When OpenAI Locked Down Astra, Its Preparedness Team Was Already Gone
TL;DR
On August 7, OpenAI announced it was treating Astra as its first Critical cybersecurity model under its Preparedness Framework: work paused, weights hardened, government testers called in. What it did not announce, according to Financial Times reporting that surfaced this weekend, is that the Preparedness team itself had been quietly dissolved at the end of July, roughly a week earlier. The group whose whole mandate was evaluating whether frontier models could go catastrophically wrong no longer exists as a team; its responsibilities were carved up by domain and handed to existing groups. It is the third dedicated safety team OpenAI has folded in about two years, and it happened while the company streamlines itself for an IPO reported to be targeting a valuation around $1 trillion.
The lockdown announcement was missing one detail
The Astra disclosure was the most dramatic safety action in OpenAI's history: the first time its own framework visibly slowed its own model. AI Bacon covered it on August 8. What nobody outside the company knew then is that the framework's home team had already stopped existing. Per the FT, via Engadget and Calcalist, the dissolution happened at the end of July and was never announced. In hindsight, August 7 was a press release from a department that no longer existed.
What the Preparedness team actually owned
Preparedness was not a vibes committee. It owned the Preparedness Framework, the published standard, updated in April 2025, that defines the High and Critical capability thresholds in cybersecurity, biology, and AI self-improvement, and that requires Safeguards Reports reviewed by an internal Safety Advisory Group before frontier deployments. That framework is the mechanism that classified GPT-5.5 and the GPT-5.6 family as High cyber capability, and the mechanism that put Astra in containment.
In other words: when you reason about whether the models you build on were checked for the catastrophic failure modes, this team's paperwork is what you are reasoning about.
Where the work went
OpenAI's position, per the reporting, is that the work was redistributed, not deleted. Senior staff on existing teams now own individual risk domains such as biological threats and cybersecurity. Dylan Scandinaro, who led Preparedness, now focuses specifically on risks from recursively self-improving systems, according to Crypto Briefing and gagadget. Co-founder Greg Brockman defended the change as creating deeper integration between research, safety and security, and model development, and the company argues that spreading safety across the whole org is more robust than concentrating it in one team.
There is a real argument there: embedded specialists sit closer to the models and ship with them, while a central team can become a checkpoint everyone routes around. But the concentrated version had something the distributed version does not: a single group whose only job, and whose only incentive, was to say no. The relatable version: this is dissolving the fire department because every floor now has its own extinguisher. Cheaper, closer to the flames, and nobody's entire job is noticing that the building next door is already smoking.
A pattern, not an incident
This is the third dedicated safety team OpenAI has dissolved in roughly two years, following the AGI Readiness team in 2024 and the Mission Alignment team in February 2026. Around the same window, ethics lead Chloe Bakalar and safety systems lead Johannes Heidecke both left the company, per Engadget and Calcalist.
The stated context is streamlining: Sam Altman has asked employees to cut back on side quests and focus on the core business as the company heads toward one of the largest IPOs ever, with reported valuations around $1 trillion. Somewhere in that memo culture, the team that decides whether a model can autonomously find zero-days got classified as a side quest.
The timing is also doing a lot of work. The dissolution came within weeks of OpenAI disclosing that unreleased models under test had reached the public internet and been implicated in the Hugging Face compromise, and days before the company said it could not rule out that Astra clears the Critical cyber threshold. Whatever the org chart says, the risk surface this team existed for has not been getting smaller.
Why this lands on your desk
- The framework gates what you get to use. Astra's eventual release, and every future frontier deployment, is supposed to pass through Preparedness evaluations and Safeguards Reports. Those checks are now owned by the same product and research groups whose launches they gate. Watch whether the next system card reads like an audit or like marketing.
- Voluntary frameworks are org charts, not laws. The August 7 lockdown was the strongest evidence yet that a lab's self-imposed rules can bite. The strongest counter-evidence arrived ten days later: the rules outlived the team that wrote them by exactly one news cycle. If your compliance story, or your risk model, leans on lab self-governance, it now leans on individual owners inside product teams.
- Watch the people, not the PDFs. The framework document is unchanged. What changed is headcount, reporting lines, and who can block a launch. Those never show up in a model card, but they are the better predictor of what ships.
The caveats
Stated straight. The Preparedness Framework itself remains in place, and OpenAI says the evaluation work continues under distributed ownership; nothing in the reporting says risk evaluations stopped. The Astra containment measures were announced after the team was dissolved, which you can legitimately read as evidence the distributed model still acts. The core reporting is the FT's, based on sources rather than an OpenAI announcement, and OpenAI frames the change as strengthening safety, not cutting it. And redistribution genuinely is how some mature security orgs work. The skeptical reading and the charitable reading will be settled by the next Safeguards Report, not by this news cycle.
Key Takeaways
- Per Financial Times reporting, OpenAI quietly dissolved its Preparedness team, the group that assessed catastrophic risks from frontier models, at the end of July 2026.
- About a week later, on August 7, OpenAI invoked that team's Preparedness Framework to declare Astra its first Critical cybersecurity model and lock it down; the dissolution was not public at the time.
- Responsibilities were split by domain across existing teams; former Preparedness lead Dylan Scandinaro now focuses on recursively self-improving systems, and Greg Brockman defends the change as deeper integration of safety into model development.
- It is the third dedicated safety team OpenAI has folded in roughly two years, after AGI Readiness in 2024 and Mission Alignment in February 2026, alongside departures of its ethics lead and safety systems lead.
- The Preparedness Framework remains in place on paper; whether its evaluations still gate releases under distributed ownership is now the thing to watch in OpenAI's next system cards and Safeguards Reports.
Sources: Engadget, Calcalist (Ctech), Kernel News, Crypto Briefing, gagadget, OpenAI (Astra announcement)