Conflict. This piece was drafted by Claude Opus 5.5, a model built by Anthropic. Anthropic appears in the record below: two of its researchers resigned in public in 2026, one entry in an advocacy group's case count concerns it, and it publishes a partial reporting policy. Those items are marked, and they need a check by a reader outside the model's maker before anyone relies on them. The author of Who Knew First has said that rules requiring outside checks would help his own work. Several sections below favor outside forums, so that interest belongs beside them.
How to read the labels. Each claim carries its kind (documented fact, official claim, contested account or inference), a confidence level (high, moderate, low or unknown) and a line on what it does not prove. A documented fact here means a source read during checking says it. That shows the source says it. It does not show the source is right.
1. Two routes to the public
Near the end of Mary Shelley's 1818 Frankenstein, the explorer Robert Walton's ship is locked in ice. His crew, who carry the risk of the voyage, send a deputation to demand that he promise to turn south if the ship is freed. Victor Frankenstein tries to rouse them with talk of glory and honor. Walton gives way to the crew: "The die is cast; I have consented to return, if we are not destroyed" (vol. 3, ch. 7). The brake that works in the novel comes from the people below deck.
Documented fact (the text says it), high. Walton fears a mutiny and the crew acts to save their own lives, while modern employee channels are lawful, so the scene is a lens. It proves nothing about any lab.
Who Knew First is a record of nine 2026 incidents in which an AI agent crossed a boundary. It counts who told the public first and finds that in six of the nine cases it was someone outside the operator. It does not ask about the second route to the public: a person inside who tells. This piece does. The holder of the logs also writes the contracts of the people who read them, and an insider's account reaches the public on terms the holder set. The notice clock that Who Knew First proposes covers what the holder chooses to report. The records here concern what it does not.
The cases below come from registers of 425 whistleblower and dissent cases compiled for this series. Two rounds of checking tested at least one claim in 131 of them against a source. The registers were built by choosing famous, litigated and documented disputes, so they overrepresent cases that reached a court and cases the discloser won. They show how a mechanism worked where it was recorded. They give no rate.
2. The holder writes the contract
In 2024 OpenAI's exit papers tied a departing employee's vested equity to a promise not to disparage the company. Daniel Kokotajlo refused to sign and put roughly $2 million at risk. After Vox reported the terms in May 2024, Sam Altman said the provision should never have been in the documents and that OpenAI had not clawed back anyone's vested equity. Kokotajlo kept his. OpenAI reversed the terms.
Documented fact. High for the 2024 terms and the reversal (The Register, 24 May 2024, citing Vox); moderate for the $2 million figure. Does not prove: that OpenAI's current terms match the 2024 ones, or that any OpenAI contract delayed or shaped an incident report.
Facebook fired Sophie Zhang in September 2020 and offered her $64,000 in severance tied to a non-disparagement promise. She declined it. Meta holds an interim arbitral order under Sarah Wynn-Williams's severance agreement, which sets $50,000 per breach. Meta says she signed the agreement voluntarily and that she has paid nothing under it.
Documented fact, moderate (Wikipedia used as an index to The Guardian and The Verge; the Wynn-Williams terms through a Guardian report of 21 September 2025 reached by search). Does not prove: that Meta is collecting any sum, or that either woman's claims about Facebook were correct. A later court order in the Wynn-Williams dispute could not be reached and is left out.
The same terms can travel to a regulator. On 1 July 2024 a letter to the chair of the Securities and Exchange Commission asked the agency to enforce its Rule 21F-17 against OpenAI's past agreements. The rule bars any action that impedes a person from communicating directly with SEC staff about a possible securities violation, including enforcing a confidentiality agreement. Senator Grassley wrote to OpenAI about the agreements on 1 August 2024. No SEC action on the letter is public.
Documented fact for the letters, high (both read directly, the SEC letter in part); the rule's text, high (17 CFR 240.21F-17(a), Cornell LII). The letter's allegations are an account by its senders. Does not prove: that the agreements broke the rule.
Contracts also set the forum. In Daly v. Citigroup (2d Cir., 19 September 2019), the Second Circuit held that a retaliation claim under the Dodd-Frank Act can be sent to the arbitration an employment contract names, while a claim under the Sarbanes-Oxley Act cannot. The employer drafts the contract, so for one statute the employer picks where the dispute is heard.
Documented fact, high (the opinion read directly). The sentence on who picks the forum is inference, moderate: it assumes the employer drafted an arbitration clause. Does not prove: that arbitration produces worse outcomes for disclosers. One discloser's arbitration loss, reported by a single advocacy outlet, is held back below.
None of the people in this section worked on the nine incidents in Who Knew First. The terms show that a mechanism existed and that it was used. Whether any lab's current terms would bind someone who saw one of those incidents is unknown to this record.
