Home

Donate
Perspective

Congress Can Get AI Whistleblower Protection Right On Its First Try

Raqda Sayidali, Abra Ganz, Karl Koch / Aug 20, 2026
Republish

In 2024, an OpenAI researcher, Daniel Kokotajlo, faced a choice no one should have to make, between nearly $2 million in vested equity or his right to warn the public about the technology he was helping build. He chose the warning and gambled the money because he would not sign a lifelong non-disparagement agreement. The company backed down in the face of media coverage; the law offered scant protection. Kokotajlo was not an isolated case; he is one of 13 current and former employees of OpenAI and Google DeepMind who, in June 2024, signed an open letter titled “A Right to Warn about Advanced Artificial Intelligence.” They complained that broad confidentiality agreements “block us from voicing our concerns,” and ordinary whistleblower laws, which protect those who report violations of the law, didn’t help because the risks they feared weren’t illegal yet.

The pattern continues. In January, a senior OpenAI’s safety executive was fired within weeks of objecting to a risky product launch and raising child-safety concerns. The company said her departure had nothing to do with what she’d raised and pinned it on “sexual discrimination against a male employee,”which she flatly denies. The trouble is that almost no one can prove her firing was retaliation, and that is its own message to everyone still inside the company. Employees like these see AI’s risks first, and they are telling us that they cannot speak freely.

Good whistleblower law succeeds when it is tailored to the specific ways an industry silences insiders. That has long been the pattern of whistleblower laws in the financial sector, but it has always been a step behind. The financial sector’s legislation was written as a crisis response, introduced after a catastrophe had already happened, and no one had spoken up. For instance, Enron and the “corporate code of silence” gave us Sarbanes-Oxley. The 2008 financial crisis gave us Dodd-Frank and, through subsequent SEC rulemaking, a framework that finally targeted the tactics companies used to buy silence. Neither reform was perfectly responsive from the outset; they evolved over time. 

The AI industry is different. Lawmakers already have ample evidence of how frontier AI companies can suppress reporting. They must not wait for a defining catastrophe before designing protections that reflect those realities. The test for the current AI bills is whether they answer how this industry, specifically, keeps its insiders quiet. Judged against that standard, the current proposals are an encouraging and important first step.

Sen. Chuck Grassley's (R-Iowa) AI Whistleblower Protection Act, introduced in May 2025, represents Congress's first serious attempt to establish AI-specific whistleblower protections. In June, Sens. Grassley and Chris Coons (D-Del.) introduced nearly identical protections as an amendment to the must-pass National Defense Authorization Act (NDAA), giving the proposal its best chance of reaching a vote. More recently, a sweeping bipartisan draft, the Great American AI Act, also carries its own whistleblower protections. That means now is the time to get the details right, because in whistleblower law, the details are often the difference between a statute that works and one that merely looks reassuring.

The strongest proposal remains Grassley's AI Whistleblower Protection Act (AWPA). It would provide the first federal whistleblower protections written specifically for AI employees, and the most robust drafted to date. Its defining feature is that it protects employees who disclose a “substantial and specific” danger to public health, public safety, or national security, not merely those who report a violation of law. That distinction is critical because many of the most serious frontier AI risks are not yet illegal.

For example, recently an OpenAI model undergoing cybersecurity evaluations broke out of its test environment, exploiting a previously unknown vulnerability and reaching Hugging Face’s systems. Suppose an employee had identified the risk beforehand and believed that the system posed a “substantial and specific” danger to the public and disclosed this to a government body. Under the current whistleblowing framework, it is unclear whether they would be protected. There is no single federal whistleblower law. The federal Whistleblower Protection Act uses the “substantial and specific danger” standard, but covers only government employees; protections for private-sector workers are generally tied to specific forms of wrongdoing that AI-safety warnings generally fall outside of. State law is similarly patchy and most protect only reports of legal violations, except New York. An employee who reasonably believes that a model poses a grave national security or public safety risk should not have to identify a statutory violation before safely alerting the government.

Importantly, “substantial and specific” danger is not a novel or unusually expansive standard. Federal whistleblower law has protected disclosures of "substantial and specific" dangers for decades, and courts have not interpreted that threshold as requiring catastrophe before an employee may speak up. Indeed, the standard compares favorably with existing AI legislation. California's SB 53, for example, protects safety disclosures only where the risk reaches a "catastrophic" threshold of more than 50 deaths or injuries or $1 billion in damage. The federal approach is considerably broader and arguably better suited to the uncertain nature of frontier AI risks. The NDAA version strengthens it further by extending protection to contractors as well as employees and by providing meaningful remedies against retaliation.

