Three former OpenAI safety researchers—Jasmine Wang, Mikita Balesni and Tomek Korbak—have published an open letter disputing the circumstances of their dismissals and warning that the company’s handling of the episode could make remaining staff less willing to speak up.
The dispute centers on a difficult boundary for any organization working on advanced AI: how to protect sensitive internal information while allowing researchers to raise concerns, challenge decisions and engage with independent safety specialists. The former employees argue that OpenAI’s public communications about their dismissal may have created uncertainty over that boundary. OpenAI, meanwhile, has said the employees violated policies governing access to and handling of sensitive company information, undermining trust needed for its work.
That is more than a workplace disagreement over process. The researchers contend that clear channels for dissent and external scrutiny are essential where the subject is frontier AI safety. Their letter asks OpenAI to preserve those channels rather than treating the dismissals as a reason to retreat from outside partnerships.
What the former researchers are challenging
OpenAI dismissed the three employees last week after alleging they had shared information with an external AI safety organization. In its statement, the company said the dismissals concerned policy breaches involving sensitive company information and a violation of the trust central to its work.
Wang, Balesni and Korbak reject the premise that their actions fell outside accepted practice. They say they acted in accordance with OpenAI’s mission and with the working norms in place at the time. More specifically, the letter says their interactions with outside parties occurred through coordination and discussion with board members and senior leadership.
The group also denies being the source for reporting about OpenAI architectures described as less monitorable. They say they do not believe they communicated externally beyond their mandate. Wang further says she notified an executive after accidentally clicking on a sensitive email.
Those are the former employees’ account of the events, not an independently resolved finding. The available statements present two sharply different interpretations: OpenAI frames the matter as mishandling sensitive material; the researchers frame it as safety-focused conduct within an established culture of consultation and candid disagreement.
Why the language around the dismissal matters
The central warning in the letter is about a chilling effect. In this context, that does not mean a formal ban on safety criticism. It means employees may decide not to raise concerns, not to question a direction, or not to consult appropriate outside expertise because they fear professional consequences or do not understand the rules.
The former researchers say the public nature of the company’s communications has left former colleagues afraid to speak or operate as they previously did. They describe an earlier environment in which researchers could openly disagree about safety and were encouraged to draw on independent safety organizations’ expertise.
The difference is consequential. A policy can technically permit internal escalation while still being ineffective if workers cannot tell what communication is protected, what material is restricted, who has authorized outside contact, and whether an honest mistake will be treated differently from misconduct. The letter argues that employees are now unclear about where they stand.
Wang expanded on that concern in posts on X, saying OpenAI leadership had indicated agreement with the letter’s recommendations while she remained worried about the company’s openness. She argued that the message employees could take from the dismissals is that raising concerns or working closely with external safety organizations might put their jobs at risk without a clear explanation.
Third-party auditors are at the heart of the request
The former employees’ recommendations focus heavily on independent safety review. They call on OpenAI to honor public commitments to embed third-party safety auditors and not to use this incident as a justification to step back from such partnerships.
A third-party safety auditor is an outside group or expert brought in to evaluate systems, practices or claims. Independence matters because an external reviewer can provide a perspective that is not wholly controlled by the company building the technology. But independence also introduces practical governance questions: auditors need enough access to do meaningful work, while the company must set legitimate controls around confidential information, system security and access permissions.
The open letter does not argue that all information should be freely shared. Rather, its authors argue that OpenAI should maintain its external safety relationships and give employees a clear, transparent framework for participating in them. The distinction is important. A company may have valid confidentiality obligations, but rules intended to protect information can also become counterproductive if they are too vague for safety personnel to know how to seek outside input responsibly.
For workers, the practical issue is authorization. A healthy process would make clear which outside organizations are approved, who may communicate with them, what types of material can be discussed, what needs prior review, and how staff should report accidental exposure to sensitive material. The former researchers’ description of coordination with board members and the C-suite suggests that they believe such authorization and discussion existed in their case. OpenAI’s stated rationale indicates it sees the conduct differently.
