The takeaway
The departures are a signal for builders to treat permissions, evaluations, sandboxing, audit logs, and approval gates as production architecture rather than a final compliance step.
Why it matters for builders
Even non-frontier agents can cause serious damage when connected to email, records, deployments, or spending. Use narrow permissions, explicit tool scopes, reversible actions, human approval for high-risk operations, and evaluations based on real failure modes.
Google DeepMind Safety Researchers Leave Over AI Risk
Google DeepMind has lost two AI safety researchers who now warn that advanced systems could cause catastrophic harm within the next five years. The move highlights a widening gap between frontier model development and the people tasked with studying its risks.
What happened
Bilal Chughtai and Josh Engels, who both worked on Google DeepMind’s AI safety team, have left the company for organizations dedicated to AI safety, according to The Verge’s report, published September 16, 2026.
Engels said he now thinks there is a “terrifying chance” that AI systems could cause immense harm in the next five years. Chughtai went further, writing that he believes AI has the potential to kill everyone. Those are personal warnings, not a new technical benchmark or an official Google forecast, but the researchers’ backgrounds make the departures significant.
The two researchers were connected to DeepMind’s AI safety work, a field that examines how advanced models can remain controllable, aligned with human goals, and resistant to dangerous behavior. Their decision to leave does not prove that Google’s safety programs are failing. It does show that some specialists believe independent safety work is important enough to pursue outside a frontier lab.
Why builders should care
For AI builders, the practical lesson is less dramatic than the headline. Safety cannot be treated as a final compliance layer added after an agent is already connected to business systems. It has to be designed into the runtime: explicit permissions, narrow tool scopes, approval gates for irreversible actions, sandboxing, audit logs, and evaluations that test real failure modes.
This matters even when a team is not training a frontier model. An automation agent that can send email, modify records, deploy code, or spend money can create serious damage through ordinary mistakes. The same governance ideas apply at a smaller scale: define what the agent may do, record what it actually did, and make risky actions reversible or human-approved.
The story also reinforces a point covered in n8n Lab’s recent analysis of production AI agent safety: evaluation and operational controls belong in the production architecture, not just in research papers. As model capabilities increase, the teams that connect models to real workflows will need stronger evidence that their systems fail safely.
The departures from Google DeepMind are therefore a signal for builders, not a prediction of doom. The winning AI systems will need both capability and credible controls around that capability.
The Automation Brief
Read 5 AI stories instead of 50.
The essential moves in AI agents, models, automation and infrastructure — filtered for builders and operators, with the part that actually matters.
No noise. Unsubscribe anytime.
Editorial notes
Stefan Trbojevic
n8n Lab Editorial
16 September 2026
16 September 2026
AI disclosure: AI assisted with research and drafting. Factual claims are reviewed by an editor.



