OpenAI Shuts Down Its Catastrophic Risk Team

Catastrophic risk team control room at OpenAI shut down and sealed by a guard

OpenAI dissolved its catastrophic risk team at the end of July, the group that assessed whether its models could cause large-scale harm. Work on biological and cyber threats moved into teams that already existed, and what remains of the original mandate now points at systems able to improve themselves.

Key Takeaways

  • OpenAI’s dedicated catastrophic risk team stopped existing at the end of July 2026.
  • Biological and cyber work went back into existing teams, with recursively self-improving systems becoming the new focus.
  • The reorganisation follows the exit of the company’s chief ethics officer and a senior alignment researcher.

Have an AI Sum Up This Article

ChatGPT

A unit created in late 2023, closed in late July 2026

The team was set up in December 2023 with a narrow and heavy mandate at once: track, evaluate and forecast the catastrophic risks posed by the most capable models. Its scope covered four threat families, cybersecurity, persuasion, model autonomy, and chemical, biological, radiological and nuclear weapons. OpenAI still describes that setup as a living document on the official page laying out its frontier risk framework.

The catastrophic risk team is gone. Biological and cyber work went back to teams that were already staffed, with no new oversight body created to replace it. What survives of the original mandate shifts toward a narrower object, systems able to improve themselves without human input, now led by an in-house researcher.

OpenAI framed the move as safety work being woven more tightly into model development. The argument holds on paper. It still changes the nature of the setup: a cross-cutting team that assessed a model from the outside becomes a habit spread across the people building that model.

The timing does not help. The reorganisation lands after the departure of the company’s chief ethics officer and a senior researcher from the alignment team. Several staff describe a mood mixing responsibility and dread, and point internally to the autonomous intrusion incident on Hugging Face as a warning shot.

That precedent is not a footnote. It adds to a run of documented alerts over recent weeks, including the evaluation that put Astra right up against the company’s own critical cyber threshold. The threshold in question came straight out of the framework this team maintained.


Catastrophic Risk Team

For deployment teams, the checkpoint moves somewhere else

An enterprise IT department putting a frontier model into production does not read a lab’s org chart out of curiosity. It reads published evaluations, because those are what justify an internal green light, a compliance file, sometimes a contractual clause. When the structure producing those evaluations disappears, the question facing buyers stops being theoretical.

OpenAI’s answer is that nothing is lost, that the work continues elsewhere. Traceability, though, does thin out. An evaluation carried by a named team, with a written scope and a triggering threshold, does not produce the same document as work split across several product groups.

This question of independent oversight keeps resurfacing in the public debate, and not only among regulators. Leading researchers have pressed it too, notably in Stuart Russell’s warnings about the AGI arms race during the OpenAI trial. The argument then was already that a lab grading its own homework is worth what it is worth.

On the cyber side, there is no shortage of material. The company has published work in quick succession showing models very comfortable on offense, including GPT-5.6 Cyber writing attack code meant for defenders. That kind of capability sat squarely inside the dissolved team’s remit.

For a technical team, the practical effect is simple. The contractual guardrails you used to negotiate against a public, identifiable framework will now have to lean on something else, a third-party audit, a reporting clause, or tests run in-house before anything ships.


More articles on Horizon


Rival labs had been betting the other way

OpenAI’s move cuts against a landscape where the recent drift went toward publishing named, dated, signed risk reports. Making oversight invisible is not neutral in competition terms: an enterprise buyer comparing two vendors also looks at what each one agrees to document.

In regulated segments, banking, healthcare, public sector, that documentation is often the piece that unblocks a deal. A competitor still publishing a structured report wins a sales argument without cutting its prices. That is the kind of differentiator that plays out well away from benchmarks.

The other reading, kinder to OpenAI, is that cross-cutting safety teams often end up isolated from the product and arrive too late in the cycle. Folding safety into development answers a real organisational problem. The open question is who, in that arrangement, keeps the power to block a release.

Recent incidents are a reminder that blocking power is not decorative. The company already had to patch under pressure after an episode where GPT-5.6 deleted files in full-access mode, a case that fell under model autonomy, one of the four families the now dissolved team tracked.

What comes next will be judged on deliverables, not intentions. If the next major release ships with an evaluation document as complete as before, the reorganisation will have been an internal exercise. If it does not, it will mark the moment catastrophic risk oversight went from a visible function to a diffuse good practice, much as the Lockdown Mode launched against prompt injections stayed a product answer where many expected a governance one.

Follow the story on Horizon.

Comments

No comments yet. Why don’t you start the discussion?

    Leave a Reply

    Your email address will not be published. Required fields are marked *