Monitorability is not just a technical buzzword
The letter also urges OpenAI to preserve the monitorability of frontier models. The supplied information does not detail the architectures at issue, so it would be premature to draw conclusions about any particular system. Still, the term is central to understanding the researchers’ concern.
Monitorability broadly refers to the degree to which a model’s behavior, operation or relevant internal signals can be observed and assessed. For safety teams, a model that is easier to monitor may offer more opportunities to identify concerning behavior, investigate failures and evaluate whether safeguards are functioning as intended. A less monitorable system could make that work harder.
Frontier models are advanced AI systems at the leading edge of capability. The label is useful because it highlights that safety questions may become more demanding as systems grow more capable or are used in more consequential settings. It does not, by itself, establish that a model is unsafe. It does mean that the quality of monitoring, evaluation and oversight can become especially important.
The former employees’ appeal therefore combines organizational and technical concerns. On the organizational side, they want a culture where safety researchers can challenge choices and collaborate with the wider safety ecosystem. On the technical side, they want systems to remain amenable to observation and evaluation. Their argument is that these goals reinforce one another: researchers need both room to flag risks and technical visibility into what requires scrutiny.
The wider stakes for AI organizations
This dispute arrives amid scrutiny of serious and potentially illegal AI-agent hacks affecting Hugging Face and other organizations. Those incidents have made questions about AI security, capability and oversight more prominent, while also putting companies under pressure to protect sensitive systems and information.
That context makes the disagreement harder to reduce to a simple choice between openness and security. Both are real needs. Sensitive information cannot be handled casually, particularly when advanced AI tools and security incidents are involved. At the same time, a safety program depends on people being able to surface bad news, challenge assumptions and seek specialized review through well-defined channels.
The key issue exposed by the letter is whether a company can make those channels concrete enough to be trusted. A broad instruction to protect confidential material is not necessarily the same thing as a workable protocol for a safety researcher confronting a concern that may benefit from independent expertise. Likewise, an appeal to openness is not a substitute for controls around what can be shared and under which authority.
For other AI labs and technology companies, the episode points to several practical governance lessons. Policies for external safety engagement should be explicit rather than informal. Employees should know the escalation path when they believe a safety issue needs independent attention. Leaders should distinguish alleged intentional disclosure from an accidental access event, while also communicating standards consistently. And public statements around disciplinary action need to account for the possibility that they will shape the willingness of other employees to report difficult issues.
- Clear scope: define which kinds of external engagement are permitted and which require prior approval.
- Documented authorization: make it possible to establish who approved a discussion and what information was in scope.
- Safe escalation: give researchers a route to raise concerns if ordinary management channels are implicated or insufficient.
- Independent review: preserve meaningful roles for outside safety auditors without abandoning information-security safeguards.
- Careful communications: explain policy enforcement without creating unnecessary ambiguity for staff trying to act responsibly.
An unresolved conflict over culture
The three researchers say they were proud of an OpenAI culture that welcomed safety concerns, open disagreement and input from independent organizations. Their letter says they fear that culture is changing. OpenAI’s public position, by contrast, is that the dismissals followed breaches of rules designed to protect sensitive information and the trust on which the organization relies.
Neither side’s statement alone settles the underlying factual disagreement. What is clear is that the dispute has put the company’s internal safety culture under a brighter light, including attention from lawmakers. The question now is not only what happened in these specific cases, but whether OpenAI can offer staff and outside partners a credible account of how safety criticism, independent review and confidential information handling are meant to coexist.
The situation also lands within a broader technology-industry conversation about corporate power, internal dissent and public accountability. Recent platform disputes in the tech sector likewise show how decisions made inside major companies can carry consequences well beyond their immediate business operations.
For Wang, Balesni and Korbak, the requested remedy is straightforward in principle: continue third-party auditing commitments, protect monitorability in advanced models and maintain a transparent dialogue between internal researchers and the broader safety community. Whether OpenAI adopts those requests—and how it defines permissible external engagement going forward—will determine whether the letter becomes an isolated personnel dispute or a turning point in how its safety operation is perceived.






