When a frontier AI lab fires safety staff and refuses to name the outside group or the data, it tests who sets the rules for independent evaluation.
OpenAI says three safety researchers "mishandled" sensitive information. The actual mechanism is narrower and older: a frontier lab invites third-party safety evaluators in, then polices the perimeter after the fact. No one has yet written down what legitimate disclosure between the two looks like.
OpenAI parted ways with Jasmine Wang, Tomek Korbak, and Mikita Balesni after an internal investigation found they had "mishandled sensitive information outside established company procedures." That is the on-the-record statement, carried by the Wall Street Journal and TechCrunch. The company has not publicly named the three; their names have been reported by Gizmodo and Ynetnews, both citing the WSJ. None of the three had commented on the record at the time of the reporting; OpenAI declined a TechCrunch follow-up beyond the WSJ statement.
The most specific public detail about what was shared comes from Bloomberg, as carried by The Hacker News: the information pertained to OpenAI's infrastructure architecture. The most specific public detail about the recipient comes from Gizmodo: Korbak had previously described himself as OpenAI's "technical contact" for METR, the third-party evaluator that investigated last year's Hugging Face model-theft incident. Neither detail was in the original WSJ report. They sit on top of it.
That sequence, an outside evaluator invited in, an inside technical contact, and a retroactive perimeter check, is the mechanism this firing exposes. METR-style third-party evaluation, in which an outside group runs structured tests on a frontier model with the lab's cooperation, is a relatively new design, and it depends on the lab's terms: who gets access, what they see, and which transfer counts as crossing the line. The boundary of legitimate disclosure has, in most published accounts, not been written down. Researchers who work in that space are caught in the middle, holding partial visibility into model behavior with no published rulebook for what they may pass back to the evaluator who is supposed to be reading it.
This is also the latest entry in a growing list of safety-team departures at OpenAI. The firings come against a backdrop of mounting scrutiny of the company's safety practices, including a prior New York Times report that raised questions about OpenAI's approach to safety, a thread the WSJ-derived coverage has touched on. The company has publicly acknowledged it has "a need to move faster." Parting ways with three researchers whose job was to flag risk sits in tension with that line, and OpenAI has offered the public no further detail on this case.
The governance-design frame holds if these firings turn out to be a boundary dispute over invited third-party access. If they turn out to be a deliberate large-scale exfiltration, the frame soft-pedals real misconduct and the focus has to move to the exfiltration itself. The public reporting does not yet establish which one it is. OpenAI's "violated policy" framing has not been tested against any version of events from the researchers or the recipient, and motive remains unestablished.
The next public data point will be whether OpenAI names the recipient organization, releases any redacted findings from its internal review, or lets the matter drop. The pattern is older than this firing. The missing rule is older still.