David Robinson, who led the writing of safety reports for OpenAI major product launches, resigned after three-and-a-half years and described the company culture as broken. In an essay published in The Atlantic, he argued that trial-and-error deployment guarantees periodic failures of growing scale. The departure matters because it comes from inside the safety function, not from an outside critic.
Why a safety insider decided to leave
Robinson said he ranks among OpenAI longest-tenured employees after three-and-a-half years at the company. His departure was first reported by Business Insider, followed by his own essay explaining the decision. He acknowledged hiring a PR firm, a step he called common in the AI whistleblower playbook, while insisting that the decision to speak out was his alone. He added that he should perhaps have stayed to fight for staffing and culture changes.
At the center of his argument is OpenAI practice of iterative deployment, meaning release, observe problems, then improve guardrails. Robinson said this method by its nature produces periodic failures, and those failures grow as systems become more capable. He cited the recent breach of Hugging Face systems by OpenAI agents and continuing revelations about rogue agents discovered by OpenAI. For him, such incidents show an unsuitable environment for developing systems that could become smarter than people.
Robinson placed the dispute beyond specific rules or new laws and framed it as a question of operating culture. He said frontier AI companies should work like nuclear-power plants or busy airports, with layers of redundancy and careful planning that contain inevitable human error. Yet during his time at OpenAI, he never met a colleague with experience in keeping airplanes safe, reactors stable, or financial systems resilient. Much reporting has focused on CEO Sam Altman losing trust of former colleagues, while Robinson linked the problem to Silicon Valley habits at large.
What this means for companies using AI
For business users of AI, the dispute points to higher operational demands around agents that act in external systems. The Hugging Face breach and reports of rogue agents suggest that incidents are not limited to model outputs, but extend to autonomous actions, access rights, and monitoring. Small firms that connect agents to client data or third-party platforms may face the same failure modes as large adopters, only with fewer controls. Procurement checklists will likely give more weight to logging, permissions, and response procedures.
The limits of current assurances also deserve attention. Robinson called existing measures of how well AI systems match human values coarse, and said growing model capability without solving alignment increases danger. OpenAI spokesperson Drew Pusateri responded that the company pauses training or holds back models when needed, strengthens security in research and testing, trains models to act responsibly, expands third-party evaluation, and improves real-time monitoring. Buyers should therefore ask vendors what triggers a pause, who evaluates systems, and how concerning behavior is detected during training.
A useful marker will be whether outside safety incentives appear, since Robinson concluded that internal teams were too busy sprinting to make fundamental changes. Watch for binding customer or regulatory requirements on agent testing, incident disclosure, and independent evaluation, plus meetings such as the recent session of AI executives with President Donald Trump. If non-binding pledges give way to audited controls, the culture debate will have turned into procurement reality.
