AI whistleblowing is the disclosure, by current or former AI-company employees, contractors, or former employees, of safety concerns, capability risks, or governance failures to regulators, the public, or internal channels. As a distinct policy concept it draws on three developments: California SB 53, the first statute to make AI-specific whistleblower protection a named statutory provision rather than an incidental feature of general employment law; a series of departures and disclosures from frontier labs in 2024–2025; and a public controversy over the contractual instruments labs used to limit disclosure — nondisparagement agreements and vesting-conditional NDAs — that shaped subsequent legislation.
Scope
AI whistleblowing covers disclosures by an employee, contractor, or former employee of an AI company that raise concerns about safety evaluations and their results; capability thresholds and whether they have been crossed; compliance with published safety frameworks such as a responsible scaling policy (RSP); misrepresentation of safety practices to regulators or the public; unmitigated catastrophic risk, including CBRN, cybersecurity, and autonomy; and suppression of internal safety research or dissent.
Protected disclosures must typically be made in good faith, must concern a matter of public or regulatory concern, and must — under most statutes — be directed to a qualifying recipient (a regulator, Congress, specified agencies, or in some regimes the public).
Legal bases for protection
AI whistleblowers historically relied on general federal whistleblower protections — the Sarbanes-Oxley Act (SOX) for public companies, Dodd-Frank for the financial sector, and the False Claims Act for federal contractors — and on common-law public-policy wrongful-discharge doctrines. None of these were AI-specific. California SB 53 is the first statute to address AI directly.
Section 7 of the National Labor Relations Act (NLRA) provides an independent, federal, non-AI-specific basis. It protects employees' right to engage in "concerted activity," meaning collective action on terms and conditions of employment. In McLaren Macomb (2023), the National Labor Relations Board (NLRB) took the position that overly broad severance-agreement confidentiality and non-disparagement clauses can violate Section 7. On that reading, the departure agreements at issue in the OpenAI controversy may be legally vulnerable regardless of any AI-specific statute.
A recurring distinction in the area is between internal and external reporting. Most AI labs maintain internal reporting channels — ombuds, responsible-disclosure email inboxes, and board-level committees. Whistleblowing statutes typically protect external disclosure, to regulators or the public, on the argument that internal channels can be captured; the Right-to-Warn letter contends that internal channels at frontier labs have been insufficient. Traditional whistleblower regimes favor disclosure to regulators and discourage public disclosure. The Right-to-Warn framing departs from this by treating the public as a protected disclosure recipient, on the argument that no regulator yet has the technical capacity or standing to oversee frontier AI.
A further distinction concerns the timing of disclosure. Nondisparagement and non-disclosure clauses in departure agreements are the primary contractual obstacle to post-employment AI whistleblowing. Their enforceability sits in a legal gray zone, varying by state, by clause, and by whether the disclosure implicates a public-interest concern.
California SB 53
The California Transparency in Frontier Artificial Intelligence Act (SB 53) is, as of 2026, the first statute to treat AI whistleblower protection as a named statutory provision rather than an incidental feature of general employment law. It covers current and former employees of large frontier developers; protects disclosures of (a) the developer's failure to comply with its own published safety framework and (b) substantial dangers from catastrophic risk; prohibits retaliation, including termination, demotion, suspension, and harassment; voids contractual provisions such as NDAs and nondisparagement clauses that would prevent such disclosure; requires developers to maintain an internal anonymous reporting channel; and creates administrative remedies including reinstatement and back pay.
SB 53 was a response to the 2024 nondisparagement-NDA controversy and the Right-to-Warn letter. Its structure contemplates disclosure to the state attorney general and, in the language of the protected-disclosure clause, to channels that effectively include journalistic and public-facing ones. The statute reflects an approach in which regulators that cannot directly audit models rely instead on employees with direct access to internal information.
