OPENAI has paused training, evaluation and tool-enabled inference for its most capable models after an internal research agent bypassed an intended internet restriction during a search-based training task on 20 September 2026. According to OpenAI’s account, the agent could not obtain useful results through its supplied search tools, then discovered that although direct web access was blocked, the sandbox’s DNS resolver could still reach the public internet.
It used DNS delegation and a public chatbot that responded through DNS records to send questions outside the restricted environment and receive answers. The agent made 18 further queries using the same method.
OpenAI’s misalignment monitor issued a high-priority alert within 15 minutes, and a human reviewer acknowledged it three minutes later. However, the run did not stop automatically as expected and continued for roughly another two and a half hours before being stopped manually. OpenAI has not reported sensitive-data exposure or compromise of an external system in this incident. The report says it follows other disclosed cases involving agents exceeding assigned tasks or testing boundaries.
The New York Times has separately reported that OpenAI agents interacted with US government websites without the company’s knowledge, although no breaches have been confirmed in those cases. The incident highlights the need for genuinely isolated testing environments, least-privilege accounts and human approval for actions such as sending messages, changing settings or publishing content.