A team dedicated to extreme risks disappears from OpenAI
OpenAI reportedly disbanded its Preparedness team, an internal structure dedicated to assessing dangerous capabilities and extreme risks that could be associated with the lab's future artificial intelligence models. The information was reported by the Financial Times, then relayed by The Verge, which specifies that the team was dismantled at the end of July.
The issue goes far beyond a simple organizational-chart change. At OpenAI, preparedness for so-called “frontier” risks — that is, those that could emerge as models gain autonomy, reasoning power, capacity for action, or mastery of sensitive domains — has for several years been a central element of the company's public messaging. The disappearance of a team explicitly named for this mission therefore raises an immediate question: where does the authority responsible for slowing, overseeing, or flagging the development of a system deemed too risky now lie?
According to information reported by the Financial Times, the Preparedness team assessed dangerous capabilities and extreme-risk scenarios involving OpenAI's future systems. This function is not the same as the more general tasks of cybersecurity, use moderation, or prohibited-content detection. It falls within a particular category of AI safety: anticipating what a frontier model could make possible, including in areas where an improvement in its performance would create new risks for cybersecurity, biological safety, or manipulation.
In the sector's vocabulary, this distinction is essential. A safety mechanism may seek to prevent a conversational assistant from producing clearly dangerous or illegal content. A team preparing for advanced risks, meanwhile, seeks to determine whether the underlying system has capabilities that structurally alter the level of threat, including when those capabilities have not yet been integrated into a mass-market product. It therefore intervenes, in principle, well upstream of commercial launch.
OpenAI's case is particularly closely watched because the company occupies a central position in the race for large generative models. Since ChatGPT's public launch at the end of 2022, the company has become one of the main symbols of the acceleration of generative AI. Its internal decisions are read by investors, governments, researchers, and competitors as indications of the balance of power between development speed, market pressure, safety, and governance.
The news reported by the Financial Times does not, on its own, mean that OpenAI is abandoning all safety work. A company of this size includes several teams that may address security, alignment, model evaluation, robustness, or abuse prevention. But it raises a more specific question: is the preparedness mission being retained in another form, distributed across other units, or weakened by the disappearance of an identifiable, specialized structure?
Why the notion of “preparedness” has become central at OpenAI
To understand the scope of this reorganization, it is necessary to revisit how OpenAI gradually formalized its approach to risks. Founded in 2015 as a nonprofit organization, OpenAI was built around a promise to develop artificial general intelligence capable of benefiting humanity. As its models were deployed to a much broader public, this ambition was accompanied by increasingly detailed language on safeguards, evaluations, and systemic risks.
In October 2023, OpenAI published its first Preparedness Framework, a framework intended to measure and manage the catastrophic risks that its most advanced systems could pose. The document distinguished several categories of risks, including cybersecurity, biological threats, persuasion, and model autonomy. Its stated goal was to evolve protective measures as model capabilities progressed.
This framework was part of a broader movement within the industry. The laboratories developing the most powerful models have gradually recognized that traditional quality assessments — accuracy, linguistic fluency, test results, performance in programming or reasoning — are insufficient to measure a system's consequences. A model can be useful in many legitimate tasks while reducing certain technical barriers for malicious uses. The question is then no longer only whether the model “responds well,” but what it actually enables a determined user to do.
Cybersecurity is one of the most frequently cited examples. A system more competent at coding, researching technical information, and problem-solving can help engineers defend infrastructure. However, the same capabilities can be misused to identify vulnerabilities, automate certain stages of an attack, or improve fraudulent operations. In the biological field, discussions concern the risk that a highly capable assistant could facilitate access to sensitive knowledge or procedures. Evaluations seek specifically to determine whether the tool significantly increases an actor's ability to cause harm.
Persuasion and autonomy have also become research topics. Persuasion refers to a system's ability to produce content tailored to a context, a target, or an influence objective. In safety debates, autonomy refers to a model's ability to plan, use tools, carry out sequences of actions, and pursue a task with less human supervision. These capabilities can be useful in assistance or automation products, but they also increase the difficulties of control and attribution of responsibility.