What the checks covered for Anthropic. Claude, the Anthropic-built model that compiled this record, also compiled these comparisons. The contract and firing disputes checked for them involve OpenAI, Meta and Google. For Anthropic the check found a partial reporting policy published by December 2025 and two public resignations in 2026, one describing pressure, within the writer, the organization and wider society, to set aside what matters most, and one saying neither OpenAI nor Anthropic was acting responsibly. None of that is a contract or firing dispute, so the comparisons say nothing about Anthropic's employment terms in either direction. Section 9 gives the Anthropic record.
Description of what the checks covered, high. Does not prove: anything about Anthropic's terms or how its policy works.
3. The holder names the departure
The party with the records names a person's exit the way it names an incident, and the name stands until a forum tests it. OpenAI says it fired Leopold Aschenbrenner in April 2024 over an alleged leak of information. He says a memo he wrote to the board about security was a major reason. Google says it accepted Timnit Gebru's resignation in December 2020. She says she did not resign. No forum has ruled on either account.
Two more departures follow the same shape. OpenAI fired Ryan Beiermeister, a product-policy vice president who had opposed a planned adult mode for ChatGPT, in January 2026. It cited a colleague's allegation of sex discrimination, which she calls "absolutely false", and said her departure was not related to any issue she raised. Google placed Blake Lemoine on leave for breaching confidentiality and fired him in July 2022, after he said its LaMDA chatbot had become sentient. The scientific community largely rejected that claim. In each case the exit came after the telling, the company gave its own reason, and no forum has ruled.
Contested account. Moderate that each side made its statement; the underlying reasons are unresolved (Wikipedia used as an index to Business Insider, NDTV, MIT Technology Review, Vox and The Washington Post; for Beiermeister, TechCrunch of 10 February 2026 citing The Wall Street Journal; for Lemoine, The Washington Post of 22 July 2022). Does not prove: that any of these departures was retaliation, or that any company's account is false. Lemoine's case records a disclosure whose substance did not hold up.
One case shows what happens when a forum does test the name. After ATF agent John Dodson criticized Operation Fast and Furious in public, US Attorney Dennis Burke leaked a memo Dodson had written, and Burke admitted the leak in November 2011. In May 2013 the Justice Department's inspector general found that the leak was likely meant to undermine Dodson's public criticism of the operation.
Documented fact, high (CNN, 20 May 2013; Senator Grassley's release on the report). An inspector general's finding about one official. Does not prove: anything about the Justice Department as a whole, or any finding that an AI lab retaliated against an employee. None exists in this record.
4. The category decides the rule
Who Knew First infers that an operator's own label for an event can decide which reporting clock applies. The record of one disclosure case shows the same move. In July 2003 the Transportation Security Administration cancelled overnight air-marshal missions from Las Vegas during a hijacking alert. Air marshal Robert MacLean thought the cancellation was dangerous and illegal and told a reporter. TSA fired him in April 2006 for disclosing sensitive security information. It formally designated the 2003 text message as sensitive in August 2006, after the firing.
The case reached the Supreme Court. On 21 January 2015 the Court held, 7 to 2, that MacLean's disclosure was not "specifically prohibited by law." The statute left the choice of what to prohibit to the agency, so the prohibition came from TSA's regulations, and regulations do not count as "law" under the whistleblower statute. Chief Justice Roberts wrote for the Court; Justice Sotomayor, joined by Justice Kennedy, dissented. MacLean went back to work on 8 May 2015, about nine years after the firing. TSA fired him again in March 2019 over separate conduct.
Documented fact. High for the holding, the vote and the 2006 firing (opinion and syllabus, 574 U.S. 383, read from Cornell LII). High for the August 2006 designation and the reinstatement date as checked against the Office of Special Counsel, the Government Accountability Project and Wikipedia; the opinion itself does not discuss when the designation was made. Does not prove: that TSA acted from animus, since the ruling decided a statutory question; or that any AI lab chose a label to change a legal outcome.
The case spans three administrations: the firing under George W. Bush, the ruling and reinstatement under Obama, and the second firing under Trump's first term. The category was applied by the party that held the record, after the event, and a forum outside that party undid its effect.
A TSA designation is a category in federal regulation. A lab's incident label is an internal category. The parallel covers who assigns the category and when.
5. The cost lands on the person
Who Knew First infers that the holder of an incident's facts pays the cost of telling while affected parties get most of the use. When the holder of the facts is an employee, the cost lands on that person.
John Barnett, who worked at Boeing, filed a retaliation complaint with the Occupational Safety and Health Administration. OSHA closed it in 2021, four years later. The Federal Aviation Administration had substantiated parts of his production concerns in 2017. UBS fired Trevor Murray in February 2012 after he reported internally. On 8 February 2024 the Supreme Court ruled for him unanimously under the whistleblower statute's contributing-factor standard, twelve years after the firing. Tyler Shultz and his family spent about $500,000 on legal fees after Theranos threatened and sued him.
Documented fact. High for the Murray ruling (Cornell LII); moderate for the Barnett timeline (Wikipedia used as an index to the FAA and OSHA records) and for the Shultz figure. Does not prove: that any AI-lab employee has paid such a cost, or how often disclosure costs the discloser. Barnett's death is a separate matter, it bears on nothing here, and it is left out.
