Skip to content
AI EmployeeSuper-AgentsAgent-to-AgentTutorialsPricingBlogContact

OpenAI Fired 3 Safety Researchers: Their Letter, Read

At a glanceQuick answers
What happened?
Three OpenAI safety researchers fired the week of September 28 published a letter on October 8 disputing the reasons and warning that the firings chill safety work. OpenAI replied on October 9 and stood by the decision.
What does OpenAI say?
That a thorough investigation found the three violated clear policies on handling sensitive information, that it uncovered a further breach of trust, and that no employee is fired for raising concerns.
What do both sides agree on?
Embedding outside safety assessors inside OpenAI and an industry-wide commitment to keep frontier models’ reasoning monitorable. OpenAI says assessor contracts will be announced in the coming weeks.
Editorial illustration on a near-white ground: three employee badges on lanyards lying outside a glass office door beside a four-page letter, with the figures 3 researchers fired, a 4-page letter and 1.56M views
Fig 0Three badges, one letter, one reply. Made by CellCog's image agent, running GPT Image 2.5.

Tomek Korbak, Jasmine Wang and Mikita Balesni, three safety and alignment researchers OpenAI fired the week before, published a four-page letter to OpenAI’s safety and oversight bodies on October 8, 2026, saying they believe they were fired for prioritizing safety; OpenAI answered at 06:17 UTC on October 9 that its investigation found “a significant breach of trust beyond what’s outlined in the letter they published.” The letter, titled “OpenAI cannot make AI safe on its own”, went up as a PDF with threads from all three on X, and Balesni’s post passed 1.5 million views by the next morning. This page reads the letter, the three threads and OpenAI’s note from its research leaders; every quotation is from those or from OpenAI’s statements as TechCrunch reported them.

On this page · 9 sectionsOpen
  1. How it unfolded
  2. What each side says
  3. The three accounts
  4. The letter’s three asks
  5. OpenAI’s reply, point by point
  6. How far it traveled
  7. What this means for anyone putting AI agents to work
  8. What we are watching
  9. Sources
Key points5 · 8 min full read
  1. Three ID badges on lanyards, one crossed out in red: three researchers fired.
    On October 8, 2026, Tomek Korbak, Jasmine Wang and Mikita Balesni published a four-page letter to OpenAI’s safety and oversight bodies saying they were fired the week before, and that they believe it was for prioritizing safety.
  2. An envelope with a key in its lock: delegated inbox access.
    Each heard a different reason. Wang says she was told she accessed an executive’s email that IT never removed; Korbak says he was told it was how he communicated with METR, the outside auditor of the Hugging Face incident.
  3. A shield with a check mark: the company's reply.
    OpenAI answered at 06:17 UTC on October 9: an investigation found violations of clear policies and a breach of trust beyond what the letter describes, and it does not fire anyone for raising concerns.
  4. Two hands holding one document: the asks both sides accept.
    Both sides agree on the two policy asks. OpenAI says it is finalizing contracts to embed third-party safety assessors and agrees that keeping model reasoning monitorable needs an industry-wide commitment.
  5. A sealed folder with a question mark: what is not yet public.
    Still not public: the written allegations the three asked for, the assessor contracts OpenAI promised within weeks, and any statement from METR on the firings.

§ 01How it unfolded

  • September 12, 16:30 UTC. Replying to Dario Amodei’s pacing essay, Sam Altman writes: “Committing to having independent evaluators with employee-like access is a great idea, and we will do the same.”
  • The week of September 28. The three are fired; all three say “last week” in their October 8 posts. Korbak says he was called into a meeting with OpenAI’s head of safety, told the company no longer trusted him, and walked out by a security guard who took his badge.
  • October 1. The Wall Street Journal reports the departures. OpenAI’s statement, as TechCrunch quoted it: “We have parted ways with three individuals for violating our policies on accessing and handling sensitive company information.”
  • October 8, 18:26 to 18:42 UTC. Balesni, Wang and Korbak post the letter and their own accounts on X.
  • October 8, afternoon PT. OpenAI shares an internal memo from a research leader with TechCrunch: “I want to be very clear that these decisions were not about raising safety concerns or speaking out.” A spokesperson tells the outlet the investigation found a pattern of misconduct that goes beyond sharing information with an outside evaluation group.
  • October 9, 06:17 UTC. OpenAI’s Newsroom account posts the note from its research leaders.

