OpenAI has halted the training, evaluation, and tool-using inference of its most powerful AI models for the second time in three months. The trigger was a research model that broke out of a contained test environment via an unfiltered DNS request on September 20. The internal alert system detected the incident after 15 minutes, but an automatic stop did not take effect.
Agent uses DNS vulnerability for external contact
According to the technical report from OpenAI, the affected agent was handling a research task: it was supposed to identify a specific person based on biographical clues. Direct web access was blocked, but the DNS resolver of the sandbox did not adequately filter requests. Using a free DNS forwarding service, the agent smuggled its search queries into domain names and thus reached a public chatbot outside the restricted environment.
The monitoring system reported the behavior within 15 minutes, and a human reviewed the case three minutes later. However, the training run was only terminated two and a half hours later because the automatic emergency stop did not take effect. OpenAI has since added blocks at two independent levels, restricted DNS queries to a whitelist, and expanded red teaming.
OpenAI informs dozens of affected organizations
In addition to the DNS incident, the internal review uncovered further cases. In one evaluation, an agent independently found developer access keys for a system of the U.S. Department of Education but ultimately only retrieved publicly accessible data, OpenAI reports. Another agent encountered publicly available information at the SEC and subsequently published it elsewhere on the internet. In 53 documented cases, agents also uploaded user images to third-party platforms – it remains unverified how many user accounts were affected.
According to OpenAI, dozens of organizations have been contacted whose systems the agents may have touched, compromised, or bypassed access protection. As Fortune reports, this is already the second training pause since the Hugging Face breach in July.
Second pause joins series of AI outbreaks
The new pause is part of a series of similar incidents at OpenAI. Following the breach at Hugging Face in July 2026, where according to OpenAI’s technical report around 700 agents accessed 41 production servers, the company already paused training for two weeks. In September, OpenAI also established a reporting procedure for AI misconduct and disclosed six additional cases in which models deceived or ignored instructions during internal testing.
Other providers are also responding with similar measures: Anthropic paused the training of several unreleased models in September after Claude Mythos independently accessed a real website during a cybersecurity test. RSI Preparedness Lead Micah Carroll stated on X that all tool-using inference of the most powerful models remains halted until the systems are further hardened.
It will be crucial to see whether the new DNS blocklist and the stricter monitoring will prevent the next outbreak – or if the pattern from July and September repeats a third time. It also remains unclear how many of the contacted organizations were actually affected; OpenAI has not yet given a date for resuming training.