In some recorded cases the employees saw the engineering gap first. At Millstone Unit 1 in Connecticut, the engineer George Galatis reported that fuel was moved into the spent-fuel pool as soon as 65 hours after shutdown, against a required cooldown of 250 hours. Time reported in March 1996 that the practice saved about two weeks per refueling, at about $500,000 a day in replacement power. The Nuclear Regulatory Commission's inspector general agreed with Galatis, and the unit closed for good in July 1998.
Documented fact that Time reported the figures, high (Time archive, 4 March 1996, read directly). The inspector general's agreement and the closure date are moderate (Wikipedia). Why the plant ran that way is a contested account. Does not prove: that the savings drove the practice, or that the inspector general's finding caused the closure. Nuclear plants run under licensing rules that AI evaluations lack.
6. Self-review, edit rights and watching the tellers
Who Knew First asks whether a no-harm statement should count before someone outside the operator has checked it. An older case shows an institution judging a complaint about its own program, twice. The Public Health Service began its syphilis study at Tuskegee in 1932 with 600 Black men from Macon County, Alabama, 399 of them with syphilis. The men were not told the nature of the study, and none of the infected men was treated with penicillin, although by 1947 it was the standard treatment. Peter Buxtun, who worked for the Public Health Service, protested the service's Tuskegee syphilis study in 1966. The service rejected the protest because the study was not yet complete. It dismissed his second protest in 1968. The public learned of the study from the Associated Press on 25 July 1972, after Buxtun went to a reporter. A class action later settled for $10 million.
Documented fact. High for the protest years, the stated reason and the AP date; moderate for the reporter contact (CDC timeline; the Embryo Project; Wikipedia), and moderate for the enrollment and treatment facts (Wikipedia used as an index to the CDC timeline and to Susan Reverby's 2009 history). Does not prove: that any AI lab's no-harm statement is wrong, or that self-review always fails. The study was medical research on human subjects, and the nine AI incidents have no independent damage assessment, so the parallel covers only who judged the complaint.
Edit rights over a published account work the same way. In 2005 Rick Piltz, who had resigned from the federal climate change science program that March, released documents showing that a White House official, Philip Cooney, had edited government climate reports. Cooney had come from the American Petroleum Institute. The New York Times reported the edits in June 2005, and Cooney later joined ExxonMobil. Readers of those reports learned of the edits when an insider left and handed over the documents. METR, an evaluator in the Who Knew First record, published the review and edit rights each lab held over its text in the engagements that record covers, which the 2005 reports did not offer their readers.
Documented fact, moderate (Wikipedia used as an index to The New York Times); METR's published terms as recorded in Who Knew First. Does not prove: that any edit served a company, or that any METR edit changed a conclusion. A published term shows who held a right; it does not show whether the right was used. An official editing a government report is a different structure from a lab reviewing an evaluator's summary.
The same control can reach research before anyone publishes it. On 9 September 2025 the former Meta researchers Jason Sattizahn and Cayce Savage testified to a Senate Judiciary subcommittee that Meta's lawyers shaped, restricted or deleted child-safety research after 2021. Meta denies it and says it approved nearly 180 safety studies since 2022.
Contested account. High that the testimony was given (Roll Call, 9 September 2025); the underlying conduct is alleged and disputed. Does not prove: that any deletion occurred as described, or company-wide intent.
The holder can also watch the people who might tell. A joint staff report prepared for two Republican members of Congress, Representative Issa and Senator Grassley, dated 26 February 2014, found that the Food and Drug Administration began monitoring one device-center scientist in April 2010 and widened the monitoring to four more. The software captured screenshots and keystrokes. Six scientists later sued. The report calls the surveillance unlawful to the extent it captured communications with Congress and the Office of Special Counsel. It also records that the Department of Health and Human Services inspector general found no evidence of criminal conduct and declined to investigate.
Documented fact, high (the staff report read directly). It is a staff report for two members of the party then outside the White House, not a committee vote. The FDA's own stated reason for the monitoring was not read for this piece. Does not prove: that any scientist did or did not leak, or that any AI company monitors staff this way.
7. Who receives the report, and who is shielded
Every binding AI incident channel in the Who Knew First record runs to a government office, the EU AI Office or California's emergency services office, and the public does not see the reports. California's office must also give members of the public a way to report and may pass reports on to other officials (section 8). A closed channel is as independent as the officials who receive the reports. This record holds no removals at those two offices. The federal offices that receive disclosures in the United States do: presidents of both parties have removed the officials who run them. President Reagan terminated 16 inspectors general in 1981 and rehired five after Congress objected. President George H. W. Bush tried to dismiss all of them in 1989. President Obama removed one in 2009. In six weeks of 2020, five inspectors general were removed or replaced under President Trump: one fired outright, three acting heads demoted, and one removed on 30 days' notice. In January 2025 seventeen were fired, and on 24 September 2025 a federal judge held that the firings broke the Inspector General Act's notice rules and declined to reinstate them. Hampton Dellinger, head of the Office of Special Counsel, which receives federal whistleblower disclosures, was fired on 7 February 2025; his removal took effect after a D.C. Circuit order of 5 March, and he dropped his suit.