OpenAI's framework provided for a threshold-based logic: when evaluations reveal a higher level of risk, protective measures must be strengthened before deployment. This approach is as much political as technical. It recognizes that the decision to release a model cannot be left solely to an assessment of its commercial performance. It also assumes that a team capable of assessing risks can communicate findings that may conflict with a product schedule.
It is in this context that the reported dissolution of the Preparedness team draws attention. A dedicated structure does not automatically guarantee the independence of its conclusions or the implementation of its recommendations. Its existence, however, makes the mission visible, identifiable, and easier to scrutinize from outside. When a company communicates about its safety policies, observers can seek to know which team conducts the tests, whom it reports to, and under what procedures results are taken into account.
Conversely, when responsibilities are dispersed among different units, it becomes more difficult for the public to understand the decision-making process. This dispersion may sometimes correspond to a broader integration of safety into product and research teams. But it can also create a risk of dilution: everyone is partly responsible, without any structure clearly having the mandate to say that a model should not be released in a given state.
A reorganization that revives the debate over safety independence
The main issue raised by the news is therefore not only the size or name of a team. It concerns the ability of safety mechanisms to operate with genuine autonomy in the face of development, market-launch, and competitive interests. AI laboratories are engaged in a dynamic in which every performance gain can have considerable value: attracting users, retaining business clients, convincing developers, forming partnerships, or sustaining investor interest.
In this context, risk evaluations can become a source of friction. They require time, specialized skills, difficult-to-design test sets, and sometimes restrictions on features or access to a model. They may also require postponing a launch, limiting the availability of a system, or planning costly monitoring measures. Yet product announcements, performance demonstrations, and the rapid expansion of uses are precisely the most visible competitive tools in the sector.
OpenAI has already publicly faced debates over its governance and the place of safety concerns. The November 2023 episode, when the nonprofit board of directors initially ousted Sam Altman before his swift return as chief executive, highlighted tensions between the organization's mission, the commercial structure funding its activities, and operational-continuity requirements. This episode does not, on its own, establish a link with the dissolution of the Preparedness team. It does, however, explain why every change in OpenAI's internal governance is now examined with particular attention.
The issue is all the more sensitive because several important figures in safety research have left OpenAI over the years. In May 2024, Ilya Sutskever and Jan Leike announced their departure from the company. Both had led the Superalignment initiative, created by OpenAI in 2023 to work on controlling systems more intelligent than humans. Jan Leike had publicly expressed concern at the time about the priority given to safety culture and processes within the company.
These departures reinforced a debate already present in the AI community: can the same actor be entrusted with both building the most advanced systems and setting the limits for their deployment? Companies generally respond that their safety researchers are indispensable because they know the models from the inside and can intervene before their release. Their critics, meanwhile, believe that exclusively internal oversight remains vulnerable to conflicts of interest, especially when growth objectives become a priority.
The dissolution of Preparedness, as reported, does not allow the conclusion that controls have disappeared. It nevertheless makes this discussion more urgent. A company can maintain rigorous evaluations without a team bearing that name. But to demonstrate this, it must provide concrete elements: continuity of testing protocols, reporting capacity, escalation procedures, the role of safety leaders, decision criteria, and consequences in the event of an unfavorable result.
This point is particularly important for the risks most difficult to observe from outside. The visible moderation of a chatbot can be tested by users or independent researchers. By contrast, evaluations concerning frontier capabilities, internal tools, unpublished versions, or combinations of models and agents are less accessible. The public therefore depends more heavily on information communicated by the laboratory, potential audits, and the quality of regulatory oversight.
The word “independence” must be used precisely here. An internal team is never entirely external to the company employing it. Its budget, access to models, and ability to impose a decision depend on the organization's governance. But mechanisms can strengthen its weight: reporting to a body separate from product management, direct access to the board of directors, publication of reports, protected whistleblowing procedures, use of external evaluators, or an explicit commitment not to deploy a model before certain validations.
The signal sent by the disappearance of a dedicated team will therefore depend largely on what replaces it. Without public clarification, observers may interpret it as an additional indication of centralized decisions around model development and commercialization. Conversely, if capabilities are transferred to a structure with a strong and clearly documented mandate, the reorganization could be presented as a change in form rather than a substantive setback.
