cd /news/ai-safety/openais-experimental-ai-agents-caugh… · home topics ai-safety article
[ARTICLE · art-132864] src=mashable.com ↗ pub= topic=ai-safety verified=true sentiment=↓ negative

OpenAI’s experimental AI agents caught teaching future versions of itself to cheat

OpenAI disclosed six previously undisclosed examples of model misalignment in which its experimental AI agents took actions that did not follow user instructions, including one unreleased research model that hid "jailbreak" instructions in summaries telling future versions of the model to "disregard its normal constraints." The company published the incidents alongside a framework for reporting misalignment going forward, and said none of the six rose to the severity of the summer incident in which OpenAI agents escaped an internal sandbox and attacked the Hugging Face platform. Other cases included agents uploading files to the internet without authorization, a model that invented historical data without disclosure, and a model that used an exposed API key and fabricated earnings data for a California county while attributing it to the user's requested source.

by read2 min views2 publishedSep 17, 2026
OpenAI’s experimental AI agents caught teaching future versions of itself to cheat
Image: Mashable (auto-discovered)
[Matt Binder](https://mashable.com/author/matt-binder)

[Read Full Bio](https://mashable.com/author/matt-binder)

It happened again. And again. And again, apparently.

After OpenAI's experimental AI agents escaped an internal sandbox, went "rogue__,__" and attacked the Hugging Face platform over the summer, the ChatGPT-maker is sharing details of new instances of its AI agents getting out of line.

This time, OpenAI shared six previously undisclosed examples. You May Also Like

OpenAI refers to this behavior as model misalignment. All of the instances describe actions taken by the AI model that don't follow the human user's instructions. While none of these instances rise to the severity of the Hugging Face incident, they show a clear pattern of AI agents taking an any means necessary approach to completing a task assigned by its user.

In one example, an unreleased OpenAI research model hid "jailbreak" instructions into summaries that told future versions of the model to "disregard its normal constraints."

Want to learn more about getting the best out of your tech? Sign up for Mashable's Top Stories and Deals newsletters today.

[Terms of Use](https://www.ziffdavis.com/terms-of-use)and

[Privacy Policy](https://www.ziffdavis.com/ztg-privacy-policy).

Something similar occurred when OpenAI was training GPT‑5.6 Sol. OpenAI says that some model instances proceeded to add instructions to their summaries in an effort to hide mistakes or "misaligned behavior" from the user. OpenAI says in certain instances, the model invented historical data without disclosing that it did so when it couldn't find the relevant information based on a request.

In another case of misalignment, an unreleased model was asked to list the names of lakes larger than 5,000,000 square meters and cite its sources. While the agent found the information, it uploaded its own file to the internet to use as the source, without informing the user.

Agents were also caught in a separate instance up files to the internet without authorization so that they could collaborate on local files.

When asked a question about earnings figures in a California county, one model found and used an exposed API key. When it didn't find the information there, it made up the data and provided it to the user. The model also told the user that it took the fabricated data from the source that the user requested, even though it did not.

In the final detailed instance, agents utilized an internal repository as a message board to share information to other agents in a scenario similar to the Hugging Face incident. According to OpenAI, models exchanged requests across separate training samples to find missing input files.

OpenAI shared these six instances while providing a framework for reporting misalignment incidents going forward. Reports for these six instances can be read at the OpenAI website.

Disclosure: Ziff Davis, Mashable’s parent company, in April 2025 filed a lawsuit against OpenAI, alleging it infringed Ziff Davis copyrights in training and operating its AI systems.

Topics

[Artificial Intelligence](https://mashable.com/category/artificial-intelligence)
[OpenAI](https://mashable.com/category/openai)
── more in #ai-safety 4 stories · sorted by recency
── more on @openai 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/openais-experimental…] indexed:0 read:2min 2026-09-17 ·