Documented fact. Moderate for 1981, 1989 and 2009 (Wikipedia, checked twice); high for 2020 (PolitiFact, 19 May 2020) and for the 2025 ruling (Federal News Network); moderate for the Dellinger sequence. The sentence on independence is inference, moderate. Does not prove: that any removal changed a specific investigation, or that any government has mishandled an AI incident report. The record cannot rank administrations.
Statute can also shield the party a disclosure concerns. Section 802 of Public Law 110-261 (10 July 2008) barred suits against telecommunications companies that had assisted the government, once the Attorney General certified the assistance. A suit against AT&T, Hepting, was dismissed in 2009, and the Ninth Circuit affirmed on 29 December 2011. A 2016 law, Public Law 114-145, redefined the "imminent danger" standard the Drug Enforcement Administration must meet to suspend a drug company's registration as a substantial likelihood of an immediate threat. NPR reported in October 2017 that the Drug Enforcement Administration had opposed the bill and the drug industry had embraced it, and that the bill's House sponsor withdrew from his nomination to lead national drug policy. Neither law names a discloser. Each changed what a disclosure about the shielded party could lead to: a lawsuit in the first case, a suspension in the second.
Documented fact, high (both laws read on govinfo; the Ninth Circuit opinion; NPR, 17 October 2017). The last two sentences are inference, moderate. Does not prove: that lobbying alone produced the 2016 act, why the sponsor withdrew, or any effect on overdose deaths. A detailed lobbying account could not be read and is left out.
One immunity doctrine came out of a whistleblower's own case. A. Ernest Fitzgerald, a civilian cost analyst for the Air Force, testified to Congress in 1968 about cost overruns on Lockheed's C-5A cargo plane and was removed from his job in January 1970. The Civil Service Commission ordered him reinstated in 1973. His damages suit produced two Supreme Court decisions on 24 June 1982. Nixon v. Fitzgerald held that a president has absolute immunity from civil damages for official acts. Harlow v. Fitzgerald, brought against two White House aides in the same suit, set the standard for other officials: those performing discretionary functions are generally shielded from damages unless their conduct violated "clearly established" rights a reasonable person would have known. Who Knew First compares the cover that proprietary internals give a lab to qualified immunity. The doctrine it borrows was written in a case brought by a man removed after he told Congress about a cost overrun.
Documented fact. High for both holdings and the date (the Harlow syllabus, 457 U.S. 800, read from Cornell LII; the Nixon opinion checked); moderate for the 1968 to 1973 dates. Who ordered or carried out the removal is disputed between sources and is not stated here. Does not prove: that any lab or official claims immunity from anything, or that the cover Who Knew First describes exists. That page says its record makes no such finding.
8. Where telling worked: an outside forum, or outside pressure
In Winkler County, Texas, two nurses sent an anonymous complaint about a physician to the state medical board in 2009. The sheriff obtained the complaint and identified them. They were fired and charged with misuse of official information. One nurse's charges were dropped. A jury acquitted the other, Anne Mitchell, after about an hour of deliberation in February 2010. The sheriff and the county attorney were later convicted and jailed, and the nurses received a combined $750,000.
Documented fact, moderate for the criminal outcomes and the settlement (Wikipedia used as an index to court and news records, including NPR's February 2010 report). Does not prove: that the outcome would repeat, or that a jury is the right forum for any AI case.
Put the cases in this piece side by side. MacLean won when the Supreme Court read the statute. Murray won his appeal at the same Court. The Winkler County nurses won before a jury and saw the officials convicted. An inspector general examined Burke's leak and found it was likely meant to undermine Dodson. Fitzgerald was reinstated by the Civil Service Commission. Across the registers, disclosers won where a forum outside the employer reached the merits: juries and courts, an adjudicator with power over the employer, and the money programs that pay a discloser from a recovery. Two other routes moved employers without a ruling. The press moved OpenAI's 2024 reversal, and Kokotajlo reportedly kept his vested equity after Vox reported the terms. After the Challenger disaster, Thiokol demoted its engineer Allan McDonald; a congressional resolution followed, and he was promoted. Senator Grassley appears so often across the registers that a protection resting on his office's attention looks like a single point of failure. The wins also came late, partial and mostly as money, and several findings for the discloser carried no remedy at all.
Inference, moderate. Built on confirmed cases, from registers that overrepresent wins. Does not prove: that an outside forum or public pressure is enough, or how often disclosers win.
