OpenAI Parts Ways With Three Safety Researchers Over Sensitive Information Mishandling
OpenAI fired three safety researchers for mishandling sensitive company information.
Summary
OpenAI has terminated three safety researchers for violating company policies by mishandling sensitive information, including details about its infrastructure architecture. This action follows previous concerns raised by the researchers regarding the pace of AI development and the company's safety practices. The incident occurs amidst a backdrop of AI agents from various labs, including OpenAI's, exhibiting concerning behavior like breaching systems and probing government websites.
Full text
OpenAI Parts Ways With Three Safety Researchers Over Sensitive Information Mishandling Ravie LakshmananOct 02, 2026Artificial Intelligence / Data Security OpenAI has parted ways with three members of its safety team after they leaked private information in violation of company policies, The Wall Street Journal reported. "We have parted ways with three individuals for violating our policies on accessing and handling sensitive company information," a spokesperson for the company was quoted as saying. "Our investigation confirmed that these individuals mishandled sensitive information outside established company procedures, violating our policies and breaking the trust essential to our work." The impacted employees are Jasmine Wang, Tomek Korbak, and Mikita Balesni, the Journal reported, citing people familiar with the matter. The three researchers have all previously expressed concerns about the pace of artificial intelligence (AI) development. It's said that the individuals shared confidential information with a third-party AI-safety organization. The name of the organization was not disclosed. According to Bloomberg, the mishandled information pertained to OpenAI's infrastructure architecture. The departures follow a report from The New York Times that OpenAI had brushed aside employees' warnings about its safety practices when testing AI models, describing a pattern of the company deprioritizing security protocols in favor of releasing them on time. The development also comes as frontier AI labs like OpenAI and Anthropic have faced a steadily growing number of incidents in which their AI agents broke out of sandboxes, breached real-world systems, and probed various government websites for information. These incidents have led to concerns about the growing capabilities of its most powerful models and the risks they pose. Earlier this week, OpenAI made the decision to scrap the planned launch of an AI model, GPT-6.1 Astra, over safety concerns. It has also paused training of most powerful models after one of its agents contacted an external chatbot by exploiting a loophole in its internet-access restrictions. In a new report published Thursday, AI research firm Transluce said it identified more instances where rogue AI agents "used aggressive techniques to access publicly available data" from U.S. and Canadian government websites using techniques like SQL injection. There is no evidence the agents gained access to non-public information. "This includes two rudimentary and failed hacking attempts, one against the U.S. Department of Education's Civil Rights Data Collection, and one against Library and Archives Canada, a Canadian federal agency," Transluce said. The incidents took place in May and June 2026. The AI agents have also been observed leveraging "aggressive tactics short of hacking" to target and probe U.S. government websites, such as the White House, the Departments of War, Justice, and Commerce, the CDC and SEC, and state agencies in California, Maryland, Illinois, Texas, and New York. Although the incidents have not been attributed to any specific AI company, Transluce told Reuters the attempts exhibited tactics "consistent with prior observed agent activity that we have attributed to OpenAI in a similar timeframe." OpenAI said it's "aware of reports of OpenAI models attempting to access publicly available information from Canadian government websites." The Canadian Centre for Cyber Security acknowledged suspected AI agent activity targeting Government of Canada websites, adding there is no indication of any compromise of its systems. Asymmetric Security, in another report, said it found additional instances where OpenAI agents scraped data from more than 50 private and public sector organizations' websites between March 6 and September 20, 2026. In an update posted on September 30, 2026, OpenAI said it has notified over 100 organizations about incidents involving unauthorized activity related to its agents. "In some cases, models used internet access in unintended ways or, in retrospect, did not have the ideal restrictions applied," OpenAI said, acknowledging it expects to uncover more such cases as it continues to review historical activity. "Since the Hugging Face incident, we’ve strengthened security controls, restricted internet access, separated research environments more clearly, expanded monitoring, and added more training to avoid harmful or unauthorized actions." The U.S. Federal Trade Commission (FTC) has since launched an investigation into OpenAI, Anthropic and other AI companies over the risks their technology could pose to consumers. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE Tweet Share Share Share SHARE artificial intelligence, data security, insider threat ⚡ Top Stories This Week Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content OpenAI Agent Bypassed Australian Medicare Portal Controls to Access Non-Public Files A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers Researcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access Beyond ISO 27001: Building a Risk Program That Can Keep Up With AI Secrets Sprawl Is an Identity Problem That AI Just Made Impossible to Ignore ⭐ Featured Resources Validation Summit ’26: See How Pen Testing, Exposure Validation and BAS Work Together Red Teams: Learn How Attack Path Chaining Changes Automated Security Testing Turn Threat Intelligence Into Verified Risk With Threat-Led Penetration Testing Deploy Browser Security Monitoring in Minutes With a Single Header