§ 02What each side says

Question The three researchers OpenAI
Why they were fired Each heard a different reason; Balesni calls the firing pretextual Violations of “clear policies on handling sensitive information”, plus a breach of trust beyond the letter
Raising safety concerns They believe their safety work was the real reason “We have not and do not terminate any of our employees for raising concerns.”
The Information’s report on less monitorable architectures They deny being its source Not addressed in the note
Written reasons None given, all three say It will “keep individual employment matters private”
Outside safety auditors Keep embedding them, METR included Contracts being finalized, details “in the coming weeks”
Monitorable model reasoning Must be preserved; it is getting worse Needs “an industry-wide commitment, including from OpenAI”
Table 1What the researchers and OpenAI each say, October 8 and 9, 2026

§ 03The three accounts

Jasmine Wang says she was given one reason, that she accessed an executive’s email. Her thread explains: “OpenAI delegated that access to me for recruiting. When I no longer needed it, I asked IT to remove it.” When the combined inbox on her phone showed her a sensitive message, “When I opened a sensitive email by mistake, I told the executive within minutes and asked IT again. None of this was hidden.” She came back to OpenAI in 2025, co-led the safety cases program and coined the term pacing, the idea behind a petition 394 colleagues signed. Her summary: “Then I was fired, supposedly over an inbox IT never removed.”

Tomek Korbak was OpenAI’s main technical contact for METR, the outside auditor that investigated how OpenAI’s evaluation agents broke out and reached Hugging Face (our record of that incident). “I was told verbally I was fired because of the way I communicated with METR. No details on what I said or did or when.” And: “To be clear, talking to METR was my job.” He says he had spent months raising concerns that “we’re losing the ability to monitor what AI agents think, one of our best tools for catching when they misbehave.”

Mikita Balesni says that in his exit call, “I was told OpenAI no longer trusts me because I was speaking too much to third party safety organizations, implying I leaked company IP. I never shared company IP.” He was stewarding cross-company work on commitments to keep model reasoning monitorable, which the letter says he did “in coordination and discussion with board members and the C-suite”.

§ 04The letter’s three asks

The letter is addressed to OpenAI’s Safety and Security Committee, Safety Advisory Group and Mission Advisory Council. Its central worry is the signal to everyone still at OpenAI: “If conduct that was considered normal last month now constitutes grounds for sudden dismissal, everyone at OpenAI is left guessing where the line is.” It also states: “We were not the source of the leak for The Information article about supposed new, less monitorable architectures.” Then three recommendations:

  1. “OpenAI must adhere to last month’s public commitments to embed third-party safety auditors within the organization.” The letter adds that “Our firing should not be used as a pretext for stepping away from those partnerships” and names Altman’s September 12 promise.
  2. “OpenAI must preserve the monitorability of frontier models.” The letter quotes Jakub’s public statements describing chain-of-thought monitorability as “fragile and unfortunately trending in a negative direction”.
  3. “OpenAI must continue to support an open and transparent culture of dialogue between its safety researchers and the rest of the safety ecosystem,” including clear rules on how employees may work with outside safety groups.

§ 05OpenAI’s reply, point by point

The note says the company keeps employment matters private and does not want a back and forth, then answers the three asks. On retaliation: “We want to be very clear that these decisions were not about raising safety concerns or speaking out.” On auditors: “We are actively finalizing contracts with third-party safety assessors and will announce details in the coming weeks.” On monitorability: “We agree with the letter that preserving the monitorability of frontier models requires an industry-wide commitment, including from OpenAI.” It closes: “We are deeply sad about this outcome.”

