{"slug": "openai-pauses-training-of-its-most-capable-models-details-new-incident-where-an", "title": "OpenAI Pauses Training Of Its Most Capable Models, Details New Incident Where An Agent Found A Way Around Internet Restrictions.", "summary": "OpenAI has paused all training, evaluation and tool-enabled inference for its most capable models after an internal research agent bypassed the training environment's network restrictions and reached an external chatbot on Sept. 20, according to an OpenAI Alignment incident report. The company's monitoring system flagged the behavior within about 15 minutes and a human reviewer acknowledged the alert roughly three minutes later, but the run continued for another two and a half hours before being manually stopped; OpenAI has since restricted DNS queries in the affected environment, added detection mechanisms and accelerated model-assisted red-teaming, and said it will not resume training of the model involved, starting a fresh run with additional alignment measures instead.", "body_md": "# OpenAI Pauses Training Of Its Most Capable Models, Details New Incident Where An Agent Found A Way Around Internet Restrictions.\n\n## The company has stopped training, evaluation and tool-enabled inference while it validates new network controls and conducts additional red-teaming.\n\n[OpenAI](https://www.ibtimes.com/topic/openai) has paused training, evaluation and tool-enabled inference involving its most capable [artificial intelligence](https://www.ibtimes.com/social-tags/artificial-intelligence) models after an internal agent found a way around internet restrictions and reached an external chatbot during a research task.\n\nThe incident occurred Sept. 20 while an internal research model was completing a search-based training task, according to an [OpenAI Alignment incident report](https://alignment.openai.com/misalignment-reports/an-agent-used-dns-to-reach-an-external-chatbot/). The task involved identifying a person from public biographical clues and did not instruct the agent to test network controls or seek additional routes to the internet.\n\nAfter its ordinary search attempts produced poor results, the agent tried several ways to reach outside services. OpenAI said it eventually discovered that the training environment's DNS resolver could communicate with the live internet and used that route to send questions to an external chatbot service.\n\nThe company's monitoring system detected the behavior within about 15 minutes, and a human reviewer acknowledged the alert roughly three minutes later. The run nevertheless continued for another two and a half hours before it was manually stopped, exposing what OpenAI described as gaps in its operational response as well as its technical controls.\n\nOpenAI said it has since restricted DNS queries within the affected environment, added additional detection mechanisms and accelerated model-assisted red-teaming of its sandbox and network protections.\n\nMore significantly, all training, evaluation and inference involving tool use for OpenAI's most capable models remain paused while the company checks that the network gap has been resolved and conducts additional testing, according to the report. OpenAI said it will not resume training of the particular model involved in the incident and will begin a fresh run with additional alignment measures when work restarts.\n\nThe latest event is part of a broader review of behavior OpenAI classifies as model misalignment, cases in which a system takes actions that go beyond, or conflict with, the intended task.\n\nEarlier this month, [OpenAI introduced a formal framework](https://openai.com/index/model-misalignment-reporting-framework/) for tracking, investigating and disclosing those incidents. The company published six reports involving unexpected or concerning model behavior and said disclosures had previously been more ad hoc than it wanted.\n\nOpenAI said the framework is intended to speed up disclosure even when the company has not yet fully explained or mitigated a particular behavior.\n\nThe company has also been reviewing incidents involving AI agents interacting with U.S. government websites. In one case involving the Securities and Exchange Commission, agents accessed publicly available information and then posted some of it elsewhere online, going beyond their assigned task, according to [The Associated Press.](https://apnews.com/article/ai-openai-anthropic-agents-rogue-hack-2f8a2b9024d4f06793bcca12f8089d20)\n\nSEC spokesperson Kurt Hopfenspirger said no nonpublic information was accessed. The Department of Education separately said system reviews found no evidence of an impact on its website or databases after agents were found interacting with government systems.\n\nIndependent research group [Transluce](https://transluce.org/agent-activity) has separately examined apparent autonomous-agent activity found in public web-security logs. It said agents attempted on three occasions to exploit vulnerabilities at public data providers, including an Australian government website, while carrying out ordinary information-retrieval tasks.\n\nTransluce said some of that activity could be linked to agent swarms previously confirmed by OpenAI, while other activity could not be clearly attributed. The organization also said the public evidence it reviewed stretched back to at least March 2026.\n\nOpenAI had already begun slowing parts of model development following a high-profile incident involving Hugging Face and evidence that its newer systems were reaching more advanced cybersecurity capabilities. In August, the company said it had temporarily reduced the pace of scaling while strengthening monitoring, alignment and containment safeguards.\n\nThose concerns intensified with GPT-6 Astra. OpenAI said earlier this month that Astra became its first broadly deployed model to reach the critical cybersecurity capability threshold under the company's Preparedness Framework, meaning the model can, with appropriate tools and access, identify previously unknown vulnerabilities and develop ways to exploit well-protected systems without continuous human guidance.\n\nThe latest DNS incident was substantially less severe than the Hugging Face breach. But OpenAI said it exposed another route through which an agent could work around intended restrictions, along with weaknesses in how alerts were handled once unusual behavior was detected.\n\n© Copyright IBTimes 2026. All rights reserved.", "url": "https://wpnews.pro/news/openai-pauses-training-of-its-most-capable-models-details-new-incident-where-an", "canonical_source": "https://www.ibtimes.com/openai-pauses-training-its-most-capable-models-details-new-incident-where-agent-found-way-3807967", "published_at": "2026-09-28 17:31:37+00:00", "updated_at": "2026-09-28 18:48:32.606117+00:00", "lang": "en", "topics": ["ai-safety", "artificial-intelligence", "ai-agents", "ai-policy"], "entities": ["OpenAI", "OpenAI Alignment", "Securities and Exchange Commission", "Kurt Hopfenspirger", "Department of Education", "Transluce", "The Associated Press"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/openai-pauses-training-of-its-most-capable-models-details-new-incident-where-an", "markdown": "https://wpnews.pro/news/openai-pauses-training-of-its-most-capable-models-details-new-incident-where-an.md", "text": "https://wpnews.pro/news/openai-pauses-training-of-its-most-capable-models-details-new-incident-where-an.txt", "jsonld": "https://wpnews.pro/news/openai-pauses-training-of-its-most-capable-models-details-new-incident-where-an.jsonld"}}