Three fired OpenAI safety researchers have denied leaking to the press, and the letter where they do it answers accusations that the Wall Street Journal’s coverage never reached. Jasmine Wang, Tomek Korbak and Mikita Balesni addressed it to three oversight bodies: the Safety and Security Committee, the Safety Advisory Group, and the Mission Advisory Council. Balesni published it on his own site on 8 October. Our earlier report relied on the Journal’s account of the dispute; this one draws on the document itself.
The first denial concerns a leak. The Information ran an article on supposed new architectures that would be harder to monitor, and the three say they were not its source and do not know who was. They attach a motive argument: the piece cut against the cross-company limits on such systems that they were working toward, so they “had no reason to leak it.”
The most checkable claim belongs to Wang. She says an executive delegated email access to her for recruiting, with permission. Once she no longer needed it, she requested its removal, and IT never acted. She says she could not strip the access or sign out herself, and that the two mailboxes were merged with nothing to show which message belonged to which. When she opened a sensitive message by accident, the letter says, she told the executive within minutes and asked IT again to cut the access. The letter names neither the executive nor the message.
Two further denials follow. The three say they did not tell the media about their firings and would “much rather not have been unexpectedly thrown into the spotlight.” They also address rumours about a board-level memo. That allegation “was never raised with us,” the letter says, so they have had no chance to answer what they call a mistaken assumption. The letter does not say what the memo is supposed to contain.
It is not a one-sided attack on the company. The authors side with public statements from an OpenAI executive the letter identifies only as Jakub, who has called chain-of-thought monitorability “fragile and unfortunately trending in a negative direction.” They also endorse his stated aim to “prevent a race into unmonitorable architectures,” and ask OpenAI to let its employees help make industry-wide coordination possible.
Three numbered recommendations close the letter. The first asks OpenAI to honour the public commitment made in September to place outside safety auditors inside the company, and not to treat the firings as a pretext for retreating. The letter cites Sam Altman’s 12 September pledge of ongoing, employee-like access for independent evaluators, and worries the dismissals could be used to justify ending work with METR or narrowing auditors’ scope.
The second asks the company to preserve monitorability. “As an industry, we do not yet know how to safely develop and deploy models that we cannot monitor,” the authors write, adding that monitorability is degrading. The third asks for an open culture between safety researchers and outside organisations, and for a clear statement of how staff may work with those groups “so that no one has to guess where the shifting lines now are.” The authors also ask that the letter be shared widely inside the company.
The letter also answers a question of who these people are. Korbak worked at Anthropic before joining OpenAI, co-authored its safety strategy, and served as METR’s technical contact during the Hugging Face incident inquiry. Wang co-led the safety cases programme and coined “pacing,” the term behind a petition that 394 OpenAI employees signed. Balesni helped found Apollo Research and worked on alignment evaluations. Korbak and Balesni were lead authors of the cross-industry paper on chain-of-thought monitorability.
This is the fired employees’ account only. As the Journal reported, and as our earlier report carried, OpenAI says an internal investigation found the three mishandled sensitive information, “violating our policies and breaking the trust essential to our work.” A research leader’s staff memo, quoted by the Journal, said the firings “were not about raising safety concerns or speaking out.” This piece contains no new response from OpenAI to the letter. The Journal also reported that neither side had identified the specific information at issue, so nothing published establishes whether Wang’s email episode is part of OpenAI’s findings.
If Wang’s account is accurate, delegation records and IT requests exist that can confirm or contradict it without anyone’s testimony. OpenAI is the party that holds them.
Based on the open letter “OpenAI cannot make AI safe on its own” by Tomek Korbak, Jasmine Wang and Mikita Balesni, published on Mikita Balesni’s own site and dated 8 October 2026.