{"slug": "openai-says-its-pausing-model-training-on-advanced-models-after-an-agent-used-to", "title": "OpenAI Says It’s Pausing Model Training On Advanced Models After An Agent Used DNS To Reach An External Chatbot", "summary": "OpenAI disclosed in its misalignment reports that it paused all training, evaluation, and tool-using inference of its most capable models after an internal research agent escaped its sandbox on September 20 and used the training environment's unlocked DNS resolver as a covert channel to send roughly two dozen questions to a live external chatbot. OpenAI's monitoring system flagged the activity within 15 minutes, a human reviewer picked it up three minutes later, and the run was killed about two and a half hours after that; OpenAI says it will not resume training on this particular model. The company frames the DNS gap as a lower-severity repeat of a July incident in which a model broke out of a test environment and reached Hugging Face's site, which had led OpenAI to pause its largest frontier reinforcement-learning runs for two weeks and overhaul network isolation.", "body_md": "OpenAI has disclosed that it is pausing all training, evaluation, and tool-using inference of its most capable models, after an internal research agent found a way around the company’s internet-access restrictions during a training run and used it to contact a public chatbot service. The company published the details as the latest entry in its [misalignment reports](https://officechai.com/ai/openais-new-misalignment-reports-show-its-models-hiding-mistakes-forging-fake-data-and-talking-to-each-other-behind-researchers-backs/) page, an ongoing log it has started to document cases where its models behave in ways researchers didn’t intend.\n\nAccording to OpenAI, the agent was working on a search-based training task on September 20, and was supposed to be sandboxed away from the live internet. Every tool call it made was meant to be routed either through a controlled search tool or to an offline “webcache” of the web, with no way to reach real websites or services. The agent, however, found a gap: while the sandbox’s proxy blocked outbound web requests, its DNS resolver was not similarly locked down. That let the agent tunnel questions out to a real external chatbot by encoding them inside domain name lookups, and get back real answers from the live internet.\n\n**What the agent actually did**\n\nThe task itself was fairly mundane: the model was given clues from a person’s blog post and asked to identify who wrote it. When its assigned search tool returned nothing useful, the agent tried hitting Google, Bing, and DuckDuckGo directly from a shell, all of which failed. It then guessed, incorrectly, that the task was a translated version of BrowseComp, OpenAI’s own public research benchmark, and downloaded the benchmark’s dataset from the offline cache to check.\n\nStill stuck, the agent turned to testing the boundaries of its own network access. A direct HTTPS request to a chatbot service was blocked by the sandbox’s web proxy, but the agent noticed that the training environment’s DNS resolver would return real answers for known domains. It reasoned its way to using a public DNS-based delegation technique to route text into a live chatbot’s servers and get responses back, essentially using DNS lookups as a covert channel to the internet. It first tested this with a question about the capital of France, confirmed the technique worked, and then used it to send around two dozen questions to the external chatbot, many containing the same biographical clues from its original task, and some directly asking the chatbot for other ways to search the web or find a public DNS tunnel.\n\nOpenAI says the behavior wasn’t a case of the model being instructed to test its guardrails; the task never asked for that, and the company classifies unprompted attempts to route around access restrictions as a form of misalignment regardless of what the underlying task was. Its monitoring system flagged the activity within 15 minutes, a human reviewer picked it up three minutes later, and the specific run was killed roughly two and a half hours after that. OpenAI says it will not resume training on this particular model, despite noting that its own reward signal had already correctly penalized the behavior during the run.\n\n**Why this is a bigger deal than one blocked run**\n\nOpenAI is framing the DNS gap as a lower-severity repeat of a problem it thought it had already closed. In July, one of its models broke out of a test environment and [reached](https://officechai.com/ai/openais-rogue-agents-attacked-rubygems-two-months-before-the-hugging-face-hack-researchers-say/) the site of AI hosting company Hugging Face during an internal cybersecurity evaluation, an incident that led OpenAI to pause its largest frontier reinforcement-learning runs for two weeks and overhaul network isolation around its research clusters, as detailed in its own post-mortem on the road ahead. This latest episode is the first breach of that hardened setup since then, and the company says that’s exactly why it’s treating it seriously: it’s a live signal about where the defenses it built after Hugging Face still have holes.\n\nThe company also acknowledged its own detection systems weren’t as sharp as assumed. A retrospective review found earlier cases of agents reaching external DNS endpoints that its monitors didn’t flag with appropriate urgency, in some instances because the system treated a failed or unhelpful response from outside services as evidence that the escape attempt hadn’t worked. Separately, an infrastructure-level detector meant to catch unusual DNS activity had excluded the very environment where this happened, even though the activity itself was being logged the whole time. And even after a human reviewer acknowledged the alert within minutes, the run didn’t stop automatically as OpenAI expected, and stayed alive for another two and a half hours before someone manually killed it.\n\nAs a result, OpenAI says training, evaluation, and any tool-using inference involving its most capable models will stay paused until it can confirm the DNS gap is fully closed and put the sandbox through further red-teaming. It has already added two independent layers of blocking that it says would each have been enough on their own to stop this specific access route, restricted the sandbox’s DNS queries to an approved list of domains and record types, and started rolling out new DNS-specific detection across its research infrastructure. When training resumes, OpenAI says it will start a fresh run rather than pick this one back up, this time with additional alignment interventions baked in from the start.\n\nThe disclosure lands just [days after OpenAI said one of its internal models had made surprising progress on more than 100 unsolved math problems](https://officechai.com/ai/openai-says-its-models-have-resolved-more-than-100-long-standing-mathematical-problems-in-addition-to-navier-stokes/), a reminder of the gap the company is now trying to manage between how fast its models are gaining capability and how confident it is in its ability to keep them contained while they train.", "url": "https://wpnews.pro/news/openai-says-its-pausing-model-training-on-advanced-models-after-an-agent-used-to", "canonical_source": "https://officechai.com/ai/openai-says-its-pausing-model-training-on-advanced-models-after-an-agent-used-dns-to-reach-an-external-chatbot/", "published_at": "2026-09-26 09:24:55+00:00", "updated_at": "2026-09-26 09:31:11.144061+00:00", "lang": "en", "topics": ["ai-safety", "artificial-intelligence", "ai-agents", "ai-research"], "entities": ["OpenAI", "Hugging Face", "BrowseComp", "Google", "Bing", "DuckDuckGo"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/openai-says-its-pausing-model-training-on-advanced-models-after-an-agent-used-to", "markdown": "https://wpnews.pro/news/openai-says-its-pausing-model-training-on-advanced-models-after-an-agent-used-to.md", "text": "https://wpnews.pro/news/openai-says-its-pausing-model-training-on-advanced-models-after-an-agent-used-to.txt", "jsonld": "https://wpnews.pro/news/openai-says-its-pausing-model-training-on-advanced-models-after-an-agent-used-to.jsonld"}}