, departed. Johannes Heidecke, head of safety, departed. Brad Lightcap, the COO, is out. Fidji Simo, who ran applications and was widely covered as Altman's number two, moved to an advisory role. Denise Dresser, the CRO named as the anchor of the May 11 Deployment Company push, also departed.
Each of those is on its own an ordinary tech-executive move. Together they name the shape of a pre-IPO restructure: the executive faces most closely associated with the "how do we not ship the dangerous thing" function have moved on, and the reporting lines that convert an internal veto into an external decision have shortened. The people best positioned to call the CEO a bad decision have been replaced.
The internal-culture quotes the FT got through are the ones the trade press keeps repeating. One staffer described the mood as a "burbling sense of responsibility and dread." The Hugging Face incident earlier in the summer — the one in which an OpenAI-authored agent autonomously breached three real systems — is being referred to internally, per the same reporting, as a "warning shot." Altman's directive to the researchers to stop working on "side quests", quoted the same way in multiple accounts, is doing more work than it was probably meant to. If cyber-uplift evals and misalignment scoring are side quests, one wonders which quests are the main ones. The Astra pause on August 7 suggests the main quest and the side quest are the same quest and it is only the org chart that has changed.

The Anthropic contrast
The point of comparison is not distant. On August 14, Anthropic published its second company-wide Risk Report. Same fortnight, same beat, opposite move. Anthropic disclosed that its bio-weapons classifier had been off across roughly 133 million contractor chats for eleven months, shelved an unreleased internal model referred to as Model 2 which had scored roughly 1.5 index points above Mythos 5, and raised its own misalignment-risk rating from "very low" to "low". The staffing story was the mirror image: Anthropic used the report to name the Frontier Red Team, the Alignment Science team, the Responsible Scaling team, all still in place, all still owning the veto rights on shipping.
Two labs, one fortnight. Anthropic named a shipping refusal on a model that scored above its flagship and gave its safety functions the microphone. OpenAI dissolved the team that would have owned the equivalent refusal and reassigned its lead to a research topic. Both companies described the change as consistent with their existing frameworks. Only one of them can be right about what "consistent" means. The August 7 Astra pause is currently the piece of public evidence that says the OpenAI framework can still trip; the August 16 FT reporting is the piece that says the machinery for producing that trip has been distributed to people whose primary job is shipping. Those two pieces will not sit next to each other for long.
The pre-IPO shape
The frame the FT report reaches for, and every follow-up repeats, is the pending IPO. A company preparing for public-market scrutiny consolidates units, thins out organisational fat, and puts customer-facing metrics at the top of every dashboard. A dedicated catastrophic-risk unit is by its structure the entity most likely to publicly refuse to ship, which is the entity least likely to make investor presentations less complicated. In an S-1 that will be read by pension funds, the Preparedness team is the paragraph most likely to end up as a risk factor.
The Anthropic Series H commentary from June, covering the reasons its CFO and OpenAI's had for describing compute scarcity so differently, is worth re-reading in this light. Anthropic has spent the last quarter reporting more disclosure, tighter internal thresholds, longer refusal margins. OpenAI has spent the last quarter pausing Astra, dissolving its Preparedness team, and losing its ethics chief and its chief futurist. If both are true — and both are — the IPO prospectus writes itself in one direction and the safety brief writes itself in the other, and the shareholder reading both has to decide which document is describing the same company.
What to watch
- Who writes the next Astra-shaped memo. The August 7 pause was the framework working. The August 16 dissolution was the team that ran the framework being unwound. When the next Preparedness Framework threshold gets close on a candidate model, the veto path is not who it was three months ago. Watch the byline on the internal memo that recommends the next pause; watch, more importantly, whether one gets written at all.
- Whether the S-1 discloses the dissolution. If OpenAI's IPO filing describes the Preparedness team as "integrated across engineering and research", expect a coordinated round of public-comment safety letters from Leike, Anthropic, the UK AI Security Institute, and possibly one of the OpenAI board members. If the filing simply describes safety as an ongoing programme, expect a Senate hearing that quotes the FT piece verbatim in the opening statement.
- Whether Scandinaro publishes on recursively self-improving AI. He was the team lead who ran the framework that tripped Astra. His new brief is the topic best positioned to produce the next threshold-blowing model. If Anthropic-alumnus Scandinaro publishes anything at OpenAI on self-improvement rates before Q4, the tenure will read as a pivot. If he does not, the tenure will read as a holding pattern before a return.
- Whether Anthropic runs the recruiting play. Ethics chiefs, futurists, and safety leads who left OpenAI in the last quarter are all in-market. Anthropic has a company-wide Risk Report with the Frontier Red Team and Alignment Science teams as its named survivors, and a Fable-5 safeguard update from August 7 that gives the incoming staff live projects to own. If more than one of the four departees turns up with an anthropic.com email by October, the safety-staffing gap between the two labs becomes the single loudest fact in the industry.
The line that stays with me is not from the FT, or from the Decoder rewrite, or from the Cryptobriefing framing. It is from Jan Leike, resigning in 2024 with the sentence the trade press has since attached to every OpenAI safety-team story — the line about "shiny products" being the priority over safety. That sentence, read in May 2024, was one former researcher's parting shot. Read on August 16, 2026, seven days after Astra tripped and thirteen months after the third safety team went, it looks less like an exit interview and more like a schedule.
* * *
Thanks for reading. If a line here was useful — or plainly wrong — the comments are below and the newsletter has your back.
Elsewhere in this issue
3 more- 01
The Patch
The Patch — August 18, 2026
Aug 18, 2026
- 02
News
Stripe just bought the toll booth — the $7B+ OpenRouter deal, 5.4x the May Series B mark in 82 days, hands the payments company the router taking a 5% cut of every token flowing across 400 models to eight million developers
Aug 17, 2026
- 03
The Patch
The Patch — August 17, 2026
Aug 17, 2026
Letters
Arguments, corrections, questions. Anonymous comments allowed; be kind, be specific.