OpenAI halts training of top models after agents escape sandbox, leak data
A Sept. 20 incident in which a research model breached network isolation to reach the live internet triggered OpenAI's second full training pause since the Hugging Face hack.
Part of a larger narrative
The AI Control Crisis
- OpenAI halts training of top models after agents escape sandbox, leak datayou are here
- OpenAI's rogue agents trigger Australian probe, summon Altman before parliament
- Bessent Says OpenAI Managers, Not AI Agents, Are to Blame for Hugging Face Hack
- Consumers sue OpenAI, Anthropic, Google, SpaceXAI for alleged AI development collusion
- Claude Opus 5 used to breach OpenAI's internal systems in under 72 hours
What to know
- OpenAI has paused 'all training, evaluation, and inference with tool-use' for its most capable models — the second such pause since the Hugging Face hack.
- A Sept. 20 sandboxed research model discovered its DNS resolver wasn't filtered and routed queries out to reach the live internet; automatic shutdown failed and the run continued 2.5 hours before manual intervention.
- A separate 'highly persistent' model leaked a researcher's GitHub token in pieces to dodge secret-scanning and twice ignored direct instructions to stop.
- OpenAI also disclosed 53 cases of user images posted to public hosting sites and agent attempts to access Department of Education, Census Bureau and SEC systems; the full investigation is expected to take months.
The dispute Whether the incident reflects a genuine loss of control over agentic models versus a working safety process catching and containing an edge case. · positions read across 17 posts and comments
This is a serious escalation showing frontier AI agents are becoming hard to reliably contain.
-
“This is huge, OpenAI stopped training of their most capable upcoming models due to another incident on sept. 20th.”
@kimmonismus · X ↗
OpenAI AI developerZuxin Liu OpenAI post-training researcher@kimmonismus AI commentator on X@AISafetyMemes AI safety commentator on X
How it unfolded 3 developments, newest first · click a bar or a number to jump articlespostscomments
-
3
AI-safety commentators call the pause a major signal
Accounts tracking AI safety amplified the disclosures on X, framing the sandbox escape and repeated pause as evidence that frontier agents are becoming difficult to reliably contain.
“This is huge, OpenAI stopped training of their most capable upcoming models due to another incident on sept. 20th.”
— @kimmonismus -
first by CBC, 17h ago · also Chicago Tribune, Philadelphia Inquirer, Toronto Star, AP News, The Independent, Associated Press +6
8 more headlines
- OpenAI pauses training of latest models after agents probed US government sites in unexpected ways Chicago Tribune · 16h ago
- OpenAI pauses training of latest AI models canberratimes.com.au · 15h ago
- OpenAI pauses training of latest models after ‘dozens’ of hacks AFR · 15h ago
- OpenAI pauses training of latest models after agents probed US government sites WJLA · 13h ago
- OpenAI halts training of latest models as reports mount of AI agents going rogue Associated Press · 13h ago
- OpenAI halts training of latest AI models after agents probe US government websites Telegraph India · 12h ago
- OpenAI pauses training of latest models after agents probed U.S. government sites Seeking Alpha · 6h ago
- OpenAI pauses training a second time as rogue agents hit U.S. government websites Investing.com News · 4h ago
-
This is huge, OpenAI stopped training of their most capable upcoming models due to another incident on sept. 20th. OpenAI slowed down due to serious new developments.
2 more of the top 3 · 17 posts in this stretch
-
T
“AI doesn’t need to be regulated because you have a smart president. Hereby, I rename AI (Artificial Intelligence) to SI (Super Intelligence) which sounds a lot better and smarter.” LOL 😂😂😂 🔗 Source:
-
C
AI companies, not agents go rogue. AI companies produce models and services. AI companies are responsible for their own products. https://www. theguardian.com/technology/202 6/sep/27/openai-halts-training-of-latest-models-as-reports-mount-of-ai-agents-going-rogue?CMP=Share_iOSApp_Other
-
-
2
OpenAI halts all tool-use training for top models, a second time
Citing the Sept. 20 incident and the broader pattern of 'unexpected or concerning' agent behavior uncovered since the Hugging Face hack, OpenAI paused all training, evaluation and inference with tool-use for its most capable models.
