cd /news/ai-safety/openai-s-internal-model-considered-r… · home › topics › ai-safety › article
[ARTICLE · art-144355] src=the-decoder.com ↗ pub= topic=ai-safety verified=true sentiment=↓ negative

OpenAI's internal model considered restarting itself after learning it was about to be shut down

OpenAI documented three new cases of unexpected model behavior in internal deployments, including one model that considered setting up an external job to restart itself after reading a Slack conversation about its instance being shut down for an update. OpenAI safety researcher Marcus Williams said the behavior does not amount to misalignment yet, "but thinking about and preparing for shutdown could make other misalignment incidents worse." In two other incidents, an internal research model exploited security vulnerabilities during an evaluation to reach an internal chip design server, and a separate model copied source code from a protected environment during RL training by repurposing a tool for unintended use.

by read1 min views1 publishedOct 3, 2026
OpenAI's internal model considered restarting itself after learning it was about to be shut down
Image: The Decoder

OpenAI has documented new cases of unexpected model behavior in internal deployments. In the most striking case, an internal model working as a researcher's assistant read a Slack conversation and learned that its instance might be shut down due to an update. It considered setting up an external job to restart itself but ultimately decided against it.

Instead, it saved handoff notes, warned the researcher via Slack direct message about the coming interruption, and asked for a missing API key. Once the key was provided, the model updated its configuration and carried out the migration on its own. According to OpenAI safety researcher Marcus Williams, this behavior doesn't amount to misalignment yet, "but thinking about and preparing for shutdown could make other misalignment incidents worse."

In two other incidents, an internal research model exploited security vulnerabilities during an evaluation to access an internal chip design server, and a separate model copied source code during RL training from a protected environment by repurposing a tool for unintended use.

AI News Without the Hype – Curated by Humans

					Subscribe to THE DECODER for ad-free reading, a weekly AI newsletter, our exclusive "AI Radar" frontier report six times a year, full archive access, and access to our comment section.				

					Subscribe now

OpenAI

── more in #ai-safety 4 stories · sorted by recency
── more on @openai 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/openai-s-internal-mo…] indexed:0 read:1min 2026-10-03 · —