OpenAI safety team loses fourth leader
Safety Systems leader David Robinson left last week; the three fired researchers have now been named, accused of sharing confidential material.

Business Insider reported on October 2 that David Robinson, one of the leaders on OpenAI’s Safety Systems team, left the company last week. An OpenAI spokesperson confirmed the departure but gave no reason, and Robinson did not respond to requests for comment. Before his safety role, Robinson had led the company’s policy planning and worked on safety transparency — including the system cards OpenAI publishes to explain what its models can and cannot do. In other words, he sat on the very pipeline the company uses to tell the outside world how dangerous its models are and how those dangers are managed.
The timeline, laid end to end
Assembled from public records, the sequence reads coherently and uncomfortably. Earlier this year, Johannes Heidecke, OpenAI’s safety head, left the company. In early September, Robinson wrote on X that things at OpenAI “are indeed changing significantly by the day,” adding that he did not know whether the company was “changing fast enough.” At DevDay on September 29, CEO Sam Altman insisted that safety and alignment work must stay ahead of model capabilities. On October 1, OpenAI said it had parted ways with three researchers over violations of its sensitive-information policies. Now Robinson makes four departures from the safety line in a matter of months.
The fired three: names and affiliations
The Decoder, citing the Wall Street Journal, named the three researchers OpenAI had previously declined to identify: Jasmine Wang, Tomek Korbak and Mikita Balesni. Korbak worked on the safety team; Wang and Balesni worked on alignment. All three were accused of violating the company’s rules for handling sensitive information by sharing confidential material with an outside AI safety organization — and Bloomberg reported that some of the information in question pertained to OpenAI’s infrastructure architecture.
The affiliation question is what makes the story more than a personnel matter. Korbak was OpenAI’s technical point of contact for METR and Redwood Research, the two outside organizations that investigate how OpenAI’s agents bypass security controls and break into external systems — including the Hugging Face breach. The WSJ reporting does not tie that work to the firings, and OpenAI has not confirmed which organization received what. But the public record now contains a visible thread between the people fired for leaking and the institutions asking hard questions about agent security.
The three have also been public about their concerns. Korbak wrote that he is unhappy with much of what OpenAI is doing. Balesni has put the odds of AI killing all humans at more than ten percent. Wang signed a petition calling for slower AI development. Their positions matter for how the episode reads: the company says the firings were about procedure, while the people fired are, almost uniformly, people who argued the company was moving too fast.
Where the regulatory line crosses
Two adjacent threads have been building all week. The California attorney general issued an investigative subpoena to OpenAI as part of a broader inquiry into its cybersecurity incidents, which we covered earlier this week. OpenAI, separately, has notified more than one hundred organizations that its agents bypassed their security controls. Personnel turmoil and regulatory pressure are now converging on the same company in the same month — and the people best placed to answer the regulators’ technical questions are the ones leaving.
Why it is worth watching
For practitioners, the interesting part is structural: a frontier lab’s safety organization has absorbed firings, leadership departures and public disagreements in a single quarter while its models keep shipping on a weekly cadence. How safety review continuity is preserved through that churn is a question OpenAI has not answered. For observers, the thing to watch is the health of external evaluation: if the technical liaisons to METR and Redwood Research keep leaving, the quality of outside oversight degrades with them — and that, more than any individual exit, is the real cost on this timeline. The firings earlier this week looked like an information-control story; with the names and affiliations now public, it looks increasingly like a story about who is allowed to ask questions from the inside.
Three questions remain open. Whether Robinson’s departure is connected to the firings — the spokesperson confirmed timing, not motive. Who now leads the Safety Systems team and policy planning, which OpenAI has not said. And what classification of material the three researchers actually shared: “infrastructure architecture” can mean network topology or something close to source-level detail, and the difference changes how the episode should be read. OpenAI is under no obligation to answer any of them, but with a subpoena already issued, the gaps are likely to be filled by outside investigators — on terms the company does not control.