BBC News reports that OpenAI dismissed three staff after investigating how they shared data with an outside AI evaluation group. To share safely, get formal approval, use a contract and pass on only the data the evaluator needs.
Prepare before you start
According to the BBC, OpenAI fired three employees for mishandling what it called “sensitive information”. The company had investigated them for passing data to an external group that evaluates AI systems. Important details have not been made public. These include what the data was, how it was passed on, whether anyone approved it, and how the evaluation group was involved. This guide does not judge that case. It covers the wider problem behind it: AI companies increasingly invite independent testers to examine their models, so staff need to know where approved collaboration ends and an unauthorised disclosure begins.
Before sharing anything with an outside evaluator, you need four things:
- A copy of your organisation’s information classification policy, which defines what counts as confidential, restricted or public.
- The name of the person or team who can authorise sharing with outside parties. This is often legal, security or a named partnership lead.
- An understanding of what the evaluator is meant to test, such as model behaviour, safety properties or misuse risks.
- Access to the approved tools for transferring files or giving access to models.
If any of these is missing, stop and get it before going further. Most problems with sharing data externally begin when someone works around a gap in process instead of closing it.
Classify the information first
Work out exactly what you plan to share and how it is classified. For AI work, sensitive material can include:
- unreleased model weights or checkpoints
- internal evaluation results
- training data details
- system prompts
- safety incident reports
- product roadmaps
- user data
Each may carry a different classification, and one document can combine several. Check every item against the policy rather than assuming. If you cannot tell how something is classified, treat it as restricted until the owner of the data confirms otherwise.
Confirm who can approve the disclosure
Being allowed to see information is not the same as being allowed to share it. An engineer with full access to model results may still have no authority to send those results outside the company. Find the named approver and ask for written approval, and make sure it covers the specific recipient, the specific data and the purpose. A comment in a chat thread or an informal nod from a manager is rarely enough.
Approval matters even when you believe the sharing helps everyone, as safety-focused evaluation often does. Organisations need a record of what has left the building, both for their own security reviews and for any regulatory obligations they have.
Put an agreement in place with the evaluator
Formal external evaluations normally run under a contract or a non-disclosure agreement. That document should set out:
- what the evaluator may access
- how long they may keep it
- who on their side may see it
- whether and how they may publish findings
- what happens to the data when the work ends
If no agreement exists, the evaluator has no clear obligations and your organisation has no clear remedy if something goes wrong. Ask legal or partnerships staff whether a framework agreement already covers this evaluator before drafting a new one.
Share only through approved channels
Use the tools your organisation has approved for external access. Examples include managed file transfer, access to a model through an API with scoped keys, or a dedicated evaluation environment. Do not use these routes:
- personal email
- consumer cloud storage
- messaging apps
- copying data to your own devices
Approved channels usually log access, enforce expiry and let the security team revoke access later. Data sent through informal routes leaves no reliable trail. It also tends to set off data loss prevention alerts, which can lead to an internal investigation even when your intentions were good.
Minimise and record what you share
Give the evaluator the least they need to do the job. Often, temporary access to a model through a controlled interface is enough, and the underlying weights never need to leave the company. Remove anything unrelated, such as internal names, customer information or notes on unrelated projects. Keep a simple record of:
- what was shared
- the date
- the recipient
- the approval reference
- the channel used
This record protects you as well as the organisation. If questions come up later, you can show that the disclosure was authorised and limited.
Raise concerns through formal routes
Some people share information outside the company because they are worried about safety or ethics and believe internal processes have failed. Even then, quietly sending data to a third party is seldom the safest choice, legally or professionally. Use these routes instead:
- internal escalation channels
- an ethics or safety committee if one exists
- a recognised whistleblowing procedure
Many jurisdictions protect people who report wrongdoing in certain ways and to certain bodies. Those protections depend on following the right route, so get independent legal advice before acting outside your organisation’s processes.
Avoid the mistakes people actually make
- Treating a good cause as approval. Thinking that evaluation helps safety does not give anyone permission to share data.
- Relying on old approvals. Permission for one project or recipient does not carry over to the next.
- Sharing more than needed. Sending a whole folder when two files would do makes any leak worse.
- Using personal tools. Personal email and consumer storage get round logging and are a common trigger for investigations.
- Leaving no record. Without a record, an authorised disclosure can look the same as an unauthorised one.
- Forgetting about retention. Evaluators may keep data long after the work ends unless the agreement says otherwise.
- Assuming contractors are covered. People working for the evaluator may not be bound by the terms you expect.
Know when this approach is the wrong choice
This process assumes that your organisation wants the sharing to happen and simply needs it done properly. It is the wrong framework in these situations:
- You want to report suspected wrongdoing. Use whistleblowing law and procedures, not a data-sharing agreement.
- The data includes personal information about users. Data protection law may require a lawful basis, a data processing agreement or an impact assessment. Internal approval alone is not enough.
- The evaluator is linked to a competitor or a foreign government. Export controls, trade secret law or national security rules may apply, and specialist advice is needed.
- You are leaving the organisation. Once you have left, you usually have no authority to share company information at all, whatever you could access before.
- Your organisation has no policy. In that case, the first step is to get one written, not to improvise case by case.
Frequently asked questions
Can an employee share AI model data with a safety research group?
Only if the organisation approves it. Seeing data at work does not give you the right to send it outside. Sharing is normally done under a written agreement that sets out scope, retention and publication rights, after approval from a named person such as a legal, security or partnership lead. Sharing without that approval can lead to disciplinary action, even when the aim was to improve safety.
What did OpenAI say the three employees did?
BBC News reports that OpenAI fired three employees over the mishandling of sensitive information, after investigating whether they had shared data with an outside AI evaluation group. Further details have not been made public. These include the nature of the data, how it was shared and the identity of the evaluation group, so drawing firm conclusions about the case would be premature.
What is an external AI evaluation group?
An external AI evaluation group is an independent organisation that tests AI models for capabilities, risks or safety problems. Developers often give these groups controlled access before a model’s release so they can probe for harmful behaviour or misuse. The arrangement usually comes with agreements on what data the evaluator receives, how long it may keep the data and what findings it may publish.
Is sharing company data a protected whistleblowing act?
Sometimes, but only under strict conditions. Whistleblowing protections usually apply when a person reports specific kinds of wrongdoing to designated recipients, such as regulators, following set procedures. Passing information to any third party on your own initiative may not qualify for protection. The rules vary by country, so anyone thinking about it should get independent legal advice before sharing.
Sources and further reading
- BBC News technology coverage, which reported the dismissals and the investigation into data sharing with an outside evaluator.
- National cyber security agency guidance on insider risk and on handling sensitive information within organisations.
- International information security management standards covering information classification, access control and supplier relationships.
- Government and standards-body frameworks on AI risk management and third-party evaluation of AI systems.
Surfaced from the rss:bbc_tech signal “AI lab staff dismissals”. AI-assisted draft, editorially reviewed.

