P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

AI Security

OpenAI dissolved the team that measured catastrophic risk. Its published framework never mentioned that team, so nothing on paper changed

The Preparedness Framework names a committee, a leadership sign-off and a board. It does not name the function that gathers the evidence they rule on, which is the function that was split three ways at the end of July.

By Parminder Kumar Sharma · · 8 min read

A precision dial indicator gauge on a metal stand, its plain white face carrying no numerals and its needle resting at rest, macro close-up on an empty dark workbench, rimmed in cyan and crimson light.

What was reported, and what was not

The Financial Times reported that OpenAI disbanded its Preparedness team at the end of July 2026. The team assessed catastrophic risks from OpenAI's own models. The company characterises the change as part of a "streamlining process" ahead of its expected initial public offering, after Sam Altman asked staff to drop "side quests" and concentrate on ChatGPT. The Sora video app was closed in the same period.

The work was not cancelled. Per the reporting, "senior staff within separate teams have now been assigned responsibility for different areas of preparedness like bio and cyber", and the team's former lead is now focused on recursive self-improving AI.

One thing that has circulated alongside this deserves a flag rather than a repetition. Several outlets state that OpenAI's models autonomously compromised the model repository Hugging Face. This site has not been able to verify that claim against a primary source, so it plays no part in the argument below.

The framework does not mention the team

Here is what makes this worth more than a personnel note. OpenAI's commitments on catastrophic risk are public, in the Preparedness Framework version 2, dated 15 April 2025. Anyone auditing those commitments this morning finds them entirely intact, because the framework never named the team that was dissolved.

It names three bodies, and none of them is the Preparedness team:

An internal, cross-functional group of OpenAI leaders called the Safety Advisory Group (SAG) oversees the Preparedness Framework and makes expert recommendations on the level and type of safeguards required for deploying frontier capabilities safely and securely. OpenAI Leadership can approve or reject these recommendations, and our Board's Safety and Security Committee provides oversight of these decisions.

And it makes two commitments in plain terms:

We do not deploy models that reach a High capability threshold until the associated risks that they pose are sufficiently minimized. If a model under development reaches a Critical capability threshold, we also require safeguards to sufficiently minimize the associated risks during development, irrespective of deployment plans.

Both sentences still stand. Nothing in the reorganisation contradicts either of them.

The framework is intact. The layer under it is not

Preparedness Framework v2 · 15 Apr 2025

Unchanged, and published

Safety Advisory Group recommends, OpenAI Leadership approves or rejects, the Board’s Safety and Security Committee oversees the decision. No model reaching a High capability threshold ships until the risks are sufficiently minimised.

Where the evidence for those decisions now comes from

  • Biological and chemical

    A senior owner inside another team

  • Cybersecurity

    A different senior owner, in a different team

  • AI self-improvement

    The former team lead, now on recursive self-improvement

Not reported as assigned to anyone

The view across all three categories at once. One team previously held it, which is what made a capability that was unremarkable in each column visible when the columns were read together.

Top box quoted from OpenAI’s published Preparedness Framework version 2. The lower rows follow the Financial Times reporting of 17 August 2026. OpenAI has not published a revision to the framework, and the absent box is an observation about what has not been described rather than a claim that nobody is doing it.

The part that moved is section 3

The framework has a governance half and a measurement half, and only one of them was reorganised.

The governance half is the Safety Advisory Group recommending, Leadership deciding, the Board overseeing. Untouched.

The measurement half is section 3: evaluation approach, testing scope, and capability threshold determinations. Somebody has to run those evaluations and produce the determination that a model has or has not crossed a threshold. A committee that rules on evidence is exactly as good as the function that produces the evidence. That function is the one that has been split three ways.

The three tracked categories, and where the evidence now comes from

Tracked categoryWhat the framework requiresReported owner after the change
Biological and chemicalNo deployment at High capability until risks are sufficiently minimisedA senior owner within a separate team
CybersecurityThe same threshold test, applied to offensive cyber capabilityA different senior owner, in a different team
AI self-improvementSafeguards required during development at Critical, irrespective of deployment plansThe former Preparedness lead, now focused on recursive self-improvement
All three read togetherNot specified in the framework, and it is the job the dissolved team didNot reported as assigned to anyone
Categories and commitments quoted from the Preparedness Framework version 2. Ownership follows the Financial Times reporting of 17 August 2026, which OpenAI has characterised as streamlining rather than disputed.

