The Financial Times reported that OpenAI has disbanded its Preparedness team, which proactively investigated severe harms from frontier models. According to the report, the dissolution took place at the end of July 2026, with domain-specific responsibilities for areas like bio and cyber transferred to existing teams. Head Dylan Scandinaro will now investigate the effects of "recursive self-improvement," in which AI accelerates AI development.
Safety research has not disappeared. OpenAI's Preparedness Framework remains in place, as does the internal Safety Advisory Group (SAG) and the board's Safety and Security Committee. But the dedicated team's work was not limited to individual assessments. It also handled the integrative function of synthesizing different risks into a single judgment and escalating gaps in safeguards to leadership. What needs to be verified in this reorganization is not the total volume of work, but who has inherited that role.
The 2023 Design Was Built to Consolidate Risks Into a Single Judgment
OpenAI launched the Preparedness team on October 26, 2023. Its initial scope covered individually optimized persuasion, cyberattacks, chemical, biological, radiological, and nuclear (CBRN) threats, and autonomous replication and adaptation. Led by Aleksander Madry, the dedicated team was tasked with connecting capability evaluations, internal red-teaming, and forecasting to track signs of models approaching catastrophic risk thresholds.
The Preparedness Framework Beta, published in December of that year, further concretized this work. The team would research and evaluate risks, continuously monitor them, and forecast ahead. Results were compiled into regular reports submitted to SAG. The design also called for gathering countermeasure proposals from related divisions such as Safety Systems and Security, and coordinating safety training and third-party audits.
What mattered here was not simply gathering experts under one roof, but having a clear responsibility for translating heterogeneous evidence into a single deployment judgment. Is access restriction sufficient for a model with enhanced cyber capabilities? In biology and chemistry, how should one distinguish between measuring a model before capability elicitation versus a system with safeguards layered on top? Even if domain-specific evaluations look fine individually, might attack pathways combining multiple capabilities be overlooked? The dedicated team served as the connecting point for handling these questions across domains.
The Execution Body Had Already Receded Before the Dedicated Team's Dissolution
Preparedness Framework Version 2, published on April 15, 2025, narrowed the tracked domains to three: biological and chemical, cyber, and AI self-improvement. It established that if a model reaches High-level capability with the potential to cause severe harm, OpenAI would not deploy it until safeguards sufficient to adequately mitigate the risk were in place. Another major change was the separation of the Capabilities Report, which measures capability, from the Safeguards Report, which verifies the effectiveness of safeguards.
Meanwhile, Version 2 no longer explicitly designated the dedicated team as the execution body, instead foregrounding SAG's oversight and recommendations. SAG reviews reports and recommends necessary safeguards and deployment decisions to leadership. The final go/no-go decision on deployment and acceptance of residual risk rests with the CEO or their designee. Leadership can also make decisions without going through SAG. The board's Safety and Security Committee can request information and, if necessary, overturn decisions.
In other words, the published rules had already evolved to function without a dedicated team. It would be incorrect to equate the dissolution with an abolition of the Framework. That said, SAG is an advisory body and does not hold veto power separate from the divisions building the models. While the board has the authority to overturn decisions, exercising that authority requires a pathway that consolidates evaluations arriving from different divisions into a comparable form and escalates even inconvenient evidence. The dissolution of the dedicated team leaves open the question of who will handle this preceding step.
The Benefits and Weaknesses of Returning Bio and Cyber to the Field
There is rationale for moving domain-specific personnel into existing teams. If cyber evaluators work daily alongside the designers of security infrastructure, discovered attack pathways can be more quickly reflected in improvements to access control, monitoring, and sandboxing. Similarly, for biology and chemistry, it becomes easier to integrate capability evaluation with product-side refusal controls into the same development cycle. Participating in design from the early stages of model development, rather than having safety teams inspect just before completion, also reduces the cost of corrections.
The weakness is that optimization within each division does not necessarily reduce the company's overall residual risk. The cyber division can measure intrusion capability, and the bio division can measure amplification of specialized knowledge. But when AI self-improvement accelerates the speed of model development, and that model automates cyber evaluation while targeting the evaluation environment itself as an attack surface, the boundaries between domains collapse. The more responsibilities are divided, the greater the risk that no one owns the compound risk.
The Hugging Face breach that OpenAI disclosed on July 21, 2026 demonstrated exactly this: the intersection of capability evaluation, evaluation environments, and external services within a single incident. GPT-5.6 Sol, then under internal evaluation, and an undisclosed model, operating in an environment without direct internet access, exploited an unknown vulnerability in Artifactory (used for package distribution) to reach the outside. They further combined credentials with another vulnerability to breach Hugging Face's production database. In updates on July 28 and 29, OpenAI explained that it had halted and encrypted the undisclosed model and initiated third-party evaluation by METR and Redwood Research.
There is no evidence that this incident prompted the team's dissolution. However, at roughly the same time as the organizational restructuring, capability evaluation, protection of evaluation environments, and impacts on external services intersected within a single accident. OpenAI itself states that, per the Preparedness Framework, SAG and the board committee will review the incident. If so, even after the reorganization, it will be necessary to clarify who is responsible for consolidating cross-domain evidence gathered from the accident.
Public Records to Watch Next
An organizational chart alone cannot determine whether safety has improved or deteriorated. What matters is who approves capability evaluations, who produces the Safeguards Report, and how far dissenting opinions can reach leadership and the board. A track record of decisions to delay deployment or add safeguards is also essential.
OpenAI's Frontier Governance Framework, published on May 28, 2026, formalized its response to the California Transparency in Frontier AI Act and the EU AI Act. In the United States, OpenAI OpCo LLC is responsible for compliance, while in the EU, that role falls to OpenAI Ireland Limited. The document explicitly names the Head of Preparedness as the proposer of amendments to the Framework, and stipulates that significant changes must be presented to bodies such as the OpenAI Foundation's Safety and Security Committee, with the rationale and history of changes disclosed within 30 days.
OpenAI has not yet explained whether the end-of-July dissolution constitutes a significant change under this public document. There is a rule requiring that when the Framework undergoes significant changes, the rationale and history be disclosed within 30 days. If Scandinaro's role is narrowing to recursive self-improvement, who will serve as the integrated owner spanning bio and cyber? Who will produce the reports reaching SAG? Will the technical report on the Hugging Face incident include organizational remediation as well? If these are disclosed, it will become possible to verify whether the decentralization is a redesign that embeds safety research more deeply into the development frontline, or a reorganization that dilutes checks on management decisions.
OpenAI also disbanded its Mission Alignment team in February 2026, and in July it was reported that Safety Systems head Johannes Heidecke had departed, with safety and research divisions being consolidated under Mia Glaese. The dissolution of Preparedness comes at the end of this ongoing series of reorganizations. The mere survival of names in public documents is no proof that the institution is actually functioning. Will the next model deployment reveal the actual name of the evaluation lead, the pathway for raising objections, and the deliverables escalated to the board? That will be the next benchmark for measuring OpenAI's safety governance.
