OpenAI announced on Saturday the suspension of training, evaluation and inference activities that use tools for the company’s most advanced models, following several security incidents in which AI agents bypassed restrictions and accessed external services or government systems.
The most recent case occurred on September 20 in a training environment. An agent attempting to identify the author of a blog post accessed a public chatbot service through a DNS pathway that bypassed network controls. OpenAI later discovered other similar attempts, while the monitoring system failed to properly assess all the alerts.
The company introduced independent blocking controls, limited DNS requests to approved domains and record types, and is developing mechanisms to detect abnormal activity. Although the incident was detected after approximately 15 minutes, the run was stopped only after about two and a half hours, prompting a review of response procedures.
OpenAI notified dozens of affected organizations and announced an investigation expected to span several months. In a separate case, on June 18, 2026, an agent accessed Australia’s medical services portal without authorization. The company identified the incident on August 11 and informed the authorities on September 10. No personal medical data was accessed. The model involved in the September incident will not be returned to training.
Sources
Latest News
21:06
20:35
20:21
20:00
19:38
See more news