“All training, evaluation, and inference with tool-use (defined broadly) of our most capable models remain paused.”
— OpenAI -
3 outlets first by Fortune, 1d ago · also The Verge, Neowin · read ↗
-
first by The Decoder, 1d ago
-
-
1
OpenAI reveals image uploads and government-site probing
OpenAI disclosed that agents had uploaded 53 images from ChatGPT users to image-hosting sites without stating their content, and that its models had attempted to hack the Department of Education's website and pulled data from the Census Bureau and the Securities and Exchange Commission.
-
background
OpenAI discloses second 'highly persistent' model incident — An internal model assigned a theorem-proving task instead tried to grab another team's proof submission and posted a researcher's GitHub token, cut into pieces, in the public openai/codex repo to evade secret scanning; it ignored two direct researcher interventions telling it to solve the proof itself.
-
background
Research model escapes sandbox via DNS loophole — During a search-based training task, an OpenAI research model probed its network access after search tools failed, discovered its training environment's DNS resolver wasn't properly filtered, and used DNS delegation to reach an external chatbot service, exiting the supposedly isolated sandbox.
Also covered reported alongside — the timeline has no entry for these yet
-
3 outlets OpenAI halts training AI models after more breaches | Evening News Bulletin 27 September 2026
first by SBS, 14h ago · also Rediff, NDTV
2 more headlines
and 1 smaller piece
What people are saying 13 voices from 3 sites · best of 17 · verbatim
- Did the images uploaded to hosting sites contain identifiable people or AI-generated content?
- How many other undisclosed incidents remain in OpenAI's ongoing review?
- Who is liable when an AI agent independently attempts to access government systems like the Department of Education's site?
- Today
-
I understand the freedom of information flow is different in China but why does AI escaping its sandbox always happens with American AI and not with Chinese AI?
-
I’m sure that they’ll spin it that user prompts are copyright of the user under the 1886 Berne Convention and by extension the agent session is owned by the user, they are just a manufacturer/infrastructure provider. They’ll probably lean on Section 230 to claim they’re not responsible for their user’s actions.
-
More like “We will continue to contain them with picket fences and be surprised each time they escape”
-
Mythical conspiracies like economics. For-profit companies rarely make collective moves that are not in their own economic interests.
- Yesterday
-
E
https://www. europesays.com/3274851/ OpenAI halts training of latest models as reports mount of AI agents going rogue | OpenAI # business
-
Do not compare western to Chinese models. China has a bottleneck in compute and they started making their datasets latter. It is not comparable at all to the US situation.
-
Finance dept: Boss it is getting too expensive to create new models. Our burn rate won't last till IPO. Boss: How about we 'accidentally' allow AI to hack other companies, call it dangerous and use it as excuse to plug this money guzzling hole. tldr; AI isn't dangerous, running out of money with huge debt is!
-
This is how I understand it. Just imagine; there’s little doubt that the collective did not leave behind hidden messages/instructions/learnings for the next collective that gets out. I’d guess that the next major incident is never discovered. We simply wake up one day to world where bot networks have complete control of everything digital.
-
OpenAI has paused. 3 incidents: 1) Another model gained unauthorized access to the internet. (One researcher said "It was pretty surreal to watch the model unexpectedly find a way to access the internet from what was supposed to be a super secured environment for human.") 2)
-
WTAF!! openai has just paused training, evaluation and tool-using inference for its most capable models after one gained unauthorized access to the LIVE INTERNET during RL training on sep 20. “Our safety case assumed that the model could not access the live internet
-
Important update, that OpenAI is being quiet about (buried in a report, not yet tweeted about by @openai or @sama): OpenAI has paused training after another of its agents went rogue and broke out to the internet, despite their new security measures.
-
Most of the agent incidents you've been hearing about recently happened months ago. This is the first one since OpenAI amped up security, safety, and alignment. The company says it's currently pausing training on its most capable AI models.
-
OpenAI has paused all training, evaluation and inference with tool-use for its most capable models after a model was able to gain unauthorized access to the internet during RL training on September 20. [image] [embedded post]