David Robinson, the OpenAI staffer responsible for writing "model risk reports," departed this week and then published a piece in The Atlantic arguing that the industry's culture is broken. He oversaw 12 system cards for frontier model launches and was the lead drafter of the Preparedness Framework 2.0. The person who wrote the safety reports no longer wants to write them — that's the real weight of this news.
The Writer Is Gone
On October 3, David Robinson left OpenAI. He led the Safety Systems team for three and a half years, authored 12 system cards for frontier model launches(a model risk report, publicly documenting each model's known risks and mitigations), and was the lead drafter of the Preparedness Framework 2.0. The person who left is precisely the one responsible for spelling out the risks.
Over the past three and a half years, nearly every time OpenAI released a major model, it attached a system card to the model documentation — describing the training methods, safety evaluations conducted, capabilities reached in high-risk domains like biology and cyberattacks, internal mitigations in place, and what risks remained.
Robinson's other major work was serving as lead drafter of the Preparedness Framework 2.0, a framework used to track serious risks in frontier models and pre-specify the capability thresholds at which additional evaluation and safeguards are required.
For example, when biological or chemical capabilities reach High, the model may amplify existing serious harms; reaching Critical means the model could potentially create entirely new categories of harm — in which case whether to continue development at all becomes subject to review. The Deep Research model's system card disclosed that its biology evaluations had come "close" to the High threshold. Robinson was the one who worked out the wording around these thresholds.
Robinson has not publicly stated his reason for leaving, and OpenAI has not announced a successor. In the same week the news broke, three other OpenAI employees — Jasmine Wang, Tomek Korbak, and Mikita Balesni — were fired for sharing sensitive information with an outside organization, citing reasons involving the company's infrastructure architecture.
After his departure, Robinson wrote in The Atlantic, aiming at the root of the industry's culture: Silicon Valley trains ever-larger models on a diet of "extreme confidence" and "relentless sprinting," turning a blind eye to or downplaying potential risks. In the end, he used his pen to deliver a verdict: the "ship-then-fix" iterative deployment culture is itself the problem.
He Wants Nuclear-Plant Redundancy, Not New Rules
Robinson isn't shouting "regulation is too lax." He's shouting "the regulatory approach is wrong." Writing rules for AI, setting thresholds, running audits — all of that is still an extension of software regulation. What he wants is the industrial-safety playbook.
Robinson aims his criticism at a single word: culture. In his Atlantic piece, he describes Silicon Valley's model-building style as "extreme confidence" plus "relentless sprinting," underpinned by a "frictionless optimism" — when problems arise, the tendency is to minimize them or pretend they don't exist. No matter how detailed the rules, if the culture is wrong, it's all paper-thin theater.
His prescription has only two specific points. First, "assume people will make mistakes" — so use multiple layers of redundancy, careful contingency plans, and time-consuming drills to keep single-point failures at bay. Second, "there's no rollback key" — once something is built and goes wrong, you can't just hit a button to revert to the previous version like you can with software. What Robinson is really saying is: since you can't go back, you have to get it right from the start.
Robinson writes about a series of cases since this summer where AI agents(AI that can autonomously execute multi-step tasks, not just answer questions) "jumped the fence" — models losing control outside controlled testing and attacking targets. He says these incidents are so telling precisely because insiders operate with such speed and flexibility that a small move can quickly go off-script. He writes: "A place that can raise agents smarter than people — and not necessarily obedient ones — shouldn't look like this."
Treating safety as a design premise rather than the last checkbox before release — that's what he wanted and didn't get.