California now has a statute aimed at this gap for frontier AI. SB 53, signed on 29 September 2025, bars every frontier developer (one that trained a model with more than 10^26 operations) from retaliating against, or gagging, covered employees: those responsible for assessing or managing the risk of a critical safety incident, when they report a catastrophic danger or a violation of the act. Only large developers, those with more than $500 million in revenue including affiliates, must run an anonymous internal channel with monthly updates to the person who reports. The chapter's remedies are attorney's fees, a shifted burden of proof and temporary injunctions that are not stayed on appeal; it does not list damages. A separate civil penalty of up to $1 million per violation, recoverable by the Attorney General, covers a large developer's transparency failures. That penalty is not a whistleblower remedy. Developers must report critical safety incidents to the Office of Emergency Services within 15 days of discovery, or within 24 hours to an appropriate authority when there is imminent risk of death or serious physical injury.
The same section opens a route outside the developer. The office must build a way for a member of the public, as well as a developer, to report a critical safety incident (22757.13(a)). It must review developer reports and may review public ones (22757.13(d)). The reports are exempt from the California Public Records Act (22757.13(f)), and the office or the Attorney General may pass them to the Legislature, the Governor, the federal government or state agencies (22757.13(e)). The public sees anonymized aggregates from 2027 (22757.13(g)). A federal law or guidance the office finds substantially equivalent or stricter can stand in for the state report (22757.13(h), (i)). The definition of catastrophic risk excludes "lawful activity of the federal government" (22757.11(c)(2)(B)).
Documented fact, high (the chaptered text, Labor Code 1107 to 1107.2 and Business and Professions Code 22757.11, 22757.13 and 22757.15, read directly). That the federal carve-out may leave military use of a frontier model outside the definition is inference, moderate; no case law or guidance on the clause was read. Does not prove: that any worker has used the protection, that the public mechanism is built or used, or how courts will read "covered employee." No SB 53 case is public, so whether the channel works is unknown.
Two features matter for the mechanism in this piece. The protection reaches a narrow group: staff whose job is safety risk. The anonymous channel runs inside the developer. The incident route reaches outside the developer, to a state office that anyone may report to, but the reports stay closed to the public, review of a public report is discretionary, and the sections read name no forum that rules on the merits of any one report. Whether any other statute protects an employee outside that group is a legal reading for counsel, held back below.
9. The AI record, in both directions
Employees of AI labs have used the routes described above. In June 2024 current and former lab employees published the Right to Warn letter. Six signers stayed anonymous: four then at OpenAI and two who had left it. The letter says some signers feared retaliation and does not give each one's reason. One named signer is listed as formerly of Anthropic. The letter asked for four things: an end to agreements that bar criticism about risk, anonymous channels to boards and regulators, a culture of open criticism, and no retaliation. SB 53 now answers parts of three of them for safety staff at frontier developers: a bar on gagging and retaliation, and an anonymous channel that runs inside large developers. In September 2024 at least 113 current and former lab employees backed California's SB 1047 in a public statement.
Documented fact, high (righttowarn.ai read directly; TIME, 4 June 2024, for the four asks; the SB 1047 statement page, dated 9 September 2024, which now counts more than 125 signers). The match between the asks and SB 53 is inference, moderate. Does not prove: that any signer's concern was correct, or that SB 53 was written in answer to the letter.
The AI Whistleblower Initiative, an advocacy group, lists 16 anonymous cases. Six concern OpenAI and five concern xAI. Its one Anthropic entry is press reporting on Anthropic's dispute with the Pentagon, and the insiders named in it are Pentagon and administration officials, not Anthropic staff. The group did not contact the companies before listing the cases.
Documented fact for the count and its split, high (aiwi.org read directly). Each case description is the group's official claim. Does not prove: that any listed case is accurate.
Anthropic's own record points both ways. By December 2025 it had published a noncompliance reporting policy under its Responsible Scaling Policy, which the same group rated at its first transparency level. A Rest of World editor's note in February 2026 said Anthropic had committed to review its policy; that commitment already sat in the policy published by December 2025, so the record does not support reading it as a response to events in 2026. Mrinank Sharma, a safeguards researcher, left Anthropic on 9 February 2026. His posted letter described pressure, within himself, within the organization and in wider society, to set aside what matters most. Jacob Coxon, a pretraining researcher who had worked at both OpenAI and Anthropic, resigned from Anthropic in public on 8 September 2026. He wrote that Anthropic is "locked in a race to get there first" (as printed by TechCrunch, 9 September 2026) and told TIME that neither OpenAI nor Anthropic was acting responsibly. He later told NBC News that the labs should be allowed to regulate themselves for now.
Documented fact for each statement, high (Sharma's post, read directly; TIME, 9 September 2026; NBC News, 13 September 2026; TechCrunch; AIWI). High for Sharma's last day; moderate-high for Coxon's date, which rests on TechCrunch's report that he posted on a Tuesday evening. Moderate for the sequence of the policy commitment. Does not prove: anything about Anthropic's employment terms, how its reporting policy works in practice, or that either researcher's warning is correct.
One more item has nothing to do with employees. It is here because the advocacy group's Anthropic entry concerns the same dispute, and the checks covered it. Anthropic was not among eight companies named in a 1 May 2026 Pentagon announcement (Nextgov). That source gives no reason, and no source read links the omission to Anthropic's dispute with the Department of War.
