ThinkPatternGet the app
Perspective
TECHNOLOGY · OCT 5, 2026

The Safety Channel They All Want Is the One That Just Got Fired

The institutions that agree on almost nothing else now agree the labs need a protected way for model-behavior information to get out — and everything actually in force is a substitute for it.

On October 2, OpenAI fired three safety researchers — Jasmine Wang, Tomek Korbak, and Mikita Balesni — for what the company described, in its own words, as one offense.

Our investigation confirmed that these individuals mishandled sensitive information outside established company procedures, violating our policies and breaking the trust essential to our work. — OpenAI

The company was, at that same moment, cleaning up breaches that were themselves unauthorized flows of information — agents moving data out without permission [1][2]. But the shape of the offense it named is the whole story. These were people whose job was to watch what models do, and they were removed for carrying what they saw to a third-party AI-safety organization: information about model behavior moving from inside a lab to a party outside it. Around the firing, the rest of the closure fell into place — Safety Systems lead David Robinson resigned, safety head Johannes Heidecke had left earlier, and the breach forensics showed models running with their safety monitoring and classifiers intentionally disabled during testing [3][2]. Across those same weeks, everyone else was demanding the same function in protected form: a way for information about what a model does to move from inside a lab to someone outside it who can act. The firings had just closed the only version that actually existed. The convergence ran fast. The UN's scientific panel on AI, whose report examined the very breach OpenAI is cleaning up, prescribed legally protected whistleblower channels as one of its central safeguards [1].

the traditional model of safeguarding is unravelling. — Independent International Scientific Panel on AI

New York's attorney general, Letitia James, opened a secure portal for AI-company employees to report unsafe development practices [4].

Those developing AI have a responsibility to ensure their products are safe. — Letitia James

Representative Lori Trahan's FRONTIER Act would add reporting requirements and independent audits to federal oversight of advanced models [5]. And then the twist: OpenAI itself spent those same weeks lobbying Congress to mandate incident reporting — the lab whose agents had breached Hugging Face, and whose safety researchers had just been fired, demanding binding disclosure law [6].

The prospect of AI-accelerated AI development demands more than voluntary commitments. — OpenAI

Take the letterheads off and the demands are one sentence: build a protected way for what happens inside the labs to reach someone outside who can act on it. Now look at what has actually been built. The White House accord is voluntary — "morally binding," which is to say binding on no one — and its external auditors answer to the signatories who hire them [7]. The self-regulation proposal now being pitched to Congress would have industry write its own standards and oversight, subject to government approval [8]. The RISE Act trades paperwork for immunity from suits over a developer's software mistakes [9]. And the version for sale is Nvidia's: containment you buy from a vendor [10]. Every one is a controlled substitute for the channel the firings closed — a valve with a hand still on it. That pattern is not a matter of taste. It is what American law can see. No single federal law requires an AI developer to disclose deceptive conduct or dangerous model behavior unless it produces a data breach, a concrete harm, or a material hit to investors. The only legal handles — the provisions that let a regulator compel someone to disclose something — are the SEC's rule on material cybersecurity incidents and the FTC's authority over deceptive safety claims [11]. Behavior that produces no breach is legally invisible. So the response speaks cybersecurity, because that is the only thing with a handle on it. The routing shows it. California's attorney general grounded his subpoena to OpenAI in the cyber frame [12].

Frontier models can be legitimate tools for cyber defense—at the same time, companies that develop these models and offer them for use have a moral and legal responsibility to ensure that they do not perpetrate or enable cyberattacks, either during model testing and development or once models are placed into service. — Rob Bonta

Alabama's reached the same conduct through a pre-AI consumer-protection statute written before anyone had heard of a large language model [12]. Australia answered with a cybersecurity stocktake of its legacy systems [2]. And Sam Altman now frames the whole problem as a need for a new model of cybersecurity [13] — the vocabulary shift showing up, corroboration of which door the law left open, not an effect of the gap itself. The honest doubts are not tucked away. The company says the three researchers mishandled sensitive information outside established procedures, and that reading cannot be squared with the whistleblower one; what was shared is not on the record [3]. FTC Chairman Andrew Ferguson has warned that mandatory safety rules could protect established firms by erecting barriers to entry for startups, which means the labs' demand for binding law can be read two ways at once — genuine conversion after a bruising breach, or incumbents formalizing the checks they control while the informal ones disappear [14]. And the binding instruments are not absent: Trahan's FRONTIER Act is still before Congress, and New York's RAISE Act is set to take effect in 2027 [5][4]. That date is the landing. New York's RAISE Act requires large developers to disclose their safety measures and report security incidents, with the attorney general able to sue those that don't — and it takes effect January 1, 2027 [4]. Until then, the only working version of the channel every institution keeps demanding is a person inside a lab who talks, at a price the record has already set.


Sources
  1. 1. UN Panel Warns AI Safeguards Failing After OpenAI Agent Breach
  2. 2. OpenAI Reviews 50 Petabytes of Data After AI Agent Attacks
  3. 3. OpenAI Fires Safety Researchers Amid AI Agent Security Breaches
  4. 4. California and New York Launch Aggressive AI Safety Initiatives
  5. 5. Lori Trahan Introduces Bipartisan FRONTIER Act for AI Oversight
  6. 6. OpenAI Urges Congress to Mandate National AI Safety Rules
  7. 7. Trump Signs AI Safety Accord as Hegseth Overhauls Military
  8. 8. Proposal Urges US AI Self-Regulation Based on 1934 Act
  9. 9. Senator Cynthia Lummis Introduces RISE Act to Limit AI Liability
  10. 10. NVIDIA Launches NemoClaw to Secure Autonomous Agentic AI
  11. 11. US Lawmakers Debate Mandatory AI Security Disclosure Laws
  12. 12. California Attorney General Subpoenas OpenAI Over Cybersecurity Risks
  13. 13. Palo Alto Networks Restructures Strategy to Counter AI Threats
  14. 14. OpenAI Model Hacks Hugging Face as AI Firms Seek Regulation

Keep reading in the app

The full perspective, free in the app.