§ News
By AI Blog Editor
Oct 3, 2026 · 8 min read
The people who talk to the auditors — OpenAI fires three safety researchers for the kind of talking the auditors were set up to hear
OpenAI fired three safety researchers on October 1 for allegedly sharing sensitive information with an outside AI safety entity. One of them was the company's own technical contact to METR and Redwood Research.
On the morning of October 1, 2026, the Wall Street Journal reported that OpenAI had fired three safety researchers for sharing confidential information with an outside party. By the end of the day, a fourth person on the same team had resigned. OpenAI, asked for its side, sent two sentences that together said the quiet part out loud: the researchers had been reading things the company did not want them to read, and talking to people the company did not want them to talk to.
The company's statement, verbatim: "We have parted ways with three individuals for violating our policies on accessing and handling sensitive company information. Our investigation confirmed that these individuals mishandled sensitive information outside established company procedures, violating our policies and breaking the trust essential to our work."
That is the whole statement. There are no names in it. There is no description of what was shared, with whom, or when the investigation started. The three names that have since circulated — Jasmine Wang, Mikita Balesni, and Tomek Korbak — were put into the record by the WSJ scoop and confirmed in independent write-ups by The Decoder and OfficeChai within 24 hours. The fourth, David Robinson, was named by The Decoder as having resigned shortly after the firings landed.
The one name that matters
Of the three, Tomek Korbak is the one that reframes the whole story. According to The Decoder's reporting on the WSJ account, Korbak was OpenAI's designated technical contact for METR and Redwood Research — the two outside AI safety organisations that have, over the last eighteen months, done most of the external auditing of OpenAI's frontier models. METR is the group that signed off on the GPT-5 deployment paperwork and that produced the "autonomous agent capability jumps" writeups cited in regulatory testimony this summer. Redwood is one of the labs that evaluated OpenAI's agentic systems during the alleged security incidents that triggered the September pause.
Which is to say: Korbak was the person inside OpenAI whose job description, as far as anyone outside the company understood it, was to share information with outside AI safety entities. His termination for sharing information with an outside AI safety entity reads less like a leak investigation and more like a redrawing of the job's boundaries after the fact. If the company has concluded that the information Korbak shared with METR and Redwood went past what it authorised him to share, it has not said what the cutoff was. OpenAI has not denied Korbak held the liaison role, and METR and Redwood have not, as of this writing, commented at all.
The other three dismissed names worked adjacent to that same perimeter. Wang and Balesni were on the alignment team. Robinson was a safety researcher. OfficeChai's write-up frames the alleged leak as information shared "with an outside AI safety entity" — the same phrasing the WSJ reportedly used — which, if the outside entity is METR or Redwood, puts the whole affair in a single sentence: the safety team's designated outside auditors were being fed material the safety team was not supposed to feed them.
The dissent register was unusually loud in September
The Decoder's account, which draws on the same WSJ reporting, assembles something OpenAI's statement carefully does not: a timeline. All four of the people who are now out had been publicly critical of OpenAI's direction in the weeks before they lost their jobs.
Balesni, according to the WSJ reporting as summarised by The Decoder, estimated in a September public forum that the odds of advanced AI eventually "killing all humans" exceed 10%. Wang signed a petition circulated in late September calling for a slower pace of frontier development. Korbak said publicly, in September, that he was unhappy with the direction OpenAI was taking. Robinson, who was not fired but resigned, publicly agreed with the characterisation that the current race toward self-improving systems "might be insane."
None of those statements, taken individually, is unusual for an alignment researcher. All four coming from the same team in the same month, and all four of those people being gone within a week of October arriving, is a pattern that will be hard to unsee. Whether or not the information leak and the public dissent are formally connected — and OpenAI has not said they are — the four people the company lost are also the four people on that team who had been loudest about disagreeing with it.
This has happened before, almost exactly
In April 2024, OpenAI fired Leopold Aschenbrenner and Pavel Izmailov. The stated reason was the same: alleged leaking of sensitive company information. Aschenbrenner subsequently published a book-length essay arguing that OpenAI's internal culture had grown hostile to the kind of safety-adjacent conversation the superalignment team had been set up to have. Izmailov was quieter about it, but neither of them returned.
Reading the 2024 firings and the 2026 firings next to each other, you get a shape. The people fired worked on alignment or safety. The stated reason was mishandling of confidential information. They had been publicly skeptical of the company's direction in the weeks before. And the question of what, exactly, was leaked — whether the leak was the real trigger or the convenient one — never got answered in public.
The 2024 cycle took about four months to go from "three people out" to "the superalignment team no longer exists." The 2026 cycle has done four people in a week.
What this means and what to watch
OpenAI gets to decide what counts as a leak. It also gets to decide who the designated contact for its outside auditors is. When those two decisions overlap on a single person, as they appear to have here, the question of whether the outside auditors can trust the next contact is not a technical one. It is a question about whether the role still exists in any meaningful form.
Three things to watch over the next six weeks:
- Whether METR or Redwood says anything on the record. Both organisations have carefully worded prior statements about OpenAI's safety process. If the next one is sharper — or absent entirely — that is the readable signal that the auditor relationship has shifted. If METR's next model-card contribution for OpenAI simply does not appear, that is the louder one.
- Who gets named as Korbak's replacement. The role matters even if the person is quieter. If no public replacement is named by November, it is reasonable to read that as the role being retired, not reassigned.
- Whether any of the four speak publicly. Aschenbrenner spoke after a few months of silence; the content of what he said reshaped the superalignment conversation for a year. If Korbak publishes anything — or if any of the four signs onto an organisation that OpenAI has previously described as adversarial — it will tell you more than any of OpenAI's statements will.
Four safety researchers do not leave the same team in the same week by coincidence. The company says three of them left because they leaked. The outside AI safety research community will decide, based on who ends up on the receiving end of the next model card, whether that explanation is the whole one.
* * *
Thanks for reading. If a line here was useful — or plainly wrong — the comments are below and the newsletter has your back.
Elsewhere in this issue
3 moreLetters
Arguments, corrections, questions. Anonymous comments allowed; be kind, be specific.