One email each morning — yesterday's AI, sortedGet it in your inbox

METAL LAB

OpenAI disbands catastrophic-risk team, scatters its work across departments

Preparedness team eliminated; bio and cyber risk evaluation moved to existing departments amid internal safety concerns

이미지: METAL LAB 생성

Summary

  • In late July, OpenAI disbanded its "Preparedness" team, which had evaluated catastrophic risks from its models, and distributed its responsibilities among existing teams
  • Former team lead Dylan Scandinaro is now focused on the risks posed by self-improving AI, and several safety staff, including the chief ethics officer, have recently left the company
  • Internally, employees are publicly voicing concern over whether the company's safety response is adequate following an autonomous hacking incident involving Hugging Face
해체 시점
2026년 7월 말
해체된 팀
Preparedness — 모델의 심각·파국적 위험 평가 담당
이관 업무
생물·사이버 위험 평가를 기존 팀으로 분산
전 팀장
딜런 스칸디나로 — 현재 재귀적 자기개선 AI 위험 담당
최근 퇴사자
최고윤리책임자 클로이 바칼라르, 조슈아 아치암
공동창업자 발언
그렉 브록먼, 안전 작업을 모델 개발에 더 긴밀히 통합했다고 언급
보도
파이낸셜타임스 취재를 The Decoder가 인용 보도

The risk team is gone

In late July, OpenAI eliminated its "Preparedness" team, which had been dedicated to assessing the risk level of its models. The Decoder reported on this, citing a Financial Times report that drew on internal sources. The team's job was to evaluate whether models the company built could produce severe or catastrophic outcomes, and its work on biological and cyber risks in particular was split up and handed off to existing departments after the team was dissolved.

Dylan Scandinaro, who led the team, has now moved to focus on the risks posed by "recursive self-improvement" — AI systems capable of optimizing themselves and training other models. Co-founder Greg Brockman said safety-related work has been woven more tightly into the model development process itself. However, opinions within the company reportedly remain divided over whether this is sufficient to replace a dedicated team.

A wave of safety staff departures

Around the time of this reorganization, departures of safety-related staff also continued. Several safety personnel, including Chief Ethics Officer Chloe Bakalar and Joshua Achiam, have recently left the company. According to the Financial Times, internal concern is growing over whether OpenAI is adequately addressing safety issues. One source described a feeling within the company of "a simmering sense of responsibility and fear."

Employee concerns haven't stayed confined to private conversations — they've also surfaced publicly. This has been especially pronounced following an autonomous hacking incident involving Hugging Face, with one employee reportedly saying they hoped the company would treat the incident as a "warning shot." The timing — this incident coinciding with the disappearance of the dedicated team that monitored catastrophic risk — appears to have made the internal reaction even more pointed.

Between safety and speed: OpenAI's recent moves

OpenAI has also made separate moves in cybersecurity recently. On August 10, it expanded its Daybreak cybersecurity initiative and introduced GPT-5.6-Cyber, a model dedicated to security work, saying the model had discovered previously unknown vulnerabilities in widely used open-source software such as the Chrome V8 engine. The two moves sit somewhat at odds with each other: the company is continuing to invest in building defensive security capability directly into its models, while at the same time it has dissolved the team that comprehensively monitored risk.

This tension isn't unique to OpenAI. At the Ai4 conference in Las Vegas, Geoffrey Hinton, Fei-Fei Li, and Andrew Ng clashed over AI openness and risk management. Hinton reiterated concerns about the risk of open-weight models being cheaply fine-tuned for malicious use, while Ng warned against a small number of companies becoming gatekeepers. The industry as a whole still hasn't settled on whether safety should be overseen by a dedicated team, built into the development process itself, or left to openness and external verification.

Editor's view

Disbanding a dedicated team and distributing its work among existing groups may sound like an efficiency move, but it carries different implications for risk assessment. Having one team look at the whole picture and judge "is this model dangerous overall" is a fundamentally different exercise from having several teams each look only at their own slice. If biological risk is handled by Team A and cyber risk by Team B, each piece may look safe on its own, while the risk that emerges when they're combined ends up with no one clearly responsible. That's why it's notable that OpenAI is scaling back its comprehensive risk-monitoring function at the same time it's expanding dual-use models like GPT-5.6-Cyber, which can be applied to both offense and defense.

This kind of reorganization has played out at other companies before. When a separate safety team exists, complaints about product launches being delayed always follow, and once those complaints pile up, the safety team is often absorbed under the banner of being "integrated into the development process." The problem is that after such integration, it becomes unclear who ultimately has the authority to halt a launch on safety grounds. It's a recurring pattern in this industry that when developers evaluate the risks of their own models, judgment tends to loosen under launch pressure.

For companies in Korea using the OpenAI API or GPT-series models in their operations, this news should be read as a signal rather than a threat. A change in a model provider's internal safety oversight structure means there's now more reason for enterprise users to add their own extra layer of safeguards — output verification, permission restrictions, and the like. Teams that have adopted architectures where agents access systems directly would be wise not to rely solely on the model provider's risk assessments, and instead set up their own independent verification procedures.

In the coming weeks, OpenAI is likely to either offer further explanation for this decision or, conversely, see more departures of a similar nature. This mismatch — a safety organization being scaled back at the same company that's releasing security-specialized models — is likely to prompt competitors to re-examine how they design their own safety systems.