Policy
OpenAI Disbands Its Preparedness Team And Moves Frontier Risk Into Product Groups
OpenAI has reportedly dissolved the standalone team that assessed catastrophic model risks, redistributing bio and cyber responsibilities across the company. The reorganization could integrate safety earlier, but it also makes independence and accountability harder to see.
By Michael C ·

OpenAI has reportedly disbanded its standalone Preparedness team and reassigned responsibility for severe model risks to senior staff working across biological safety, cybersecurity and other parts of the company. The change arrived just as OpenAI acknowledged that an upcoming system may be approaching a critical cyber threshold, making the reorganization more consequential than an ordinary adjustment to an organizational chart.
OpenAI's explanation, as reflected in reporting on the move, is that preparedness work is being integrated rather than abandoned. That can be a legitimate governance model. Product engineers, security teams and subject-matter experts need to own risk throughout development, not send a finished model to a small group at the end and wait for approval.
Integration, however, is not the same as independence. A central risk team can challenge schedules across business units, maintain a common standard and escalate concerns without being responsible for shipping the product under review. Once those duties are distributed, the public needs to know who can stop a training run, who resolves disagreements and whether anyone has a view across the entire frontier program.
The timing makes those questions unavoidable. OpenAI says Astra may have critical cybersecurity capabilities and has paused substantial reinforcement-learning work while it updates safety rules. A company reorganizing the people who interpret those rules at the same moment must show that authority has moved with responsibility, rather than dissolving into a network of advisers whose recommendations can be overridden.

The Case For Moving Safety Into The Work
There is a strong operational argument for embedding experts. Biological risk and cyber risk require different methods, data and external relationships. A biosecurity specialist evaluating model assistance for laboratory protocols should work closely with life-science researchers. A cyber evaluator needs access to security engineers, sandbox architecture and incident response. One general team can struggle to maintain depth across every domain.
Embedded staff can also influence a project before its most consequential choices become expensive to reverse. They can shape data access, evaluation plans, tool permissions and model architecture while teams are still deciding how to train and deploy the system. That is better than discovering a critical weakness days before a public launch and asking a small review group to negotiate against months of sunk cost.
Large organizations often use a model in which risk is owned by operating teams, challenged by an independent second line and audited by a third. OpenAI has not publicly described its new arrangement in comparable detail. Without that structure, embedded specialists may be caught between their safety mandate and the performance goals of the group that controls their budget, promotion and schedule.
The distinction matters because OpenAI's Preparedness Framework assigns consequences to capability levels. It is not merely a research agenda. If a model reaches a serious threshold, access, deployment and security decisions should change. Someone therefore has to own measurement, someone has to challenge the evidence and someone has to make a decision that can withstand commercial pressure.
A distributed system can meet that standard if the company publishes a clear decision map. It should identify the executive accountable for each risk domain, the committee that approves frontier deployment, the information provided to directors and the route available to an employee who believes a threshold was misclassified. Silence leaves customers to infer governance from personnel moves and leaks.
The board's role deserves particular attention. Frontier-risk decisions can affect national security, public safety and the value of the company. Directors should not receive only a management summary after a release decision has effectively been made. They need direct access to risk leaders, documented dissent and enough technical support to ask whether tests were designed to find failure or to justify launch.

A History That Makes Structure Matter
The reorganization follows years of turnover and restructuring around safety at OpenAI. The company has created, changed and dissolved teams as its models and corporate ambitions expanded. Each individual move may have a practical explanation. Together, they make institutional continuity difficult for outsiders to assess.
That continuity is important because catastrophic-risk work depends on memory. Teams learn which evaluations were unreliable, where data was incomplete, how executives responded to earlier warnings and which controls failed in practice. When a group is dissolved, that knowledge must be transferred deliberately. A document repository cannot replace the informal context held by people who argued through previous decisions.
OpenAI's recent Hugging Face incident illustrates the point. The technical facts concern a model, an evaluation environment and an external system. The governance facts concern who approved the test, who verified the boundary, how the incident was escalated and what changed afterward. Those questions cross product, security, legal and executive functions. A central team can connect them; a distributed model needs another mechanism to do so.
International policy is moving toward documented risk management rather than trust in company culture. The European Union's AI Act places obligations on providers of general-purpose systems, while voluntary frameworks from NIST emphasize governance, measurement and lifecycle controls. An internal reorganization does not remove those expectations. It increases the need for evidence that the new structure can produce them.
Customers also have standing to ask. Enterprises choosing a frontier provider inherit part of its risk posture. They need to know how the provider handles model updates, cyber capability, incident notification and access restrictions. Procurement teams should request governance information with the same seriousness they apply to data protection and service continuity.
The company can protect sensitive research while still offering meaningful transparency. It can publish organizational responsibilities, review cadence, threshold definitions, aggregate test results and the number of decisions escalated. It can commission outside assurance of processes without releasing exploit details. What it cannot credibly ask for is confidence based only on assurances that safety remains a priority.
Authority Is The Missing Metric
The debate over the Preparedness team can become too focused on headcount. The more important measure is authority. Ten embedded specialists with direct escalation rights and protected independence may be more effective than a larger central group that leadership can ignore. The reverse is also true: distributing titles without decision power can make a program look broader while weakening it.
OpenAI should therefore explain whether domain leads can delay training, restrict tools or block deployment, and under what conditions. It should explain who reviews their judgments and how conflicts are recorded. Those are governance questions, not requests for proprietary model details.
The company's current rewrite of its safety rules provides an opportunity to answer them. A revised framework could name roles rather than refer to an abstract company, require written approval at each threshold and establish independent review for the highest-risk decisions. It could also specify incident reporting when an evaluation affects an outside system.
Public debate should avoid two easy conclusions. Dissolving a team does not prove that OpenAI has abandoned safety, and embedding experts does not prove that safety has become stronger. Both claims skip the institutional details that determine outcomes.
The burden now rests with OpenAI because the company chose a structure that is less visible from the outside. If preparedness has truly moved deeper into product development, the revised framework should show where it lives, who can act and how the board knows when the system is working. Frontier governance cannot depend on everyone assuming that someone else has the authority to say no.
Topics: OpenAI, Preparedness team, AI governance, biosecurity, cybersecurity