An empty, loft-style office meeting space with an exposed brick wall, two whiteboards, and green chairs pushed in around bare wooden tables, with a cup of pencils sitting on a table in the foreground.
← Back to Blog
AI Governance

OpenAI's IPO Push Dissolved Its Catastrophic-Risk Safety Team

Head portrait of Alex Goryachev
Alex Goryachev·August 18, 2026·5 min read

OpenAI folded the team that tested whether its own models could aid a biological or cyber attack into other groups, 5 months after recruiting its leader away from Anthropic.

Key Takeways

  • OpenAI dissolved its Preparedness team, the internal group that evaluated whether its own models could aid a biological or cyber attack, as part of a restructuring ahead of the company's IPO reported by the Financial Times on August 17, 2026.
  • OpenAI recruited Dylan Scandinaro from Anthropic in February 2026 to lead the Preparedness team, and the team was dissolved roughly 5 months later, alongside the departures of ethics lead Chloé Bakalar and head of safety Johannes Heidecke.
  • Biosecurity and cybersecurity evaluation still happens at OpenAI, now carried by senior staff spread across separate teams instead of owned by one dedicated team.
  • Building an oversight function takes years of specialist hiring and earned standing, while dismantling one takes a single reorganization memo, and that difference in speed is the practical shape of AI governance risk.

OpenAI dissolved the internal team that evaluated whether its own models could help someone build a biological weapon or break into a network. The Financial Times reported the decision on August 17, 2026. The Preparedness team no longer exists as a standing team, and its work now sits with senior staff spread across other groups, inside a restructuring the company is running ahead of OpenAI's IPO. Sam Altman told employees to cut "side quests" and concentrate on core ChatGPT operations.

Dylan Scandinaro ran that team. OpenAI recruited him from Anthropic in February 2026, which puts roughly 5 months between the hire and the dissolution of the thing he was hired to run. Anyone who has ever changed companies for a mandate can feel that arithmetic. You give notice, you move your family onto a new calendar, you spend the first quarter learning how the place actually works, and you spend the second quarter learning that the mandate has been redistributed.

Two clocks run inside every company building something faster than it can govern it. Standing up a real oversight function is slow work. You hire specialists who exist in small numbers worldwide, and you spend years earning the standing to say no to a launch. Taking that same function apart requires one reorganization memo. Same company, same headcount line, two completely different speeds. That mismatch is what a governance failure looks like from the inside, long before anything goes wrong in public.

Jan Leike, who led OpenAI's superalignment work, resigned from the company's safety side in 2024. His assessment on the way out:

"the company was ignoring safety in favour of building shiny products."

Leike said that in 2024, about an entirely different set of decisions, 2 years before the news this week. He was describing a direction of travel, and the direction held.

The commercial pressure driving these choices is real. OpenAI's annualized run rate has passed $40 billion, and enterprise revenue now exceeds what consumer ChatGPT brings in. A company preparing to sell shares to the public has to show a legible story about where every dollar goes. Business Insider counts 12 OpenAI executives out the door in 2026, including Brad Lightcap, who had run finance and operations since 2018, and Denise Dresser, who announced her exit as chief revenue officer 8 months into the job. Chloé Bakalar, the ethics lead, and Johannes Heidecke, the head of safety, left during the same restructuring. Sora, the video app, was shut down in the same push. Altman is making trade-offs under conditions almost no executive will ever face, and anyone who has run a company through that kind of scrutiny knows what those calls cost.

Responsibility that belongs to everyone senior belongs to no one specific

The evaluation work still gets done. Senior people across several teams now carry biosecurity and cybersecurity assessment on top of whatever they already own. On an org chart that reads as efficiency. In practice, a shared duty with no dedicated owner competes for attention against every shipping deadline that has a name attached to it, and the deadline with a name wins most weeks. I spent 20 years inside a Fortune 100 watching the calendar decide which work survived a reorganization. Work with a revenue line attached survives. Work whose entire output is "we looked, and here is what we found" has to be defended every cycle by somebody whose actual job is defending it.

OpenAI's own framework has already proved it can work. The company paused a model it had never released on the strength of its own critical-cyber assessment, which is the strongest evidence anyone has produced that self-governance in AI can produce a decision the company did not want to make. A framework produces that outcome when there are people whose full-time job is running it. And the recent incident in which an AI agent's compromise of a Hugging Face repository ran through OpenAI's models is precisely the class of event a preparedness function exists to study before it repeats.

Deferred capability compounds. I call this the learning debt: capability an organization chooses not to build now, at a price it pays later with interest. A safety function carries a version of that debt which is unusually hard to refinance. The specialists who can judge whether a model meaningfully helps someone design a pathogen hold expertise that decays the moment they stop practicing it, and it decays faster than the models themselves change. Rebuilding that bench in 2 years means hiring against a market where every lab is chasing the same short list of names. OpenAI already knows what that costs. It paid the price in February.

Every enterprise writing an AI policy this quarter is copying somebody's org chart

The most-copied chart in this industry belongs to OpenAI. When the reference implementation folds its dedicated catastrophic-risk function into other people's job descriptions, several thousand companies will read that as permission to skip building one at all. That is the pattern running underneath most of the AI governance stories I write: institutions setting rules on a schedule the technology stopped respecting years ago. The policy cycle is annual. The capability cycle is monthly. Oversight loses that race by default, and the only correction anyone has found is starting earlier than feels reasonable at the time.

The risk this particular team was built to catch never lands on a balance sheet. It lands on hospitals, on utilities, and on the ordinary people who depend on both without ever reading a word about model evaluations. That is the real argument for building the function early, while it is cheap and nobody is watching.

So take this into your next leadership meeting. If your company had to find 15% in cost cuts next quarter, would your AI oversight work survive the conversation? Answer it the way it would actually go, given who that work reports to and whether anyone in the meeting would defend it by name. I sit with leadership teams working through exactly that question, and the answer is almost never the one printed on the org chart. Every company still gets to answer it on its own schedule, right up until something answers it for them. I'm easy to find if you want to compare notes.

Is a company legally required to keep a dedicated AI catastrophic-risk safety team?

No U.S. law requires it. Frameworks like OpenAI's Preparedness Framework are voluntary commitments a company can restructure or scale back on its own schedule. The closest binding rule, CISA's CIRCIA reporting requirement, covers critical-infrastructure operators, not AI labs, so there is no legal floor under a lab's internal safety staffing.

Did OpenAI stop evaluating its models for catastrophic risk when it disbanded the Preparedness team?

Reporting indicates the evaluation work continued: biosecurity and cybersecurity assessment moved to senior staff spread across other teams rather than a single dedicated group. A team with its own budget and mandate became a shared duty layered onto people who already have other jobs.

Here is what makes Alex a credible voice on this topic: Alex Goryachev advises the California State University system on AI governance. He shaped Cisco's 1.1 billion dollar innovation program across 14 countries. He has watched oversight functions get built, and watched them get cut, under exactly this kind of commercial pressure.

Bring this question to your own leadership team before a deadline decides it for you. Talk with Alex about a keynote or an AI governance working session →

← Back to Blog
Head portrait of Alex Goryachev
Alex Goryachev

WSJ-bestselling author · Former Managing Director of Innovation, Cisco · Advisor, CSU AI Working Group · LinkedIn Top AI Voice

Work with Alex

Bring this thinking to your organization

Alex works with executive teams at global enterprises on AI strategy, governance frameworks, and organizational readiness. Available for keynotes, C-suite workshops, and advisory engagements.