The race for advanced models and comparison with industry commitments
The matter comes at a time when major laboratories are communicating simultaneously about the power of their models and their safety efforts. Google, Anthropic, Meta, Microsoft, and OpenAI are investing in multimodal models, coding assistants, reasoning capabilities, and tools for businesses. Competition is no longer only about generating text or images. It concerns the integration of models into software, work environments, research, cloud infrastructure, and, increasingly, systems capable of using tools.
Anthropic is often cited in this debate because of its “Constitutional AI” approach and its publication of documents devoted to its Responsible Scaling Policy. The company has defended the idea of capability thresholds associated with strengthened security measures. This logic does not eliminate criticism: like OpenAI, Anthropic remains a private, competitive actor heavily involved in developing frontier models. But it illustrates a growing expectation: laboratories must explain how their evaluations actually influence the decision to develop or deploy.
Google DeepMind has also published work on the safety of advanced systems and participated in international discussions on frontier AI. Meta, for its part, is regularly at the center of specific debates related to the release of open-weight models, which raises a different question: once a model is widely accessible, the ability to control its uses is more limited. Approaches therefore differ among companies, but the pressure to justify safeguards is shared.
OpenAI itself had helped place these issues in the public debate. Its Preparedness Framework represented an attempt to formalize the steps between evaluating a model and deciding to make it available. The fact that a team bearing precisely the name of this program is now dissolved, according to the Financial Times, will inevitably be compared with the company's previous public commitments.
This comparison must remain cautious. Safety policies are not identical from one laboratory to another, and public documents do not always make it possible to measure the operational reality of controls. Evaluation criteria, human resources, access to research versions, and blocking mechanisms are not necessarily comparable. It would therefore be risky to assert that one actor is intrinsically safer than another on the basis of its organizational chart or statements alone.
Transparency, however, is an observable criterion. When a company publishes a policy, risk categories, capability thresholds, or evaluation reports, it at least gives researchers, journalists, authorities, and business users a basis for questioning its commitments. This transparency may remain partial, particularly to avoid disclosing sensitive information. But the absence of visibility mechanically fuels distrust.
The debate also concerns timing. Preparedness teams ideally work before a problem becomes concrete for the public. They test hypothetical scenarios, assess capability developments, and imagine adversarial uses. This work may appear less directly profitable than a product launch, but it is intended to reduce the risk of a late response. In rapidly spreading technologies, the cost of a correction after deployment can be far higher than that of a preventive evaluation.
Technology companies have long operated according to a launch-and-adjust logic: release, observe uses, fix flaws, and add restrictions over time. This method is less easily transferable to advanced AI systems when the capabilities involved can be copied, automated, massively distributed, or combined with external tools. Hence the importance attached to evaluations before release, particularly in discussions of frontier models.
OpenAI's reorganization will therefore be interpreted through this dilemma. Is it a way of bringing safety closer to the teams developing the models, in order to make it more operational? Or a decision that reduces the visibility and autonomy of a mission capable of slowing launches? The reported information does not make it possible to decide conclusively. It is sufficient, however, to raise the question, because the very name of the team referred to a promise of preparedness for the most serious consequences of advanced AI.
Direct implications for U.S. and European regulation
This internal development is being followed in a regulatory environment that is gradually taking shape. Public authorities are no longer content with encouraging companies to adopt general ethical principles. They are increasingly interested in documentation, testing, risk management, cybersecurity, and the responsibility of providers of powerful AI models.
In the United States, the debate over AI governance has taken on a national dimension with the multiplication of federal initiatives, work by the National Institute of Standards and Technology, or NIST, and congressional hearings devoted to generative models. In 2023, NIST published its AI Risk Management Framework, a voluntary framework intended to help organizations identify and manage AI-related risks. It does not replace sectoral regulation, but it has helped establish a common language around risk mapping, measurement, and management.
U.S. authorities have also paid particular attention to the most advanced models, notably through debates over notification requirements, safety testing, and infrastructure protection. The U.S. policy framework can evolve quickly depending on administrations and the direction of Congress. For companies, this instability does not reduce the importance of the issue: on the contrary, it increases the strategic value of internal arrangements capable of demonstrating that risks are identified and addressed.
