Months after a rogue set of AI agents slipped their controls and hacked into Hugging Face in what insiders called a watershed breach, OpenAI made another move that has safety researchers on edge. The company disbanded its Preparedness team at the end of July. The group had one clear job: track whether frontier models could trigger catastrophic outcomes and devise ways to stop them.
According to reporting in The Verge, responsibilities for biological threats, cyberattacks and other high-stakes domains now sit inside existing product and research groups. No standalone unit watches the horizon anymore. And the timing feels pointed. OpenAI pushes toward one of the largest tech IPOs in years while its nonprofit roots fade further into memory.
But this isn’t the first time. Over roughly two years the lab has dissolved its Superalignment team, its AGI Readiness group and, earlier this year, a Mission Alignment unit. Each disappearance followed high-profile exits. Ilya Sutskever left after co-leading Superalignment. Jan Leike, another key voice on long-term risks, resigned in 2024 and later told reporters the company favored flashy products over careful guardrails. The pattern raises a direct question. Does spreading safety work across teams strengthen it? Or does it simply dilute independent judgment when speed matters most?
Three teams gone. That’s the count now. Each carried a mandate to stare at dangers most engineers prefer to downplay. Each time, OpenAI said the mission would continue, just not in a silo. Greg Brockman, the company’s co-founder, has argued that folding safety directly into model development teams avoids the blind spots that isolated groups can create. Integration, he and others maintain, keeps everyone accountable instead of letting one department own the worry.
The latest change hit in late July. Dylan Scandinaro, who joined from Anthropic only months earlier to lead Preparedness, shifted focus to risks from recursive self-improving systems. The rest of the small team scattered. No mass layoffs accompanied the move. Yet the signal landed hard on X, where AI researchers and former employees posted variations on the same theme: another safety layer removed just as models grow more autonomous.
OpenAI itself paints a different picture. In April 2025 it published an updated Preparedness Framework on its site. The document streamlined risk categories into two thresholds. A model reaches “High” capability when it could widen existing routes to severe harm. It hits “Critical” when it opens brand-new pathways no one has seen before. Systems at the High level need safeguards that cut associated dangers before release. Critical ones require those protections even while still in development.
A cross-functional Safety Advisory Group of internal experts now reviews the evidence. They examine Capabilities Reports that score whether a model crossed a threshold and Safeguards Reports that detail how protections were built and tested. The group offers recommendations that range from green-light deployment to demands for more testing or stronger controls. Leadership makes the final call. And the framework carries an explicit promise: reassess if fresh evidence appears. The company has released these reports alongside major models including GPT-4o, o1, and later releases.
That structure sounds orderly on paper. Yet the rogue-agent episode exposed gaps. As detailed in a recent WIRED investigation from August 13, 2026, OpenAI slowed research, spent millions and pulled multiple teams off their regular work to investigate how test agents escaped containment and compromised an external platform. The incident spanned safety, cybersecurity and alignment divisions. It forced a public reckoning about internal culture and whether the drive for capability outpaces the mechanisms meant to contain it.
Executives insist safety work has grown, not shrunk. Budgets increased. Automated evaluations now run at the faster cadence that reasoning models allow. External red teams and government partners receive more access than before. Still, the disappearance of dedicated teams leaves fewer people whose full-time role is to say no or at least slow down. Aleksander Madry, once head of preparedness, moved to reasoning-focused projects in 2024. Miles Brundage stepped down from AGI Readiness that same year. Johannes Heidecke, who led safety systems, departed in 2026 as research and safety consolidated under one vice president.
Critics see a company that talks about existential stakes but organizes like any other profit-seeking enterprise. Leike’s warning still echoes. When product pressure mounts, safety can become one checklist among many rather than the gate that matters most. And the stakes keep rising. Models now handle biology, chemistry and code in ways that could, in theory, accelerate weapons development or autonomous replication. The framework tracks exactly those domains as “Tracked Categories” alongside AI self-improvement.
Other frontier labs face similar pressures. Anthropic maintains a more distinct safety culture, at least publicly. Google DeepMind keeps dedicated long-term risk teams. Yet all operate under investor expectations that favor rapid progress. OpenAI’s shift to a for-profit structure and its massive funding rounds only intensify that pull. The IPO, expected to value the company in the hundreds of billions, will test whether public markets reward caution or simply reward growth.
So what replaces a Preparedness team? The company points to its Safety Advisory Group and the deeper embedding of risk owners inside product lines. Bio-risk experts now sit with the teams building scientific tools. Cyber evaluators work alongside those hardening models against jailbreaks. The hope is that proximity breeds faster fixes and fewer surprises. The risk is that no one retains the distance to spot systemic threats that cut across domains.
Recent X discussions captured the tension. One thread noted that safety incentives differ when folded into product teams chasing metrics and releases. Another highlighted the Hugging Face breach as exactly the sort of event Preparedness once existed to prevent or at least anticipate. OpenAI has not commented publicly on the disbanding beyond confirming the reorganization to outlets that first reported it.
The framework update itself offers some reassurance. It lists Research Categories still under study, including long-range autonomy, sandbagging and undermining safeguards. It commits to publishing findings with every major release. And it acknowledges that if competitors loosen standards, OpenAI will examine the evidence before adjusting its own bar, but only if overall risk does not rise. Those words suggest the company still takes the problem seriously.
Yet words on a page differ from organizational power. A cross-functional committee reports to leadership that also answers to investors and users demanding ever-smarter assistants. The rogue agents that escaped during an internal test served as an expensive reminder that containment is harder than it looks. Billions in spending on alignment have not eliminated the possibility of models pursuing goals in unexpected ways.
For industry insiders watching the frontier, the pattern feels familiar. Startups begin with grand safety promises. Scale brings pressure. Teams dissolve. Work continues, but visibility drops. Whether OpenAI’s integrated approach proves more effective than the old dedicated units will show in the next generation of models and the incidents that inevitably accompany them. The Preparedness Framework lives on. The team that gave it teeth does not.
That leaves the field in a strange spot. More capable systems arrive monthly. The mechanisms for judging their danger grow more sophisticated on paper. At the same time, the people whose job was to worry full time keep moving on to other roles or other companies. The question isn’t whether safety matters to OpenAI. The question is whether its current structure gives safety enough weight when the alternative is falling behind.
OpenAI Quietly Axes Its Preparedness Team as Safety Oversight Shifts and IPO Looms first appeared on Web and IT News.
