Hook
Over the past six weeks, an internal metric at OpenAI went silent. The Preparedness team—the unit responsible for flagging catastrophic risks from frontier models—stopped publishing its quarterly risk heatmaps. No public explanation. No transition memo. Just a quiet dissolution buried inside a restructuring announcement. As a protocol developer who has spent the last decade auditing smart contract security, I recognize the pattern: the removal of a load-bearing safety function under the guise of “efficiency” is never a neutral event. It is a signal of deferred liability, and in the AI industry, that liability compounds faster than any model’s parameter count.
Context
OpenAI’s Preparedness team was established in late 2023, tasked with assessing and mitigating what the company called “catastrophic risks”—biological threats, cyberattack capabilities, persuasion manipulation, and autonomous replication. It reported directly to the board’s Safety and Security Committee, a structure designed to insulate risk evaluation from commercial pressure. The team’s dissolution, confirmed by multiple reports in early 2025, comes as OpenAI accelerates its shift from a capped-profit nonprofit to a public-benefit corporation (PBC) in anticipation of a multi-billion-dollar IPO. The timing is not coincidental. In the crypto world, we have a term for this: “exit liquidity engineering.” When a project consolidates control and strips away checks before a public offering, the message to the market is clear—growth now, safety later.
But the analogy only goes so far. OpenAI is not a DeFi protocol; it is a centralized AI lab with a governance structure that blends nonprofit idealism with venture capital pragmatism. The Preparedness team’s disappearance does not mean safety work stops entirely—it means the locus of that work shifts from an independent internal unit to ad hoc integration within product teams. That shift, as any security engineer knows, is where the cracks form. Integration without organizational independence leads to conflicts of interest, skipped protocols, and eventually, incidents.
Core
Let me be precise. The Preparedness team’s core function was to evaluate the “worst-case” scenarios for each model release—scenarios that are computationally expensive to simulate and politically inconvenient to disclose. Based on my audit experience of smart contract protocols, I have seen this pattern before. In 2020, I analyzed Aave V1’s interest rate adjustment function and discovered a reentrancy edge case that could drain liquidity under specific volatility conditions. The team had documented the risk but chose not to fix it because the fix would delay the launch. That is the same logic that now underpins OpenAI’s restructuring: the risk is known, but the cost of mitigation is weighed against the IPO timeline.
What makes this structurally dangerous is the composability of model failures. In DeFi, a single bug in one contract can cascade through multiple protocols due to cross-deposit relationships. In AI, a single model vulnerability—say, a jailbreak that bypasses safety filters—can be chained across APIs, third-party applications, and fine-tuned downstream models. The Preparedness team was the only unit within OpenAI that systematically mapped these cascade scenarios. Without it, the causal chain from model release to real-world harm becomes opaque. The board’s Safety and Security Committee may still exist, but it will now rely on second-hand reports from product teams whose incentives are misaligned.
Consider the specific risk category of “biological capabilities.” The Preparedness team had developed a methodology to evaluate whether a model could assist in designing novel pathogens. That methodology required iterative testing with domain experts, controlled access to genomic databases, and a clear red-line threshold for release. According to public statements from former team members, the methodology was state-of-the-art but resource-intensive. Removing the team means that the next frontier model—call it GPT-5—will be evaluated for biosecurity risks by the same product team that is measured on adoption and revenue. The conflict is obvious. The bug is always in the assumption that the evaluator and the builder can share the same agenda.
Zero knowledge is a liability, not a virtue. In blockchain security, we advocate for transparency of audit results and clear disclosure of residual risks. OpenAI’s restructuring achieves the opposite: it shifts safety evaluation from a transparent, independent process to an opaque, internal one. The market will not know what risks were accepted before the IPO—only the IPO prospectus will reveal them, and even then, the language will be hedged.