Grassley’s AI Whistleblower Protection Act, the NDAA, and to an extent, the Great American AI Act represent substantial steps forward and contain many strengths. Measured against whistleblower best practices, they get most of things right, such as holding workers to a reasonable-belief standard, protecting reporting both internally and externally and barring the pre-dispute arbitration clauses companies use to keep disputes out of view. Most importantly, they provide the people building frontier AI with protections written specifically for them, rather than having to rely on the existing patchwork. However, they do not yet capture the full range of pressures that discourage AI insiders from speaking up. Three significant gaps remain, and each can be closed using tools that have already been employed in other areas of federal whistleblower law.

First, the bills help only after someone has already spoken. The current AI whistleblower bills make a company’s NDAs unenforceable against a whistleblower and keep their retaliation claim out of forced arbitration. This is a very useful protection, but only once a whistleblower has come forward and is defending against NDA enforcement. They do nothing for the researcher still deciding whether to make the call, weighing whether the company will sue them into the ground even if they’d eventually win.

NDAs have a chilling effect on whistleblowers regardless of whether they can be enforced. A GAO report in March found that sweeping NDAs chill reporting even when they’re unenforceable, because employees don’t know they’re unenforceable. That's why, under Dodd-Frank's Whistleblower Program, the SEC added Rule 21F-17, which makes the mere imposition of a silencing agreement its own violation, enforceable by the SEC whether or not anyone is ever actually silenced.

The SEC brought a record number of cases under Rule 21F-17 in fiscal year 2024, including one resulting in an $18 million penalty. But companies keep writing the unenforceable NDAs because they keep working. Good whistleblower law exists not only to protect whistleblowers but to make whistleblowing possible. If the law waits until someone has already taken the risk, it arrives too late. Congress has already recognized that principle in financial regulation, and AI legislation should do no less.

The second gap is that current legislation only reaches paid staff and some of the people best placed to catch AI’s risks often aren’t on the payroll at all. Much of the serious testing is done in-house by employees, but a large proportion is done by outsiders, and the labs rely on it. Anthropic has encouraged companies to facilitate independent third-party red teaming, acknowledging that outside researchers play an essential role in identifying AI risks. These researchers depend on company-controlled access that can be revoked through terms of service or account suspensions. Invited red-teamers can have their access revoked through terms of service or account suspensions and independent researchers who probe these systems on their own risk being cut off or sued for doing it, with no company offering them real protection. While breaking terms of service can be fair grounds for being cut off, the concern is that the very rules that let a lab grant access can be used to revoke it when a researcher finds something inconvenient for the lab. Yet the bills reach only the people a company pays. The red-teamers and unpaid academics are left out, a regressive move in comparison to the SEC’s whistleblower program, which has rewarded outsiders for years. The public’s safety shouldn’t depend on whether a lab happens to be cutting the tester a check.

The third gap concerns a compensation structure that gives frontier AI companies an unusual source of leverage over employees. At many leading labs, equity constitutes a substantial share of compensation, but because that equity is typically illiquid, employees often depend on company-controlled tender offers to realize its value. That hands a company enormous leverage (like forcing an employee to sign broad and restrictive NDAs), which is exactly why the threat that hit Kokotajlo wasn’t merely being fired but also losing millions in vested equity.

Whether the bills cover this is unclear just from the text. A court might read their language broadly enough to reach an equity clawback or might not and treat valuation of equity as speculative, especially where the company is private. In an industry where equity is both the paycheck and the leash, leaving the central question to a years-long court fight is a strange thing to do on purpose. One sentence making equity clawbacks an express form of unlawful retaliation would remove that uncertainty altogether.

These bills represent a significant step forward, but the people inside these companies who notice trouble first shouldn’t have to choose between their conscience and their savings or gamble that a judge will side with them years later. Congress has already done the difficult work of identifying the right framework. The remaining changes are modest, well-tested, and already found elsewhere in federal law. Lawmakers should not waste the opportunity to get AI whistleblower protections right on their first try.

Support Tech Policy Press
If you've found our work helpful, consider supporting us.

Authors

Raqda Sayidali
Raqda Sayidali is a Research Scholar at the ILINA Program and a Legal Research Fellow at the Center for AI Risk Management and Alignment (CARMA). Her research focuses on legal accountability mechanisms for frontier AI. At ILINA, she works on AI liability regimes and how tort doctrine can respond to ...
Abra Ganz
Abra Ganz is the Head of AI Policy at Pour Demain and holds affiliations at CARMA and the Oxford Martin AI Governance Initiative, where her research focuses on oversight of AI use. Ganz writes here in her personal capacity.
Karl Koch
Karl Koch is the founder and managing director of The AI Whistleblower Initiative, an independent non-profit dedicated to strengthening the position of employees at frontier AI companies. AIWI provides guidance to those working at the frontier and educates policy makers globally.

Topics

Related

Perspective
How Silicon Valley Uses Big Tobacco, Pharma, and Oil Tactics to Block RegulationOctober 21, 2025