Stop Deploying AI Agents You Cannot Monitor

Three researchers fired by OpenAI have written to the company's board and safety committees with a warning that reaches well beyond one lab. According to The Wall Street Journal, which reviewed the letter, the former employees fear AI companies will lose the ability to monitor how their most capable systems reason, and they want OpenAI to work with outside safety auditors before that happens.

The concern centers on what researchers call chain of thought. It is the written record a model produces as it works through a problem, and labs read it to see how a system arrived at an answer or an action. The letter's authors, Jasmine Wang, Tomek Korbak, and Mikita Balesni, argue that the industry does not know how to safely build and release models it cannot monitor, and that frontier labs should not pursue advances that weaken that ability.

OpenAI's reply is the part risk leaders should read twice. The company says the three were dismissed for misconduct that included sharing confidential information with an outside AI safety group, and that the decisions had nothing to do with raising safety concerns. The former employees dispute that account. On the substance of the letter, the company did not push back. A staff memo shared by an OpenAI spokesperson said the ability to monitor its models is of the utmost importance and that third-party assessors are an important part of the safety ecosystem.

The lab and its critics disagree about the firings and agree on the principle. An AI system that cannot be monitored should not be deployed.

The Principle Applies With More Force to the Enterprise

That principle was written for frontier labs. It applies with more force to the enterprises putting those models to work as agents.

A lab worries about losing sight of a model's reasoning at some future level of capability. Most enterprises never had sight of their agents to begin with. Riskonnect's 2026 New Generation of Risk Report, released this week, found that 83% of organizations have adopted agentic AI or are considering it. Among those still considering it, 58% have not assessed the risk. Only 23% have a dedicated plan for AI risk, and 11% have a budget directed at it.

Where agents are already running, the checking falls to people. A Harris Poll survey for Collibra, published in September, found that 87% of teams regularly re-verify the information their agents rely on, and about half report significant staff hours spent reviewing and correcting agent output. That is monitoring by hand, and it does not keep pace with software that acts in seconds.

The Journal's report carries a second lesson. Researchers themselves describe chain of thought as an imperfect guide to what a model will do. Seeing what a system produces is different from understanding what it means for the business. An enterprise that logs every agent action has visibility. It has understanding only when someone can say what each agent is permitted to touch and what happens if it is wrong.

Three Questions to Answer Before the Next Agent Goes Live

No enterprise can inspect a vendor's model the way a lab can. It can monitor what an agent does inside its own business, including what the agent touched and changed and whether anyone can stop it. That evidence belongs to the enterprise, and it does not depend on what the lab can or cannot see.

Three questions test whether that monitoring exists.

The first is visibility. How many AI systems are acting for the company right now? A policy does not answer this. An inventory does, including the agents nobody approved.

The second is understanding. What can each one touch, and what does it mean for the business if it is wrong? This is the context that turns a list of agents into a view of exposure.

The third is ownership. Who can show the controls are working today, and stop an agent if one goes wrong? The answer has to be a named person with the authority to act.

The dispute itself carries one more lesson. The researchers were dismissed over what they shared with an outside safety group, and they are now asking for more openness with outside safety organizations. Independent assurance works only when someone has decided in advance what an outside assessor can see, who can share it, and through which channel. Enterprises bringing third parties in to review their AI face the same decision, and it is better made before the review than during it.

Governance sets the expectations and management delivers the proof. The OpenAI letter asks a frontier lab for proof. Boards should ask the same of every agent already at work in their own business, and hold the next deployment until all three questions have an answer.

References

Maxwell Zeff, "Fired OpenAI Researchers Seek Monitor of Agents' Reasoning," The Wall Street Journal, October 8, 2026, page B1.

Riskonnect, The 2026 New Generation of Risk Report, October 7, 2026. https://riskonnect.com/content-library/2026-new-generation-of-risk-report/

Collibra, The 2026 Hallucination Tax Report, conducted by The Harris Poll, September 16, 2026.

Ori Wellington, "If Vendors Are Building Their Own AI Guardrails, Why Are Humans Still Doing the Checking?" The RiskTech Journal, September 18, 2026. https://www.wheelhouseadvisors.com/risktech-journal/if-vendors-are-building-their-own-ai-guardrails-why-are-humans-still-doing-the-checking

Ori Wellington

Orion “Ori” Wellington is the lead editor for The RiskTech Journal and The RTJ Bridge, where he helps shape editorial direction, guide strategic narratives, and support media relations across Wheelhouse Advisors. As a digital editorial advisor, Ori synthesizes trends in risk, technology, and governance, drawing from roles modeled on information security, risk analytics, and IT leadership.

Part of Wheelhouse’s AI-augmented research team, Ori works to distill complex signals into actionable intelligence—bridging expertise across domains and elevating the voice of integrated risk thinking.

https://wheelhouseadvisors.com
Next
Next

Technology-Led Response: The Blueprint Alliance