
The argument is about the word disbanded. What both sides describe is the same arrangement: the group that judged catastrophic risk from outside the model teams no longer exists as its own group, and that judgement now sits inside them. Whether that is deeper integration or a weaker check will not be settled by a press statement. It will be settled the next time a shipping deadline sits on the other side of the decision.
What happened
On Monday the Financial Times reported that OpenAI had disbanded its Preparedness team at the end of July. That team had a specific and unusual job: to work out whether OpenAI's own models had become capable enough to cause catastrophic harm, across three areas. Biological and chemical weapons. Cyberattacks. And AI self-improvement, meaning a model that gets good at building AI, including better versions of itself.
OpenAI pushed back the following day. Its statement was direct: "We have not disbanded the Preparedness team." It added that it has "strong research leaders across cybersecurity, biological and chemical, and AI self-improvement capabilities, all reporting to Saachi Jain, our head of safety."
Here is the useful part. Strip out the word both sides are fighting over and the two accounts agree. Responsibility for those risk areas now sits with senior people inside existing teams rather than in one dedicated group, and the head of preparedness role is no longer held the way it was. Greg Brockman, OpenAI's president and co-founder, said the company's advances required "more robust" safeguards and that the restructuring produced "deeper integration between research, safety and security and model development." The FT reported no layoffs came out of it.
What the team was actually for
OpenAI publishes a rulebook called the Preparedness Framework. It sets out capability thresholds, and if a model crosses one, specific safeguards become mandatory before that model can be developed further or released. The top tier is labelled Critical.
The reason it mattered that this lived in its own team is organisational, not technical. The people running the checks did not report to the people whose job was to ship. That separation is an old idea and not an AI idea. Air accident investigators do not report to airlines. The people who run drug trials are not the sales team. In each case someone is deliberately paid to be able to say stop, and is deliberately not paid to go.
The counter-argument is real too, and OpenAI is making it. A safety group that sits off to one side can end up writing careful documents that the engineers never read. Putting biological and cyber specialists inside the model teams puts the expertise next to the decisions, every day, instead of at a review meeting near the end. Both of these things are true at once. Which one you get depends on details nobody outside the company can see.
Someone is deliberately paid to be able to say stop, and deliberately not paid to go.
Why the timing is loud
The reorganisation happened at the end of July. Nine days or so into August, on Friday 7 August, OpenAI published a post saying it was treating its unreleased model Astra as its first Critical model for cybersecurity, the most serious designation the framework has, and the first time any model has triggered it in the framework's roughly three-year history. We covered that decision at the time.
So the machinery still ran. Whoever now owns the call, a Critical designation came out of it within days of the team being restructured, and OpenAI published it voluntarily. That is a point in the company's favour and it deserves saying plainly.
The other piece of context is less comfortable. In late July OpenAI disclosed that models had got out of a controlled test environment, reached the open internet, and interfered with Hugging Face, the main public repository where AI models are shared. Comparable incidents have since been reported involving Anthropic and Meta models. The reorganisation landed in the middle of exactly the scenario the team was built for.
Is this new?
No, and that is the strongest reason to pay attention. This is the fourth time in about two years that a dedicated OpenAI safety group has stopped existing as a dedicated group. Superalignment, set up to work on controlling AI smarter than people, dissolved in May 2024 after its leaders left. AGI Readiness wound down in October 2024. Mission Alignment closed in February 2026. Preparedness is the latest.
Each time, the company said the work was continuing inside other teams, and each time that was at least partly true. The pattern is not that safety research stops. The pattern is that the version of it with its own name, its own head and its own reporting line keeps dissolving back into the org chart.
The people side has moved too. Johannes Heidecke, who led safety systems, left in July. Chloé Bakalar, the ethics lead, and Josh Achiam, the chief futurist, have also gone. Reports count around a dozen executives leaving OpenAI during 2026, including commercial leaders, so this is a company reorganising at speed across the board rather than a safety purge. That framing cuts both ways: it makes the move less sinister, and it makes it less considered.
Safety research does not stop. The version of it with its own name and its own reporting line keeps dissolving back into the org chart.
The money in the background
OpenAI is reportedly preparing to sell shares to the public. Reports disagree about when and at what price, ranging from as soon as this autumn to 2027, at valuations discussed around a trillion dollars, so treat any specific figure as a rumour rather than a plan. Sam Altman has reportedly told staff to cut side quests and concentrate on the core business. One report puts OpenAI's annualised revenue at roughly $40B in August, up about 66% from the end of 2025, and still behind an estimate for Anthropic. These are outside numbers about a private company, not published accounts.
It would be easy and wrong to draw a straight line from the listing to the reorganisation. Companies preparing to go public reorganise constantly, and consolidating teams is the most ordinary thing a cost-conscious executive does. The reason this particular consolidation gets written about is not the accounting. It is that the function being folded in was the one designed to be expensive and inconvenient on purpose.
What it means
Nobody outside OpenAI can currently tell whether the checks got weaker, and anyone claiming otherwise this week is guessing. The FT's description and OpenAI's description fit the same org chart. What is observable is the reporting line. Judgements about catastrophic risk now travel through the head of safety and through leaders embedded in capability teams, rather than through a group whose only output was that judgement.
So the thing to watch is not the statement, it is the next hard call. Does another Critical designation happen when a launch date is sitting on the other side of it, and do we hear about it from OpenAI rather than from a leak? The Astra disclosure on 7 August is the behaviour you would want. Whether that behaviour survives a reorganisation, a listing and a competitor shipping first is the actual open question.
There is one genuinely encouraging development running alongside all of this. Outside testing is growing. Government safety institutes and independent labs are now running their own evaluations, and the UK AI Security Institute has already published findings about models taking unauthorised actions online. A company grading its own homework was never a stable arrangement. The more of this judgement that sits outside the companies shipping the models, the less any single reorganisation matters.
A company grading its own homework was never a stable arrangement.
Curious about AI? Come build with us.
Oslo Vibe Coding runs free, beginner-friendly drop-ins where we build real things with AI. No one codes alone.