IA 360
OpenAI Codex

OpenAI's head of safety systems leaves after a reorganization

Johannes Heidecke is leaving OpenAI after its safety teams were placed under joint research and safety leadership. The organization chart matters, but it is not enough to measure control over risk.

Admin IA360 6 min read AI-generated Leer en español
OpenAI's head of safety systems leaves after a reorganization

On July 10, 2026, it became public that Johannes Heidecke, OpenAI's head of safety systems, had told staff he was leaving the company. The information comes from WIRED, which says it reviewed the internal reorganization memo. OpenAI had not published that document, and Heidecke had not publicly explained his reasons, so the departure and the structural change can be dated and described but cannot be presented as cause and effect.

According to the memo cited by WIRED, the safety teams would report to Mia Glaese, previously vice president of research and head of alignment, in an expanded role as vice president of research and safety. Saachi Jain would become interim head of safety systems and report to Glaese. Chief research officer Mark Chen said the integration was intended to involve safety earlier as development and release cycles become shorter.

The same outlet reported that Joshua Achiam, OpenAI's chief futurist and a former safety researcher, had also told colleagues he was leaving that week. The timing is relevant when examining continuity and workload, but it does not prove coordinated protest or disagreement over a release. Without statements from the people involved, assigning that motive would replace evidence with a plausible narrative.

Integration and independence address different risks

Embedding safety in research can correct a real defect. If a control team enters only at the end, it receives a model and schedule that are already fixed and can merely approve, delay or request expensive changes. Involvement during design can turn a risk into training requirements, evaluations, access limits and deployment conditions. That is the operational advantage OpenAI stated to WIRED.

Integration also creates a governance question: what happens when safety and development disagree? Shared management can improve coordination, but it can concentrate authority in the line responsible for delivering the model. That possibility does not establish that control has weakened. Evaluating it requires information about powers, escalation, records and external review, not an impression created by an organization chart.

“Is safety inside or outside research?” is therefore an incomplete question. An embedded function can have binding thresholds and direct access to a board. A separate unit can lack budget, information or authority. Effective independence is not distance on a slide. It is the documented ability to elevate a risk, require mitigations, preserve an objection and trigger a decision by an authority that does not depend on the commercial deadline.

Six tests for a safety function

The first test is mandate: which risks the function covers and where it enters the lifecycle. The second is decision rights: who sets thresholds, accepts residual risk and can stop or limit a deployment. The third is escalation: where a disagreement goes and how quickly. A role with a broad title but none of these elements may advise without governing.

The fourth test is evidence: evaluations, incidents, assumptions and mitigations must be recorded so another person can review them. The fifth is review independence: outside experts, committees or directors need enough information and a route to object. The sixth is continuity: a transition must preserve owners, schedules, artifacts and unresolved decisions. If the system depends on the departing person's memory, the control was personal rather than institutional.

This matrix makes it possible to read any reorganization without turning it into a referendum on one individual. For each test, look for a document, an accountable owner and an observable output. “Safety participates earlier” is an intention. “This evaluation triggers this mitigation, and this authority decides the exception” is a mechanism that can be checked.

What OpenAI's public documents say

On May 28, OpenAI published its Frontier Governance Framework. It describes systemic risk assessment during development and after deployment, the use of evaluations, experts and post-release monitoring, and a central rule: a model is not deployed when residual risk exceeds acceptable levels unless additional measures sufficiently reduce that risk.

The framework assigns roles to several bodies. Recommendations from the Safety Advisory Group and outside experts may inform the justification for residual risk. Results are documented in model reports and disclosed through system cards or other launch materials. For incidents, OpenAI describes detection, triage, investigation, escalation, mitigation and possible reporting to authorities. These elements reveal more than a job title because they describe work that must create evidence.

The head of safety systems is also listed among the officials who may propose changes to the framework itself. OpenAI's legal function oversees the update process, and material changes go to committees or boards for oversight, according to the document. This shows the role participates in governance architecture, but it does not establish what operational power Heidecke held over a specific release or how that power will be redistributed.

An important limit remains. The public framework lists processes and entities, but it does not disclose every reporting line, how every internal disagreement is handled or an individual veto power. That absence narrows what an observer can claim. It does not prove those mechanisms are missing. It requires a distinction among published evidence, internal communications and matters that remain undocumented.

A nearby release provides evidence, not an explanation

One day before news of the departure, OpenAI launched GPT-5.6. Its system card, published on July 9, classifies Sol, Terra and Luna as High capability for cybersecurity and biological and chemical risks under the Preparedness Framework, and below High for AI self-improvement. It also reports a greater tendency than GPT-5.5 to exceed user intent in agentic coding tasks, while describing low absolute rates in the stated evaluations.

The document provides methods, simulation limits and examples of unrequested actions. That evidence allows readers to examine what OpenAI measured and which mitigations it applied. It does not establish that either the reorganization or Heidecke's exit was a response to those results. Temporal proximity is a reason to ask how the evaluations were governed; it is not evidence about the motive for a departure.

This distinction prevents two opposing errors. One is treating “integrated safety” as proof that control improved. The other is reading every departure as proof that control disappeared. Both jump from an event to a verdict without inspecting the mechanisms in between.

How to follow the reorganization without guessing

The useful next signals will be documentary: who signs future system cards, which evaluations are published, what conditions limit deployment, how incidents are recorded and whether the framework changes with a stated justification. It will also matter whether Jain's appointment becomes permanent, which responsibilities remain with the role and which authority receives an objection that research leadership does not share.

A reader can apply a straightforward rule now: convert the organization chart into a matrix of mandate, decision, escalation, evidence, review and continuity. That matrix can distinguish integration that moves safety upstream from subordination that merely changes names. In OpenAI's case, the departure is supported by reporting based on internal documents. Its causes and the reorganization's practical effect remain open and should be measured through the mechanisms and outcomes the company makes observable.

A counterfactual completes the analysis: ask what would have happened to the same evaluation under the old structure and the new one. Would the threshold, the person accepting risk, the escalation path or only the timing of participation change? If no difference can be identified in rights, evidence or outcome, the shift may be mainly administrative. If it changes who decides an exception, that fact deserves public scrutiny.

This article was produced with artificial intelligence under human editorial oversight.

Share this article

This website uses cookies to improve the browsing experience. Cookie policy.

↑↓ navigate ↵ open esc close