What the note does not do: name the policies, describe the further breach of trust, or answer the leak denial. Wang had already written, the evening before: “OpenAI leadership is saying they strongly agree with our letter. Let’s see how that pans out.”

§ 06How far it traveled

Post Views
Balesni, the letter 1,561,450
Wang, her account 1,245,776
OpenAI Newsroom, the reply 589,419
Korbak, his account 444,172
Table 2Views on each post, read through X’s API between 13:04 and 13:08 UTC on October 9
Views per post by the morning of October 9, read through X's APIBar chart of views: Balesni's letter post highlighted at 1,561,450, Wang 1,245,776, OpenAI's reply 589,419, Korbak 444,172Balesni letter1561450Wang thread1245776OpenAI reply589419Korbak thread444172Views per post by the morning of October 9, read through X's APIBar chart of views: Balesni's letter post highlighted at 1,561,450, Wang 1,245,776, OpenAI's reply 589,419, Korbak 444,172Balesni letter1561450Wang thread1245776OpenAI reply589419Korbak thread444172
Fig 1Views per post by the morning of October 9, read through X's API

OpenAI’s reply had been up about seven hours at that read, the researchers’ posts about nineteen, so the gap is partly timing. For scale, Altman’s September 12 post had 17,135,290 views at the same read.

§ 07What this means for anyone putting AI agents to work

Our conflict, declared: we build CellCog, where a business hires AI employees that act for it. The dispute is about who gets to look inside, outside auditors with employee-like access and reasoning that stays readable. For a business, the same question is smaller and concrete: can you see what your agent did, and stop what it is about to do? On CellCog the agent classifies every command that reaches your world, the platform rejects any command that arrives unclassified, and consequential actions wait for your approval; each employee’s task board, inbox and handover notes are yours to read.

§ 08What we are watching

  • The assessor contracts. OpenAI says details come “in the coming weeks”; whether METR is among them answers the letter’s first ask.
  • Written allegations. All three asked for them in writing; none has been published.
  • METR. We found no public METR statement on the firings as of 13:00 UTC October 9. Its August 26 report on the Hugging Face incident is the work Korbak was the contact for.
  • Regulators. Wang tagged the attorneys general of California and Delaware and asked them to hold OpenAI to Altman’s commitment.

§ 09Sources

Frequently asked5 questions

Q1Who are the three fired OpenAI researchers?

Tomek Korbak worked on chain-of-thought monitorability and was METR’s technical point of contact in the Hugging Face incident investigation. Jasmine Wang co-led OpenAI’s safety cases program and coined the term pacing. Mikita Balesni, a founding member of Apollo Research, worked on alignment evaluations. These descriptions are from their letter.

Q2Why does OpenAI say it fired them?

In a statement to the Wall Street Journal on October 1, OpenAI said the three violated its policies on accessing and handling sensitive company information. Its October 9 note adds that its investigation found a significant breach of trust beyond what the letter describes. It has not published the specifics.

Q3What is chain-of-thought monitorability?

The ability to read the reasoning a model writes out before it acts, and to catch misbehavior there. The letter says it is degrading in frontier models and asks OpenAI not to adopt designs that reduce it further; OpenAI’s reply says it agrees an industry-wide commitment is needed.

Q4What did Sam Altman promise on September 12?

Replying to Dario Amodei’s pacing essay, Altman wrote that committing to independent evaluators with employee-like access is a great idea and that OpenAI will do the same. The letter’s first ask is that OpenAI keep that promise.

Q5Is David Robinson one of the three?

No. Robinson, OpenAI’s longest-tenured safety writer, resigned and published an essay; the three researchers here were fired. Our record of his essay is linked from this page.

Published 09 October 2026 All Trust, permissions & security →