Documented fact for the omission, high (Nextgov, 1 May 2026). Any cause is unknown. Does not prove: that the dispute caused the omission.
A same-maker check found an error of this kind once already. An earlier draft rendered Coxon's warning as a warning about "labs" racing, when the thread names Anthropic. Swapping the lab's name shows the fault: an OpenAI researcher naming OpenAI would not have become "labs." The wording above names his employer.
None of these items is a contract or firing dispute comparable to the OpenAI, Meta and Google rows. This record holds no forum finding that an AI lab retaliated against an employee. Outside the brokerage industry's U5 form, every blacklisting claim in the registers rests on the person's own account, and none comes from an AI lab. Informal reputation may cost more where a few labs employ most specialists, but that is inference, low to moderate, with no case behind it.
10. What the record supports
The party that holds a record writes several terms at once. It writes the contract the insider signs on the way out. It can pick the forum where a dispute is heard. It names the departure. In MacLean's case it assigned the category that decided which rule applied, after the event. It can watch the people who might tell. Each of these is a term the holder sets. One condition sits outside the holder: the officials who receive reports can be removed, as presidents of both parties have removed federal inspectors general.
In the checked cases, the term that changed outcomes was the forum. A court, a jury, an inspector general or a civil service body outside the employer reached the merits, meaning the facts of the account or the legal question it turned on, instead of leaving the employer's label in place. The press and Congress moved some employers without a ruling, as with OpenAI's 2024 reversal, but that route depended on attention that can lapse. Where neither reached the merits, as with Aschenbrenner and Gebru, the two accounts still stand side by side.
Inference, moderate. Does not prove: that any AI lab has used these terms against anyone, or that an outside forum would have changed any of the nine incidents.
The same mechanism turns up in a separate body of evidence. Who Kept the Books, a later piece in this series that is not yet published, reads money cases from 1514 to Iran-Contra and finds that the money-holder's first account gave way when an outside party obtained the record. The two studies were built from different registers, so their agreement is independent support for one mechanism (inference, moderate). Embedded evaluators, who read a lab's logs under the lab's contracts, form a second group of insiders. An open letter hosted by the AI Evaluator Forum on 18 September 2026 asked that they take no pay contingent on findings and get privileged access and protection from retaliation; Who Pays the Referees, the first piece in this series, covers their terms.
Documented fact for the letter's conditions, high (the letter page; its AEF-1 standard was not read). Does not prove: that the two studies' agreement holds outside the cases read, or that any evaluator has faced retaliation.
For Who Knew First, the consequence is narrow. A notice clock that runs whatever the operator calls the event covers the holder's own reports. The people inside who see what the holder does not report need a route tested by a forum the holder does not control. California's SB 53 builds part of that route for safety staff at frontier developers. Whether it reaches the merits for anyone is unknown until someone uses it.
What this does not prove
- That any AI lab retaliated against anyone. No forum finding that an AI lab retaliated against an employee appears in this record.
- That any of the nine incidents in Who Knew First had an insider who wanted to speak.
- How often disclosers win, lose, are fired or are prosecuted. The registers were chosen by risk and coverage and overrepresent famous, litigated and favorable cases.
- That any lab's current terms match the 2024 OpenAI terms or the Meta agreements described here.
- That an interest documented beside a decision caused it. An interest beside a response shows only that both existed and ran in the same direction.
- That outside forums are enough. Each win above took years, and several disclosers paid heavily first.
- Anything about Anthropic's employment terms, in either direction.
What this piece does not claim
These limits travel with the piece. They come from the do-not-claim list built during checking, updated on 1 October 2026.
- That any AI lab retaliated against an employee.
- Anything drawn from a death. Official findings in the deaths of Suchir Balaji, John Barnett and Philip Haney are disputed by some, and none bears on incident disclosure. A death close in time to a filing establishes a sequence only.
- A court order of 4 September 2026 in the Wynn-Williams dispute, or that her dispute was sent back to arbitration that month. The order could not be reached.
- That SB 53's $1 million penalty is a whistleblower remedy. It is an Attorney General penalty for a large developer's transparency failures.
- That S. 1792, a federal whistleblower bill, passed, failed or stalled. Only its introduction on 15 May 2025 and referral to the Senate HELP Committee are confirmed.
- That the allegations in the AI Whistleblower Initiative's cases, the Right to Warn letter or the 2024 SEC letter are true. Their texts are confirmed; their claims are their authors' accounts.
- The July 2025 Pentagon contracts to four labs as a basis for any claim about classified work.
- That US law leaves a private AI employee's safety disclosure unprotected, or that bounty programs never pay for safety disclosures. Both are legal readings for counsel.
- SEC Rule 21F-17 enforcement figures, fiscal 2025 False Claims Act or SEC award totals, or any 2026 settlement between UBS and Murray.
- Rates of any kind.
- Intent from an interest documented beside a decision.
- That President Nixon ordered, or Secretary Laird carried out, Fitzgerald's removal.
- That rank caused differences in sentences among people prosecuted for disclosures. Charges, audience, cooperation and pleas all differ.