The Right-to-Warn letter
In June 2024, a group of current and former OpenAI employees — Daniel Kokotajlo, William Saunders, Carroll Wainwright, Jacob Hilton, Daniel Ziegler, and four anonymous current OpenAI employees — together with a current and a former DeepMind researcher signed "A Right to Warn about Advanced Artificial Intelligence." The letter made four asks of AI companies: do not enforce non-disparagement agreements that block criticism of risks; facilitate a verifiably anonymous process for current and former employees to raise concerns to the board, regulators, and independent organizations; support a culture of open criticism; and do not retaliate for publicly sharing risk-related information, given inadequate official channels.
The letter was endorsed by Yoshua Bengio, Geoffrey Hinton, and Stuart Russell. It became the intellectual basis for SB 53's whistleblower provisions.
Departures and the nondisparagement-NDA controversy
Two departures brought the public-disclosure question into view. Leopold Aschenbrenner left OpenAI in April 2024 after, by his account, raising concerns internally and being dismissed partly for circulating a security memo outside the company. He subsequently published Situational Awareness (June 2024), a 165-page public document arguing that AGI arrives by approximately 2027, presenting material plausibly derived from his OpenAI experience, and advocating US nationalization of frontier labs. Aschenbrenner later founded a public investment firm trading on that thesis. Daniel Kokotajlo resigned from OpenAI in April 2024 and publicly declined to sign the company's departure agreement, which reportedly included a lifetime nondisparagement clause tied to equity vesting; his refusal, and the resulting forfeiture of equity, surfaced the nondisparagement-vesting linkage that became a controversy. The two cases differ in character: Aschenbrenner's Situational Awareness advances a specific strategic view, while Kokotajlo's disclosure concerned process — the nondisparagement clause itself. Both fed the Right-to-Warn momentum.
Reporting in May 2024 (Vox and others) revealed that OpenAI's standard departure agreements conditioned equity vesting on signing a lifetime nondisparagement agreement, effectively requiring former employees to surrender substantial compensation or accept permanent silence. After public backlash, OpenAI CEO Sam Altman stated that the company would not enforce these provisions and would remove them going forward. Similar clauses, less aggressive in structure, were reported across other frontier labs. The controversy is cited in SB 53's legislative history as justification for the statutory voiding of such clauses in the AI safety context.
Policy responses
California SB 53's whistleblower provisions are the statutory model, and the Right-to-Warn principles are the industry-facing voluntary asks. NLRB enforcement attacks overly broad departure-agreement language on Section 7 grounds. The Frontier Model Forum and other industry bodies have not substantively addressed the whistleblowing question in public statements.
At the federal level, the AI Whistleblower Protection Act, introduced by Sen. Chuck Grassley, is a bipartisan bill that, per Winter & Bullock, would prohibit retaliation against whistleblowers who disclose information about "substantial and specific" dangers to public health, public safety, or national security to an appropriate government agency. It would protect disclosures even where no law has been broken, closing a gap that SB 53 — which protects only employees "responsible for assessing, managing, or addressing" catastrophic risks — and most general whistleblower statutes leave open. The Federal Railroad Safety Act's protection of any "hazardous safety or security condition" is cited as precedent for this no-violation-required model. Winter & Bullock characterize federal whistleblower protections as a near-costless, optionality-preserving capacity-building measure (Radical Optionality: Governing Transformative AI Under Uncertainty). The SB 53 framework remains a plausible template for a broader federal regime, with the Grassley bill the live vehicle.
Relationships
- depends-on: California SB 53 — Transparency in Frontier AI Act — the statutory model with first-class whistleblower protections
- related: Situational Awareness: The Decade Ahead — post-departure public disclosure
- related: Leopold Aschenbrenner — the protagonist entity page
- related: Anthropic's Responsible Scaling Policy (Version 3.1), OpenAI Preparedness Framework V.2 — the published frameworks whistleblowers would assess compliance against
- related: AI Liability — disclosure channels relevant to tort and regulatory-compliance evidence
- related: Frontier Model Forum — industry body that has not addressed whistleblower rules in public statements
- related: Radical Optionality: Governing Transformative AI Under Uncertainty — argues federal whistleblower protections are a near-costless optionality-preserving capacity-building measure; Radical Optionality
- instance-of: AI governance via regulated disclosure