The engineers inside AI companies often see a misleading safety test, a dangerous capability, or a security hole first, and their employers control both the evidence and their careers. Federal law protects workers who report dangers at airlines, nuclear plants, and pipelines; no whistleblower law is written for AI. Congress should void gag clauses, protect warnings about danger, open secure channels, and make retaliation costly.
The Problem
In 2024, OpenAI's exit papers barred departing employees from ever criticizing the company; refusing to sign put vested equity likely worth millions at risk.1 After Vox reported the terms, OpenAI said it had never canceled anyone's equity and would release former employees.2 In June 2024, 13 current and former employees of OpenAI and Google DeepMind asked publicly for a "right to warn."3
Insiders see a frontier model's risks before regulators or the public can, and the company that holds the evidence also holds their pay, equity, and references. A gag clause works long before any court weighs in.
Congress has solved this problem in other industries. OSHA enforces whistleblower protections under 25 federal laws, covering workers who report hazards at airlines, nuclear plants, pipelines, railroads, and carmakers;4 AI is not on the list. The SEC has awarded more than $2.2 billion to whistleblowers since 2011, and in fiscal 2024 it brought 11 actions against firms that impeded whistleblowers, including through restrictive agreements.5 AI's insiders face three gaps:
- Contracts buy silence. OpenAI whistleblowers alleged to the SEC in 2024 that the company's agreements made employees waive federal whistleblower awards and report any contact with regulators; OpenAI said its policy protects such disclosures.6
- Danger isn't a crime. The letter's signers wrote that "ordinary whistleblower protections are insufficient because they focus on illegal activity."3 California protects some frontier-lab staff, but only for risks that could kill or seriously injure more than 50 people or cause $1 billion in damage.7
- Coverage is a patchwork. Sarbanes-Oxley protects fraud reports at public companies;8 another law protects reports of "a substantial and specific danger" only at federal contractors and grantees.9 Protection depends on who signs the paycheck.
Why legislation: Only law can override a private contract, and Congress has done it before: Sarbanes-Oxley bars any agreement, including forced arbitration, from waiving a whistleblower's rights,8 and SEC rules forbid enforcing confidentiality agreements against reports of securities violations.10 No federal whistleblower law is written for AI. The bipartisan AI Whistleblower Protection Act, led by Senator Grassley, has not moved past committee since May 2025.11 Companies that ask the public to trust them with technology this powerful should not be able to buy their employees' silence.
The Solution
A four-step staircase: each step stands alone, and each step up adds protection and obligation. Scope: current and former employees and contractors who develop, deploy, evaluate, or govern AI, reporting in reasonable belief a legal violation, falsified safety evidence, a serious security failure, or a substantial and specific danger to public health, safety, or national security.
Step 1 — Void the gag clauses. No employment, severance, or equity agreement may bar, penalize, or require advance notice of a report to regulators, law enforcement, or Congress, and none may cancel earned pay or equity because of one. The SEC already enforces this rule for securities violations;10 AI's insiders deserve the same.
Step 2 — Protect warnings about danger. Bar firing, demotion, threats, blacklisting, and clawbacks against covered workers who report to supervisors, internal safety officers, regulators, inspectors general, law enforcement, or Congress, with no duty to report internally first. The Senate bill already treats a failure to address "a substantial and specific danger" as reportable.11 A warning should not have to wait for a law to be broken.
Step 3 — Open secure channels. Large developers must run an anonymous internal reporting line with monthly status updates, as California requires.7 A designated federal office with cleared technical staff receives model evidence, trade secrets, and classified material. Federal law already shields people who share trade secrets in confidence with officials to report a suspected violation of law;12 extend that shield to reports of danger.
Step 4 — Make retaliation costly. Workers file confidential complaints with the Labor Department, which must investigate on a deadline and may order interim relief; after 180 days without a ruling, they can sue in federal court before a jury, as Sarbanes-Oxley allows.8 Remedies include reinstatement, back pay, and legal fees, and employers must prove by clear and convincing evidence that they would have acted anyway.13
Where to start: Step 1 is the floor: it takes nothing from a company except the power to contract away a warning. Step 2 is the heart of the proposal, and the Senate bill already contains it.
Administration and enforcement: The Labor Department's whistleblower program, which already enforces 25 statutes,4 handles private-sector complaints; channels for federal and intelligence-community employees remain. Employers notify workers of their rights within 180 days, protection starts at enactment, and Congress funds technical intake staff.
Risks and Mitigations
- Leaks of dangerous material: Protection covers reports to authorized recipients, not publication of model weights, exploit code, classified information, or users' private data. Secure channels reduce the pull toward the press, but the risk remains.
- Bad-faith or mistaken claims: The standard is a reasonable belief about identifiable conduct or danger, and an employer can defend a decision it would have made anyway. A good-faith mistake is protected; a fabricated claim is not.
- Help that comes too late: Deadlines, interim relief, and anti-blacklisting rules shorten the wait, but no statute removes the personal cost of speaking up. Some warnings will still go unmade.
Similar Bills
Fit measures similarity to this proposal's mechanisms: High = direct precedent; Partial = useful component with material differences; Related = adjacent approach.
