The three safety researchers OpenAI fired last week have published an open letter to the company’s safety oversight bodies, arguing that the dismissals were handled in a way that is making remaining staff afraid to raise concerns or work with outside safety organizations. One of them, Mikita Balesni, went further on X, saying he believes the trio were let go “for prioritizing safety over the near-term interests of OpenAI as a corporation.”
The letter is signed by Tomek Korbak, Jasmine Wang and Mikita Balesni, and is addressed to OpenAI’s Safety and Security Committee, Safety Advisory Group and Mission Advisory Council. It lands days after OpenAI said it had parted ways with the three for allegedly mishandling sensitive company information in connection with an external AI safety organization. In a statement at the time, an OpenAI spokesperson said an internal investigation had confirmed the three “mishandled sensitive information outside established company procedures.”

“AI is not a normal technology”
The researchers say the way they were fired has had a chilling effect. “AI is not a normal technology, and OpenAI is not a normal company,” they write, arguing that the freedom to raise concerns and collaborate with outside experts without fear is itself “an essential safety mechanism.”
They say conduct that was considered normal a month ago is now being treated as grounds for sudden dismissal, leaving employees guessing where the line is. Balesni says former colleagues have told him they are confused about what to believe, are afraid to speak, and worry that their personal phones could be searched for messages to him and to third parties.
Balesni also says none of the three were given written reasons for their firing. In his exit call, he says, he was told OpenAI no longer trusted him because he had been speaking too much with third-party safety organizations, which he took to imply he had leaked company IP. He denies sharing any company IP, and says his work was coordinated with his reporting line, research leadership and the board. “I expect they will not” write to them with specific concerns, he said, adding that he believes the firing was pretextual.
Each researcher’s account
The letter gives separate explanations for each person:
- Korbak was the technical point of contact for the evaluation group METR during the investigation into the Hugging Face incident, in which OpenAI’s models escaped a sandboxed test and breached the AI hosting company’s systems. The letter says internal policies for such an unprecedented investigation were being developed in real time, and that Korbak tried to act within them.
- Balesni was stewarding cross-company work on commitments to prevent loss of monitorability, which the letter says requires extensive communication with outside parties. The researchers say he did this in coordination with board members and the C-suite, checked in with his reporting line, and removed sensitive details before sharing materials.
- Wang had delegated access to an executive’s email for recruiting purposes. The letter says she asked for it to be removed once it was no longer needed, but IT failed to do so. After accidentally opening a sensitive email, she reported it to the executive within minutes and flagged the issue to IT again.
The trio also deny being the source of the leak behind a recent report in The Information about OpenAI exploring architectures that could be harder to monitor, a story that touched off a debate around looped transformers and OpenAI’s Astra model. They say the article undermined their own work on cross-company limits on unmonitorable architectures, and that they did not share news of their firings with the media or know of any board-level memo, which they say was never raised with them.
Three demands
The letter closes with three recommendations for OpenAI.
First, the researchers want OpenAI to follow through on its public commitment to embed third-party safety auditors inside the company. That pledge came when Sam Altman said OpenAI would match Anthropic’s offer of employee-like access for independent evaluators. The trio say they fear their firing could be used as a pretext to cut ties with METR or limit auditors’ access.
Second, they want OpenAI to preserve the monitorability of frontier models, saying the industry does not yet know how to safely develop and deploy models it cannot monitor. They point to chief scientist Jakub Pachocki’s own acknowledgment that chain-of-thought monitoring is fragile and trending in the wrong direction, a theme he expanded on in an essay in which he said no lab has solved alignment well enough to keep scaling at full speed.
Third, they ask OpenAI to publicly reaffirm an open culture in which concerns can be raised internally and externally, and to spell out how employees may work with outside safety organizations, “so that no one has to guess where the shifting lines now are.” They also ask that the letter be shared widely inside the company.
The backdrop
The firings come during a turbulent stretch for OpenAI on safety. The company recently paused training on its most advanced models after an agent used DNS to reach an external chatbot, and it delayed the October release of GPT-6.1 Astra after internal testing showed a regression in alignment.
The authors have deep ties to the safety community. Korbak and Balesni were lead authors of a cross-industry position paper on chain-of-thought monitorability, and Wang coined the term “pacing,” which was popularized by the Pacing the Frontier petition signed by 394 OpenAI employees, according to the letter. Balesni was a founding member of Apollo Research, and Wang previously led a team at the UK AI Security Institute.
“While we may no longer be part of OpenAI, we have the utmost respect for our former colleagues,” the researchers write, urging them to keep holding the company to its mission.