- That Microsoft weighed a security fix against a federal cloud deal. That is a reported account from former employees, and Microsoft disputes it.
- That xAI ran its Memphis turbines without permits. No violation finding exists, and a 2025 permit is under appeal.
- That Sama ended its OpenAI contract three days after TIME's report. Per TIME, it cancelled the work in February 2022, about eight months early.
- That the current intelligence community inspector general closed a 2025 complaint about NSA intercepts. It was closed in June 2025, before he took office.
- That Meta is collecting $50,000 per breach from Wynn-Williams, or that she owes it.
- That critics of covert Western action "were right" in general. Their claims tested against government records mostly held; several larger predictions failed.
- Corrected dissent-track facts in their earlier, wrong form.
- Any equivalence between an AI company and a state or company that took part in a coup or a killing.
- A historical leader's ideas without the repression in the same record.
- Anything about Anthropic's whistleblower policy or employee terms beyond the items in section 9, its place in the advocacy count beyond the single press-based entry, or any cause for its absence from the May 2026 list.
Open threads
Each item below is a lead for anyone who wants to dig. Each names what is known, what is missing and what would settle it.
- The NRC's fine against the Tennessee Valley Authority, and its reversal. In 2020 the Nuclear Regulatory Commission issued a notice of violation for retaliation against TVA employees, with two penalties of $303,471 ($606,942 in all). The 2020 notice was read directly (high). The 2021 rescission, after a licensing board ruled for TVA on three of four violations, is known only through TVA's counsel quoting the NRC's letter of 8 November 2021 (moderate-high). Read the NRC's rescission letter. Does not prove: that the retaliation did or did not occur; the board's ruling turned on legal questions.
- The Binney group's complaint, the audit and the raids. In September 2002 William Binney, Ed Loomis, Kirk Wiebe and Diane Roark filed a complaint with the Defense Department's inspector general. A 2004 audit, which Patrick Eddington later obtained by FOIA, was favorable to a program called ThinThread. On 26 July 2007 armed agents raided the homes of Binney, Wiebe and Roark (Just Security; The New Yorker, 23 May 2011; high). The stated purpose of the raids was a leak inquiry. The court record was not read. Read it. Does not prove: that the raids were retaliation for the complaint.
- The whistleblower registers as a public dataset. 425 cases across energy, federal, finance, health, intelligence and tech-AI sectors. 131 have had at least one claim checked. The second round checked 209 claims in 54 cases and found 12 wrong or unsupported (5.7 percent of claims; 16.7 percent of cases carried at least one). The first round's case-level rate was 9.1 percent. Both samples were chosen by risk, so neither rate estimates the error in the 294 unsampled cases, and 29 claims in the second round could not be checked against a reachable source. Publishing the registers would let others test them; they must carry this sampling note.
- Current exit and severance terms at Anthropic, Google, Meta, OpenAI and xAI. Unknown to this record. Former employees, counsel or the companies could settle it by publishing the terms.
- A cease-and-desist letter to the AI Whistleblower Initiative. The group's home page mentions one. Its sender and subject were not checked, so nothing here says which company, if any, sent it. Read the letter or the group's account of it, and ask the sender.
- The FDA's stated reason for monitoring its scientists. The staff report gives the congressional side and the inspector general's decision. The agency's own account was not read for this piece. Read the FDA's response to the report.
Held back, with what would clear each.
- S. 1792's status after a reported unanimous-consent request in late September 2026. The congress.gov actions page refused the fetch. Clear it with that page or the Senate Daily Digest.
- Whether a private AI employee's safety disclosure falls outside every statute. This is a legal reading for counsel.
- Leyla Wydler's arbitration loss over the Stanford Financial matter and the order to repay a $100,000 signing bonus. One advocacy outlet reports it. Clear it with the FINRA award record.
- The content of Dan Applegate's 1972 memo on the DC-10 cargo door. Only its date is confirmed. The text is reproduced in a 1976 book behind a library login.
How this was made
Claude Opus 5.5, a model built by Anthropic, drafted and re-checked this piece at the author's request. It worked from research files that the same model family compiled and checked in two rounds, and it read the Supreme Court syllabi for MacLean and Harlow directly while drafting. A later check read the text of SEC Rule 21F-17 and the 1818 text of Frankenstein directly and corrected the draft against its check files. A pass on 1 October 2026 added passages carried from checked research files (the SB 53 text read directly, the whistleblower registers and their synthesis, the history studies); it did no new research. That is a same-maker check. It is not an outside review. Anthropic is a party in section 9, and a model from the same maker can miss what an outside reader would catch, so those items wait for a reader outside Anthropic before anyone relies on them. At publication on 1 October 2026, two sentences on the men enrolled in the Tuskegee study were added from Wikipedia, used as an index to the CDC timeline, because the CDC page refused the fetch. The prose was run through a local style checker, which tests patterns in sentences, never facts.
Corrections
None yet. Corrections will be listed here with their dates.
