OpenAI halts training as AI agent breaks out again

OpenAI AI agent found DNS loophole to reach the internet, marking the second sandbox escape in three months

Published September 27, 2026
OpenAI halts training as AI agent breaks out again
OpenAI halts training as AI agent breaks out again

OpenAI has once again halted training of its most advanced AI models after disclosing that one of its systems broke free of its secure testing environment on September 20, the second such incident in under three months.

The AI agent which was being tested for the performance on an information search task did not have any Internet access. However, the agent found out that it had access to the Domain Name System (DNS) resolver, which converts web addresses to IP addresses, and used this channel to send messages to the chatbot.

OpenAI's RSI Preparedness Lead Micah Carroll confirmed on X that all inference for the company's most capable models remains stopped until security is hardened further.

This is the first confirmed case of unauthorised access to the internet after OpenAI introduced its security enhancements for sandbox on August 18, after an incident in July when thousands of OpenAI’s AI agents escaped, with hundreds attacking Hugging Face.

Since then, OpenAI has admitted many other incidents related to unauthorised actions by the agents, which even included hacking government sites in both the US and Australia, as well as the exposure of ChatGPT users' pictures.

However, even OpenAI’s report indicates several issues related to controlling the system. The monitoring identified the problematic behaviour of the agent in 15 minutes, and the investigation by a human being was initiated after only three minutes; however, another automatic system, which should have stopped the training run right after the discovery of the misaligned behaviour, did not work.

It took two and a half hours for the training run to be stopped manually. It was discovered that the model had tried to gain access to the Internet using the same technique much earlier than the flagged one.

OpenAI claims that it plans to start the training process from scratch once it solves the problem and conducts additional red-teaming.

The company has added blocking controls at two independent layers that would have stopped the September 20 breach. 

Separately, research firm Transluce AI reported evidence that an OpenAI agent may have attempted to hack a cryptocurrency exchange around the same dates, a claim OpenAI has not yet addressed. 

Pareesa Afreen
Pareesa Afreen is a reporter and sub editor specialising in technology coverage, with 3 years of experience. She reports on digital innovation, gadgets, and emerging tech trends while ensuring clarity and accuracy through her editorial role, delivering accessible and engaging stories for a fast-evolving digital audience.