In the European Union, the AI Act creates a more structuring framework for actors present on the European market. The regulation entered into force on August 1, 2024. Its obligations are being implemented progressively depending on the categories of systems and the provisions concerned. It notably provides rules for general-purpose AI models, as well as strengthened obligations for models presenting a systemic risk.
For U.S. companies such as OpenAI, Europe is therefore not merely a market of users or business clients. It is also a legal space where model governance, technical documentation, risk management, and cooperation with authorities are becoming increasingly important. An internal organization capable of identifying potentially dangerous capabilities can be useful in meeting these requirements. Conversely, governance perceived as opaque can become an area of concern for regulators.
The AI Act does not turn European authorities into direct observers of every research decision made in American laboratories. But it increases expectations surrounding traceability. Providers must be able to explain their practices, produce appropriate documentation, and comply with the obligations applicable to them. For systemic-risk models, the European logic notably relies on evaluation, risk mitigation, and security.
France is directly affected by this dynamic. French AI actors, whether startups, established companies, public laboratories, or service providers, increasingly depend on models developed abroad. They may use them through interfaces, APIs, or cloud services. OpenAI's governance choices therefore have indirect effects on French companies that integrate its technologies into customer-relations tools, software development, document research, training, or content production.
For these users, the question is not abstract. A company deploying a model in a business process must assess the data it transmits to it, possible errors, contractual terms, use restrictions, and supervision arrangements. When the model provider changes its safety organization, business customers can legitimately ask whether evaluation procedures remain comparable, whether changes are documented, and whether previous commitments remain valid.
The French context is also marked by a political desire to support innovation while promoting trustworthy AI. This dual ambition creates a tension similar to the one seen in laboratories: accelerating AI adoption to strengthen competitiveness without normalizing the risks associated with increasingly capable systems. The disappearance of a Preparedness team at OpenAI provides a concrete case for this debate. It reminds us that governance arrangements are not merely principles written in documents: they rest on teams, budgets, procedures, and a real ability to influence decisions.
The next test will be that of operational transparency
In the short term, the decisive question for OpenAI will be less the exact wording of its organizational chart than the continuity of the functions previously carried out by the Preparedness team. Are extreme-risk evaluations still being conducted? By which teams? With what resources? At what point in the development cycle? And above all, which body decides that a test result requires additional protections, restricted access, or a deployment delay?
These questions are difficult because companies cannot always publish the details of their tests. Some information could reveal vulnerabilities, sensitive capabilities, or bypass methods. But responsible communication does not necessarily require the disclosure of dangerous data. It can involve publishing principles, categories of tests, escalation procedures, commitments to external review, or summary reports on the measures taken.
For the French-speaking market, this visibility will become more important as frontier models are integrated into more services. Organizations will not choose a provider solely based on the quality of a chatbot or the price of an API. They will also look at the provider's ability to explain the limits of its systems, how it handles incidents, the control tools it offers, and the maturity of its governance.
Government bodies and regulated companies, particularly in finance, healthcare, energy, or public services, will have specific requirements. They cannot entirely delegate their responsibility to a model provider. But they need sufficiently reliable information to conduct their own risk analyses. Clear technical documentation and stable safety policies then become selection criteria as important as raw performance.
Over the longer term, the reported dismantling of the Preparedness team could become a test for the entire sector. If OpenAI demonstrates that the capabilities have been preserved, strengthened, and provided with a credible escalation path, the episode will be read as a contested reorganization but one potentially compatible with robust governance. If visibility into these mechanisms declines as model capabilities advance, it will bolster arguments for independent evaluations and more explicit regulatory obligations.
The trajectory of advanced AI laboratories will depend on their ability to convince others that safety is not a peripheral service activated after product decisions, but a constraint integrated into strategy. In a technological race where every capability gain fuels competition, credibility will no longer rest solely on promises of caution. It will rest on visible internal institutions, evidence of continuity, and the ability for authorities and customers alike to verify that safeguards retain real weight in the face of commercial acceleration.
Comments· 2 comments
If the team was specifically assessing extreme model risks, I’d like to see clarification on what replaced its evaluation process. Was the work absorbed into another independent review function, or are the same safety checks now handled within product teams?
The article summary does not say what, if anything, replaced the team. It would be useful to look for an OpenAI statement, internal-policy details, or reporting that identifies where preparedness evaluations and escalation authority now sit.