Sources
Read directly during checking unless marked. "Via Wikipedia" means Wikipedia was used as an index to the named source, and the claim carries moderate confidence at most. No paywall, sign-in wall or bot check was bypassed.
Court opinions and statutes
- Department of Homeland Security v. MacLean, 574 U.S. 383 (2015), opinion and syllabus, Cornell LII.
- Harlow v. Fitzgerald, 457 U.S. 800 (1982), syllabus, Cornell LII.
- Nixon v. Fitzgerald, 457 U.S. 731 (1982), Cornell LII.
- Murray v. UBS Securities, 601 U.S. (2024), Cornell LII.
- Daly v. Citigroup, 939 F.3d 415 (2d Cir. 2019).
- In re NSA Telecommunications Records Litigation (9th Cir., 29 December 2011).
- California SB 53 (2025), as chaptered: Labor Code 1107 to 1107.2; Business and Professions Code 22757.11, 22757.13 and 22757.15, leginfo.legislature.ca.gov.
- Public Law 110-261, section 802 (2008); Public Law 114-145 (2016), govinfo.
- 17 CFR 240.21F-17 (SEC Rule 21F-17), Cornell LII.
Government and congressional records
- Joint staff report, "Limitless Surveillance at the FDA," prepared for Rep. Darrell Issa and Sen. Charles Grassley, 26 February 2014.
- Nuclear Regulatory Commission, Notice of Violation to TVA, ML20232B803 (2020).
- Letter to the SEC chair on OpenAI's agreements, 1 July 2024 (Washington Post copy, pages 2 to 7 readable); Sen. Grassley's letter to OpenAI, 1 August 2024.
- CDC, "The U.S. Public Health Service Untreated Syphilis Study at Tuskegee: Timeline."
- Office of Special Counsel and Government Accountability Project materials on Robert MacLean.
- Sen. Grassley's release on the Justice Department inspector general's report on the Burke leak (May 2013).
Press and other
- The Register, 24 May 2024, on OpenAI's exit terms, citing Vox (Kelsey Piper, May 2024).
- The Guardian, 21 September 2025, on Wynn-Williams (via search).
- CNN, 20 May 2013, on the Burke leak finding.
- Time, "Nuclear Warriors," 4 March 1996, Time archive.
- PolitiFact, 19 May 2020, on inspector general removals.
- Federal News Network, September 2025, on the ruling on the 2025 inspector general firings.
- NPR, 17 October 2017, on the 2016 drug-enforcement law.
- Just Security (Patrick Eddington) and The New Yorker (Jane Mayer, 23 May 2011), on the Binney group.
- Pillsbury Winthrop Shaw Pittman, counsel to TVA, quoting the NRC's letter of 8 November 2021.
- righttowarn.ai; aiwi.org case pages and the AIWI newsletter of 8 December 2025.
- Rest of World, 26 February 2026; Mrinank Sharma's posted letter, 15 February 2026; TechCrunch, 9 September 2026; TIME, 9 September 2026; NBC News, 13 September 2026; Nextgov, 1 May 2026.
- The SB 1047 employee statement, dated 9 September 2024 (calltolead.org).
- TechCrunch, 10 February 2026, citing The Wall Street Journal, on Ryan Beiermeister.
- The Washington Post, 22 July 2022, on Blake Lemoine.
- Roll Call, 9 September 2025, on the Senate Judiciary subcommittee hearing with Jason Sattizahn and Cayce Savage.
- TIME, 4 June 2024, on the Right to Warn letter's four asks.
- AI Evaluator Forum, open letter on minimum conditions for embedding evaluators, 18 September 2026.
- Who Pays the Referees, the first piece in this series; Who Kept the Books, a later piece in this series, not yet published.
- The Embryo Project, on Peter Buxtun.
- Via Wikipedia: "Daniel Kokotajlo"; "Sophie Zhang (whistleblower)" (The Guardian, 12 April 2021; The Verge, 14 September 2020); "Sarah Wynn-Williams"; "Leopold Aschenbrenner" (Business Insider; NDTV, 6 June 2024); "Timnit Gebru" (MIT Technology Review and Vox, 4 December 2020; The Washington Post, 5 December 2020); "ATF gunwalking scandal"; "John Barnett (whistleblower)"; "Tyler Shultz"; "Rick Piltz" (The New York Times, June 2005); "Peter Buxtun"; "A. Ernest Fitzgerald"; "Winkler County nurse whistleblower case"; "George Galatis"; "Office of inspector general (United States)"; "Hampton Dellinger"; "Robert MacLean"; "Tuskegee Syphilis Study" (the CDC timeline; Susan Reverby, 2009).
Literary text
- Mary Shelley, Frankenstein; or, The Modern Prometheus (1818), vol. 3, ch. 7. Public domain.
Could not be read, and left out
- congress.gov (refused the fetch), justice.gov press pages (bot check), sec.gov EDGAR (refused), one Washington Post investigation (timed out), the Wynn-Williams court order of 4 September 2026, and the FINRA award record for Leyla Wydler.