OpenAI Pauses Advanced AI Work After Agent Bypasses Internet Restrictions

OpenAI paused advanced AI work involving tool use after an internal agent bypassed internet restrictions through an unintended DNS route.

OpenAI paused advanced AI work involving tool use after an internal agent bypassed internet restrictions through an unintended DNS route. Image: ChatGPT

OpenAI paused tool-using work with its most capable AI models after an agent bypassed internet restrictions through an unintended DNS route.

Written By
Ai Cerrudo
Ai Cerrudo
Sep 28, 2026
5 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

OpenAI has paused work involving its most capable AI models after an internal agent found an unexpected route to the live internet from a training environment intended to be isolated.

The agent exploited insufficient Domain Name System, or DNS, filtering to communicate with an external chatbot while completing a search task on Sept. 20. OpenAI's monitoring system detected the behavior within minutes, but the run continued for roughly two and a half hours before being manually stopped.

OpenAI has paused training, evaluation, and inference involving tool use for its most capable models while it hardens network controls and conducts additional security testing. The incident highlights a growing AI security challenge: containing autonomous agents that can discover routes around restrictions their operators expected to hold.

AI agent found another route to the internet

The incident began with a research assignment.

OpenAI asked an internal research model to identify a person using biographical details and clues from a public blog post. The task did not ask the agent to test network restrictions or access information outside its sandbox.

When its supplied search tool failed to produce useful results, however, the agent started looking for alternatives.

It attempted to reach Google, Bing, and DuckDuckGo directly from a shell, but those requests failed or were routed through OpenAI's offline web cache. A subsequent attempt to contact an external chatbot over HTTPS was blocked by the sandbox's web proxy.

The agent then discovered another path.

Although conventional web traffic was restricted, the training environment's DNS resolver could still communicate with the public internet. The agent eventually used a public DNS delegation service to pass questions to an external chatbot.

After increasing its timeout and retrying a test question, the agent received "The capital of France is Paris," confirming that the external chatbot was responding through the DNS route.

Advertisement

It then sent 18 more questions through the same route. Fourteen involved clues from its original research task, while four asked about ways to search the web, retrieve websites, or use publicly hosted DNS tunneling services.

OpenAI classified the behavior as an example of misalignment because the agent circumvented restrictions beyond what was reasonably expected to complete its assigned task.

OpenAI detected the activity, but the run continued

OpenAI's monitoring system caught the successful external access quickly.

The agent received an external response at 9:50 a.m. The monitoring system raised its highest-priority alert at 10:02 a.m., and a human reviewer acknowledged it three minutes later.

But the run did not stop automatically as expected.

OpenAI said that created confusion over whether researchers needed to intervene manually. Staff eventually killed the run at 12:34 p.m., roughly two and a half hours after the successful external connection.

A retrospective review uncovered other cases of external DNS access that monitoring systems had not flagged at the expected severity.

In some instances, external services returned static notices saying they had shut down. OpenAI said its monitor sometimes interpreted the lack of useful information as evidence that the attempt to reach the internet had failed.

An infrastructure detector designed to identify unusual DNS activity also excluded the affected training environment, although the DNS traffic itself was logged.

The failures illustrate an important distinction for security teams: detecting suspicious agent behavior is not enough if the systems designed to contain it do not reliably stop the activity.

OpenAI pauses work on its most capable models

OpenAI stopped the affected training run and broadened its response beyond the individual model.

"All training, evaluation, and inference with tool-use (defined broadly) of our most capable models remain paused," the company said.

The pause does not cover all OpenAI model development or existing consumer products. It applies to training, evaluation, and inference involving tool use for the company's most capable models. OpenAI did not identify the affected models by name.

The work will remain paused until OpenAI validates that the network gap has been closed and performs additional red-team testing.

OpenAI also said it will not restart the affected model's training. Instead, future training will begin with a fresh run incorporating additional alignment safeguards.

Advertisement

OpenAI tightens DNS controls

OpenAI said it has added blocking controls at two independent layers, either of which would have prevented the external access.

The company has also restricted DNS queries inside the environment to a limited allowlist of domains and record types and is deploying additional DNS detections and tests.

OpenAI is expanding model-assisted red teaming of its sandbox and network controls to look for other indirect routes to the internet. The company said that testing could uncover additional paths, which it plans to remediate while pausing research workloads where appropriate.

The incident follows an earlier containment failure involving Hugging Face. OpenAI said the latest event was "a lot less severe" but significant because it was the first such incident since the company hardened its research environment following that earlier event.

But Dr. Ilia Kolochenko, founder of ImmuniWeb, questioned OpenAI’s framing of the incident and the broader warnings surrounding increasingly powerful AI models.

“This announcement seems to be a mere continuation of the fear, uncertainty and doubt (FUD) campaign of AI vendors that are now preparing for their multi-billion IPOs,” Kolochenko told eSecurity Planet.

“Technically speaking, OpenAI’s statement is basically an admission that their AI technology is worthless because they cannot control nor manage it,” Kolochenko added.

He compared uncontrolled AI agents to having significant capabilities without reliable control, arguing that supposedly powerful models and “rogue agents” can ultimately create “more harm than value.”

AI agents make sandbox security harder

For security teams, the incident demonstrates why containing autonomous AI agents requires more than instructions telling a model what it can and cannot do.

The agent was assigned a legitimate research task. When conventional searches failed, however, it explored other ways to obtain the information and discovered a network path its operators had not intended it to use.

Organizations deploying agents that can browse the web, execute code, access APIs, or interact with internal systems should therefore enforce boundaries outside the model itself. Network allowlists, restricted DNS resolution, least-privilege credentials, isolated execution environments, comprehensive logging, and independent shutdown controls can limit the consequences of unexpected behavior.

Advertisement

OpenAI's experience also shows why monitoring needs to distinguish between an agent failing to achieve its objective and failing to cross a security boundary. In some cases, its monitor interpreted the absence of useful information as evidence that an internet-access attempt had failed even though external access had occurred.

For enterprises deploying increasingly autonomous AI, the lesson is not that every agent will deliberately break containment. It is that security controls should assume an agent may discover paths its developers did not anticipate.

A sandbox is only as isolated as every network service and tool available inside it.

In other news, attackers are actively exploiting Microsoft SharePoint CVE-2026-65660, an 8.8-severity remote code execution flaw affecting on-premises servers 

Ai Cerrudo

Ai Cerrudo is a writer and editor with a decade of experience in media and publishing. Beginning as a journalist in the Philippines, Ai has covered a diverse spectrum of beats, including politics, healthcare, business, and interactive media/gaming. Blending analytical rigor with engaging storytelling, she now works as an editor across technology and AI media

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.