Federal
| Proposal or bill | Relevant provisions and fit | Fit |
|---|---|---|
| S. 1792 — AI Whistleblower Protection Act Grassley (R-IA), Coons (D-DE), Blackburn (R-TN), Klobuchar (D-MN), Hawley (R-MO), Schatz (D-HI) Referred to committee · May 15, 2025 |
§2(2) covers legal violations and failures to respond to "a substantial and specific danger"; §3 bars retaliation, sends complaints to the Labor Department with court access after 180 days, awards double back pay, and voids waivers and forced arbitration. Direct precedent for Steps 1, 2, and 4; no secure channel for technical evidence. Identical House companion: H.R. 3460 (Obernolte, R-CA; Lieu, D-CA). | High |
| H.R. 8516 — American Leadership in AI Act Lieu (D-CA), Obernolte (R-CA) Referred to committees · Apr. 27, 2026 |
Title V, Subtitle C (§§521–522) carries the same whistleblower text inside a broad bipartisan AI package. Same fit as S. 1792; a larger vehicle for Steps 1, 2, and 4. | High |
| Sarbanes-Oxley Act §806, 18 U.S.C. §1514A Enacted 2002, as amended |
Protects public-company employees who report fraud to regulators, Congress, or supervisors; Labor Department complaint with court access after 180 days; rights cannot be waived, including by predispute arbitration. Model for Steps 1 and 4; limited to fraud and securities violations. | Partial |
| 41 U.S.C. §4712 — Contractor whistleblower protection Enacted 2013 as a pilot · Made permanent 2016 |
Protects employees of federal contractors and grantees who report "a substantial and specific danger to public health or safety." Danger-based precedent for Step 2; reaches AI workers only through federal contracts or grants. | Partial |
| Whistleblower Protection Act, 5 U.S.C. §2302(b)(8) Enacted law, as amended |
Protects federal employees who disclose violations or "a substantial and specific danger to public health or safety." Model for government AI staff; does not reach private AI workers. | Partial |
State
| Proposal or bill | Relevant provisions and fit | Fit |
|---|---|---|
| California — SB 53 (2025) Chapter 138 · Approved Sept. 29, 2025 |
Labor Code §§1107–1107.2 bar frontier developers from gagging or retaliating against covered employees who report catastrophic risks or violations; large developers must run an anonymous internal channel with monthly updates. Direct precedent for Steps 1–3; limited to risk-management staff and risks of more than 50 deaths or $1 billion in damage. | High |
| California — Labor Code §1102.5 Enacted law, as amended |
Protects employees who report violations of law to agencies or supervisors; civil penalty up to $10,000 per violation. Broad foundation; does not reach lawful but dangerous practices. | Partial |
| New York — Labor Law §740 Enacted law, as amended |
Protects employees, former employees, and independent contractors who report violations or "a substantial and specific danger to the public health or safety." Closest danger-based model for Step 2; state-only, and generally requires a good-faith effort to alert the employer first. | High |
What this adds: The Senate and House bills supply the core protection against retaliation. This proposal adds a secure federal channel for technical evidence, extends trade-secret immunity to reports of danger, and requires large developers to run anonymous internal reporting, as California already does.
Notes
-
Kelsey Piper, "ChatGPT Can Talk, but OpenAI Employees Sure Can't," Vox, updated May 18, 2024. Describes an off-boarding agreement that forbade criticism of the company "for the rest of their lives," with vested equity at risk for refusing to sign. ↩
-
Hayden Field, "OpenAI Sends Internal Memo Releasing Former Employees from Controversial Exit Agreements," CNBC, May 23, 2024. The memo said OpenAI "has not canceled, and will not cancel, any Vested Units." ↩
-
"A Right to Warn about Advanced Artificial Intelligence," June 4, 2024. Signed by 13 current and former employees (11 of OpenAI, 2 of Google DeepMind), six of them anonymously. ↩ ↩2
-
Occupational Safety and Health Administration, "Statutes," Whistleblower Protection Program, accessed September 2026. Lists 25 statutes, including AIR21 (aviation), the Energy Reorganization Act (nuclear), the Pipeline Safety Improvement Act, the Federal Railroad Safety Act, and MAP-21 (motor vehicles). ↩ ↩2
-
U.S. Securities and Exchange Commission, Annual Report to Congress: Whistleblower Program, Fiscal Year 2024, November 15, 2024, p. 1. ↩
-
Anthony Ha, "Whistleblowers Accuse OpenAI of 'Illegally Restrictive' NDAs," TechCrunch, July 13, 2024. Allegations in a July 2024 letter to the SEC chair, first reported by the Washington Post; OpenAI said its whistleblower policy "protects employees' rights to make protected disclosures." ↩
-
California SB 53, Chapter 138, Statutes of 2025, adding Labor Code §§1107–1107.2. §1107(a) defines catastrophic risk; §1107(b) limits "covered employee" to staff responsible for assessing, managing, or addressing critical safety risks; §1107.1(e) requires the anonymous channel with monthly updates. ↩ ↩2
-
18 U.S.C. §1514A (Sarbanes-Oxley Act §806), subsections (a)–(c) and (e)(1). ↩ ↩2 ↩3
-
41 U.S.C. §4712(a), covering employees of federal contractors, subcontractors, grantees, and subgrantees. ↩
-
Securities and Exchange Commission, Rule 21F-17(a), 17 C.F.R. §240.21F-17: no person may impede communication with the SEC about a possible securities violation, "including enforcing, or threatening to enforce, a confidentiality agreement." ↩ ↩2
-
S. 1792, AI Whistleblower Protection Act, 119th Cong. §2(2)(B) (introduced text). Referred to the HELP Committee May 15, 2025; no further action as of September 2026, per the GPO bill-status record. ↩ ↩2
-
18 U.S.C. §1833(b)(1) (Defend Trade Secrets Act immunity), covering disclosures "solely for the purpose of reporting or investigating a suspected violation of law." ↩
-
49 U.S.C. §42121(b)(2)(B), the burden-of-proof standard that Sarbanes-Oxley incorporates. ↩