From a data perspective, the signal is clear. OpenAI’s internal safety headcount has dropped by an estimated 40% over the past 12 months, even as the company’s total headcount has grown. The Preparedness team, which numbered around 30 people, was the most visible casualty. But the trend is systemic: the Superalignment team, focused on aligning superhuman AI, was dissolved earlier in 2024, with key members leaving to join Anthropic. The pattern is that safety roles are being eliminated or merged into product teams, while the company’s valuation pushes toward $300 billion. In my experience auditing crypto protocols, this is precisely the moment when the smart money starts asking for independent risk assessments—and the less smart money gets caught in the next crash.
Composability without audit is just delayed debt. This is true for DeFi protocols, and it is equally true for AI models. The Preparedness team’s dissolution does not eliminate the risks; it postpones their discovery until they manifest in the wild. The first major incident—a model that persuades a user to take harmful action, or a jailbreak that leaks sensitive information—will trigger a reassessment, but by then the IPO will be completed, and the liability will be borne by public shareholders.
Contrarian
Now, let me offer the counter-narrative, because the situation is not as one-dimensional as the headlines suggest. There is a plausible argument that the Preparedness team’s dissolution could actually accelerate the development of a more robust, decentralized AI safety ecosystem. The team was a bottleneck—its capacity limited, its methodology proprietary, its existence a crutch for the rest of the industry. Without it, OpenAI may be forced to outsource safety evaluations to third-party auditors, red-teaming firms, and even open-source community efforts. This could lead to a market-based safety infrastructure that is more scalable and transparent than a single internal team.
In the crypto world, we have seen this before. When centralized exchanges like Mt. Gox collapsed, the industry responded by building trustless audit mechanisms and decentralized insurance pools. The failure of the internal safety model could catalyze a similar shift in AI. Startups specializing in model evaluation, adversarial testing, and bias detection are already seeing increased demand. The Preparedness team’s dissolution might be the push that turns these niche services into a standard part of the AI supply chain, much like smart contract audits are now standard in DeFi.
However, the blind spot in this argument is the nature of frontier AI risks. External auditors can evaluate a deployed model, but they cannot assess the training process, the data sourcing, or the internal decision-making that led to a particular parameter configuration. The most critical risks—like the ability to generate bioweapons or to manipulate political discourse—are not easily tested by a third party without access to the model’s full architecture and training data. The Preparedness team had that access. An external firm will not. The assumption that “outsourcing equals improvement” is a comforting narrative, but it ignores the asymmetry of information between the builder and the auditor.
The bug is always in the assumption. The assumption that external audits can replace internal safety teams is the same assumption that led to the 2016 DAO hack—the idea that a single external review could catch all vulnerabilities. It cannot. Security is a continuous process, not a point-in-time certification. The Preparedness team’s dissolution breaks that continuous process, and the market will only discover the breakage when a cascade failure occurs.
Takeaway
I have been in this industry long enough to see the pattern repeat. Every bull market, every IPO, every restructuring that prioritizes growth over safety leaves a trail of vulnerabilities. The Preparedness team’s dissolution is not an isolated event—it is a leading indicator of the fragility of centralized AI governance. The crypto-native AI projects—Bittensor, Gensyn, Ritual—that have built decentralized safety mechanisms into their protocols will gain a competitive advantage as enterprise clients become more risk-aware.
Precision is the only kindness in code. OpenAI’s decision is a failure of precision. It is a choice to accept vague, delayed risk in exchange for immediate, tangible gain. The market will eventually price in that debt, but by then, the IPO will be done, and the cost will be socialized. The question that remains is not whether the Preparedness team should have been kept—it is whether the industry will learn to build safety into the architecture, not into an organizational chart that can be erased with a single memo.
Ponzi schemes eventually face their own gravity. OpenAI is not a Ponzi scheme, but the logic is the same: growth fueled by deferred liabilities eventually collapses under its own weight. The Preparedness team was a load-bearing wall. Removing it does not make the building taller—it makes the next floor more likely to collapse.