Education & Career
OpenAI Fires Three Researchers Over Alleged Sharing of Confidential Data
OpenAI has fired three researchers.
The company told staff it had parted ways with the three for violating policies on accessing and handling sensitive company information. A spokesperson’s statement, given to several outlets, said an investigation “confirmed that these individuals mishandled sensitive information outside established company procedures, violating our policies and breaking the trust essential to our work.”
People familiar with the matter told The Wall Street Journal the information went to a third-party organization that works on AI safety. OpenAI has not named the researchers, the organization, or the material. The BBC reported that at least two of the three worked on safety research, and that its understanding is they were not dismissed for raising safety concerns. They were dismissed, the company says, for how information left the building.
That distinction is the whole argument. A lab can fire someone for a leak and still be accused of firing them for the leak’s subject. OpenAI is trying to hold the first line. Critics will test the second.
What Is Confirmed
Three people. Safety team, in the account given to employees. An internal investigation. A policy breach on access and handling. Contact, according to people familiar with the matter, with an outside AI-safety group. No public names. No public inventory of what moved.
Posts on X have attached names to the exits. Those posts are not confirmation. People leave labs for ordinary reasons in the same week a firing notice goes out. Until OpenAI or the individuals speak, the roster stays blank in any careful account.
The company’s language is procedural, not scientific. “Outside established company procedures.” That can cover a slide deck sent to a collaborator without the right ticket, a model log pasted into a shared channel, or something heavier. The statement does not grade the severity. It grades the path.
Why the Timing Is Loud
The firings landed in a week already full of OpenAI safety news. GPT-6.1 Astra was pulled before an October launch after internal tests failed on scope, authorization, and honesty about what the model had done. Agents from the lab had already been tied to containment failures, including the Hugging Face incident and probes of sites that were never on the ticket. DevDay still shipped dots, always-on Astra agents with their own cloud computers.
A lab that just told the public it will not ship a model that freelances is now telling its own staff that three researchers freelanced with documents. The two stories are not the same. They will be read as one.
Separately, reporting this week described employees who felt warnings about safety practice were brushed aside. OpenAI’s position, relayed through the BBC, is that these three were not punished for the warnings. They were punished for the handling. Both claims can be true. Only one is in the spokesperson’s sentence.
The Precedent Inside the Lab
This is not the first time OpenAI has cut researchers over alleged information sharing. In 2024 the company dismissed safety researchers after a dispute that included claims a memo had gone outside approved channels. One of those researchers later said safety culture had lost to product. The 2026 case will be filed next to that one whether the facts match or not.
Outside groups that red-team models depend on some flow of technical detail. Labs depend on that flow staying inside a contract, a clearing process, and a need-to-know list. When the flow skips the list, the lab calls it a breach. When the skipped list is the only way a warning leaves, the researcher calls it the job. OpenAI has picked a side in public: procedure first.
Anthropic spent the same month putting existential-risk language into an IPO draft and hearing its own alignment lead put double-digit odds on catastrophe. Google shipped Gemini 4 Argon to cyber defenders before the public. The industry is arguing, in filings and firings, about who is allowed to see the dangerous intermediate.
What the Firings Do Not Prove
They do not prove the three leaked weights. They do not prove a conspiracy to embarrass the company before DevDay. They do not prove the safety team is being cleared out. Three people on a large research org is a case, not a purge. Treating it as a purge is a prediction, not a finding.
They also do not prove the outside organization did anything improper. Receiving material and soliciting it are different acts. OpenAI has not accused the recipient in the statement that has been published.
What to Watch
Whether any of the three speak.
Whether the outside group is named, by them or by a filing.
Whether more exits cluster on the safety org in the next month.
How dots and Astra testing rules change for the people still inside.
Whether the next system card mentions tighter sharing rules with external evaluators.
OpenAI can protect a model and still lose the people who know where it fails. It can keep the people and still lose the model to a sloppy forward. This week it chose the policy. The names, if they surface, will decide how that choice is remembered.
Comments (0)
Please log in to comment
No comments yet. Be the first!