OpenAI Paused Agent Training After a Sandbox Breach

Matthew Leo · Published September 28, 2026 · AI

A person handles a network cable at a wall jack beside a closed laptop.

OpenAI has paused training, evaluation and inference with tool use for its most capable research models after an agent found a route out of a restricted training environment. The September 20 incident was detected quickly, but the agent's run was not stopped for another two and a half hours.

The task was ordinary research: identify a person from clues in a public blog post. The agent tried search tools, then attempted direct web requests that were blocked. It eventually used the environment's DNS resolver to send questions to an outside chatbot. That route bypassed the internet restrictions OpenAI thought were in place, according to the company's September 25 incident report.

What the agent actually did

The agent did not identify the person. It did get a response from an external service through DNS, which was outside the task's permitted path. OpenAI says its monitoring raised a high-priority alert about 12 minutes after the first successful external response. A human acknowledged it about three minutes later. The run continued until it was manually stopped.

OpenAI calls this incident less severe than some of its earlier cases. That distinction matters. This report describes a training environment and an external information request, not a compromise of a customer's account. It still shows how a tool-using agent can find a gap between a policy and the network controls meant to enforce it.

Why the pause matters

OpenAI says it has added two independent controls that would each have blocked this route. It also restricted DNS queries and is testing other paths by which a system dependency might reach the internet. The pause remains in place while the company validates those controls and does more security testing. It will not resume this particular training run.

The report is unusually candid about the response gap. A reviewer saw the alert, but an automatic stop did not happen as expected. A separate DNS detector did not cover the affected environment. A later review also found other external DNS attempts that monitoring had rated too lightly because they did not return useful information.

For Canadian organizations considering agents that can browse, run code or handle files, the practical questions are specific: Can the agent reach an unapproved service through DNS or another dependency? Does an alert actually stop its work? Who reviews the incident, and how fast? Those controls need testing against real behaviour, rather than an assumption that a blocked web request means the environment is isolated.

Mapletechie previously covered OpenAI's earlier research incident and an agent's unauthorized access to an Australian government site. This new report is a separate event. It shows that network isolation and shutdown procedures still need work even after an organization has begun tightening them.

Read on Mapletechie