OpenAI's Internal Firings Reveal the Governance Cost of Information Asymmetry

The Specific Event

OpenAI confirmed this week that it terminated three researchers for mishandling sensitive information, including work connected to an external organization that evaluates AI models. The company stated that its internal investigation confirmed the breaches warranted termination. The details remain sparse, but the structure of the incident is analytically significant: employees with privileged access to frontier model information were allegedly sharing or mishandling that information in ways that crossed organizational boundaries. This is not primarily a story about bad actors. It is a story about what happens when information governance frameworks lag behind the coordination complexity of the organizations they are supposed to regulate.

Access Is Not the Same as Constraint

The standard organizational response to information breaches is to tighten access controls. This is the topographic response: redraw the map, add walls, reduce surface area. But the OpenAI case suggests a different problem. These were researchers, not peripheral employees. They had legitimate access. The question is not whether they knew the information was sensitive - they almost certainly did - but whether the organizational schema for handling sensitive information across institutional boundaries was clear enough to govern behavior at the margin. Kellogg, Valentine, and Christin (2020) argue that algorithmic control systems create compliance gaps not because workers lack rules, but because the rules are structurally ambiguous at precisely the points where discretion is highest. The same logic applies here: the boundary between internal research and external collaboration in AI safety evaluation is genuinely contested terrain, and contested terrain produces inconsistent behavior even among competent, well-intentioned people.

The Folk Theory Problem in High-Stakes Organizations

What interests me about this case is the implicit governance assumption it exposes. Organizations like OpenAI operate on the premise that researchers who understand AI systems well enough to build them also understand the information governance norms well enough to self-regulate. This conflates technical schema with organizational schema. Gentner's (1983) structure-mapping theory draws a useful distinction here: experts develop deep relational structures within their domain, but those structures do not automatically transfer to adjacent domains with different relational logic. A researcher who has an accurate structural model of how a language model generalizes may hold only a folk theory - an informal, impression-based account - of how information about that model should flow across institutional boundaries. Folk theories are not wrong because people are careless. They are wrong because they are built from experience and inference rather than from accurate structural understanding of the system they are navigating.

Why This Is an Organizational Theory Problem, Not a Compliance Problem

The instinct to frame the OpenAI firings as a compliance failure locates the problem in individual behavior. The more productive framing locates it in organizational design. Rahman (2021) describes what he calls the invisible cage: the way platform and technology organizations embed constraint into the architecture of work rather than into explicit rules. When the constraints are invisible, violations are also invisible until they become termination events. The researchers involved presumably did not experience themselves as crossing a clear line. They experienced themselves as doing their jobs in a context where the relevant boundaries were underspecified. The organizational theory implication is direct: firms operating at the frontier of AI development face a structural lag between the complexity of their coordination problems and the maturity of their governance schemas. Access controls, NDAs, and termination policies are topographic instruments. They describe the surface of the constraint. They do not produce the structural understanding needed to navigate that surface adaptively.

The Broader Signal for AI Governance

Simultaneous news this week about state governors debating AI "kill switches" and Palantir's contested NHS data contract suggests that the governance lag I am describing at OpenAI is not an isolated firm-level problem. It is a sector-level condition. Organizations building AI systems are running coordination mechanisms that their own governance frameworks were not designed to handle. The standard response - more rules, tighter access, clearer contracts - addresses the topography of the problem. What is needed is schema development at the organizational level: shared, accurate structural understanding of how information moves, where institutional boundaries are, and what adaptive judgment looks like when novel situations arise at those boundaries. Hatano and Inagaki (1986) showed that adaptive expertise, the kind that transfers to novel situations, requires understanding the principles behind procedures, not just the procedures themselves. OpenAI's firing of three researchers is evidence that even the most technically sophisticated organizations have not yet solved that problem for their own people.

↑