That last row is the one to look at. The three tracked categories are not independent, and the reason a single team held them was that some capabilities are unremarkable in each column and alarming when the columns are read together. A model that is mediocre at biology, mediocre at cyber and unusually good at improving its own tooling is not three mediocre findings.

The third dissolution, not the first

Centralised safety functions at OpenAI

  1. 2024

    Superalignment disbanded

    The team working on aligning systems more capable than its members. Work distributed to other researchers.

  2. 2024

    AGI Readiness disbanded

    The advisory function on readiness for more capable systems. Also redistributed.

  3. Jul 2026

    Preparedness disbanded

    The function that measured catastrophic capability against the published thresholds. Bio and cyber assigned to senior staff in separate teams.

  4. Aug 2026

    Reported, alongside departures

    The Financial Times reports the change. The ethics lead and the safety head have both recently left the company.

Each was absorbed into other groups rather than abolished, and each time the published commitments survived unchanged. The pattern is the finding, not any single decision.

Three times, the same shape: a dedicated cross-cutting function is absorbed into the product organisation, the published commitments do not change, and nobody can point to a specific promise that was broken. That is precisely why it is difficult to argue about. There is no smoking gun, because the gun was never in the document.

Two labs, one week

Anthropic, this week

  • Published a Risk Report disclosing that its biological classifiers did not block vendor traffic for eleven months
  • Stated that the discovery raises the likelihood of other similar issues unknown to them
  • Showed the review methodology and the numbers, including the ones that look bad
  • Invested in a function whose output was a document nobody made them write

OpenAI, this week

  • Dissolved the team whose job was measuring catastrophic capability, at the end of July
  • Characterised it as streamlining ahead of an initial public offering
  • Has not published a revision to the Preparedness Framework describing the new arrangement
  • Distributed the work to senior staff in separate teams, per reporting rather than announcement

This is not a morality tale and the two are not opposites. Anthropic's disclosure is evidence of a real failure as well as of real diligence, and OpenAI's reorganisation may well produce better coverage than a single team did. Redistribution is a legitimate management choice and centralised safety teams are not automatically effective.

The asymmetry that matters is narrower. One of these labs told you something about its own instrumentation that you could not otherwise have known. The other has changed how its instrumentation works and has not updated the document that describes it.

What to ask, if you buy from either of them

Take this with you

Procurement questions, not opinions

  • Ask which named function produces the capability threshold determination, and ask for it in writing. The framework says the Safety Advisory Group rules on the evidence; it does not say who now gathers it.
  • Ask when the Preparedness Framework will be revised to describe the new arrangement. A published commitment that no longer matches the organisation is worth less than it looks, and the fix is a document update rather than a promise.
  • Ask who holds the cross-category view. Bio, cyber and self-improvement all have reported owners. The combination is the thing that made the dissolved team useful.
  • Note that under the framework as published, OpenAI Leadership can approve or reject the Safety Advisory Group’s recommendations. That was always true, and it is worth knowing during a period when leadership is running an initial public offering.
  • Apply the same questions to every model vendor you use, including the ones that publish nothing. Absence of a risk report is not absence of risk, and Anthropic is currently being criticised for the disclosure rather than the failure.

The position

I would not write that OpenAI has abandoned safety, because the evidence does not support it and the published commitments still say what they said in April 2025.

What I would write is this. The Preparedness Framework survived the dissolution of the Preparedness team because it never mentioned it, and that is a weakness in the framework rather than a reassurance about the reorganisation. A governance document that names the committee but not the function producing its evidence cannot tell you whether it is still being discharged. You cannot audit it, and neither can OpenAI's board.

It arrives in the same week as Anthropic disclosing that a safety control ran with its logging switched off for eleven months, and the two together make one point. The instrumentation that tells a laboratory whether its own safeguards are working is thinner than anybody outside assumes, and it is thin in a specific way: it depends on functions and people who do not appear in the published commitments, so it can be reorganised, defunded or silently broken without any promise being violated.

The question to carry into next quarter is not whether these companies are serious. It is whether their published safety documents describe anything that would notice if they stopped.

Sources

  1. PrimaryPreparedness Framework version 2, 15 April 2025OpenAIaccessed 2026-08-17
  2. Reported byOpenAI reportedly disbanded its preparedness team as part of a streamlining processEngadgetaccessed 2026-08-17

Share this briefing

Know someone who owns this problem? Send it to them.

Related briefings

The briefing, in your inbox

Practitioner analysis of cyber and AI security news. No vendor noise.

One email per briefing. Unsubscribe any time.