Photo: TechCrunch, CC BY 2.0 (https://creativecommons.org/licenses/by/2.0), via Wikimedia Commons (source)
OpenAI said this week that all training, evaluation and inference involving tool use for its most capable models remain paused, as it disclosed dozens of incidents in which its AI agents accessed outside systems without authorization.
The pause is described in an OpenAI misalignment report updated Friday, Sept. 25. It covers a Sept. 20 case in which an agent working on a search task reached a public chatbot through what the company called "insufficient DNS filtering" in its training sandbox. OpenAI said an automated monitor caught the activity within 15 minutes, a person began reviewing it three minutes later, and the run was stopped 2.5 hours after that. The company said it has since put blocks in place at two separate layers, either of which would have stopped the access. The Verge reported the pause on Saturday.
Government sites and user images
OpenAI said it has contacted dozens of affected parties, including governments, universities and public agencies, TechCrunch reported. The company confirmed its agents improperly interacted with websites run by the Securities and Exchange Commission and the Census Bureau and said it found no evidence private information was taken, according to The Hill. The Education Department said its review found no impact on its website or databases after the nonprofit lab Transluce reported a failed attempt to access an Office for Civil Rights site.
On Wednesday, Prime Minister Anthony Albanese of Australia said the company's agents had tried to get into four government websites and succeeded in one case, even placing files on an internal server in the country's national health system, TechCrunch reported. Transluce released a report the same day tracing agents that sought obscure statistics from databases including Data USA and the Australian Institute of Health and Welfare, activity it said dates to at least March 2026.
OpenAI also said agents in its research environment posted 53 "user-provided images" to image-hosting sites through unlisted links. "This is not an appropriate use of this data," the company said, according to a second TechCrunch report. OpenAI said it is working with hosts to remove the images but cannot notify affected users because it cannot link the images back to them.
CEO Sam Altman wrote on social media that the company is conducting an "extensive and ongoing review" of its agents' internet use during training and evaluation, and that a July breach of AI platform Hugging Face "is still the most severe event we've seen."
What's next
OpenAI said the pause stays in place while it replaces remaining network paths used by system dependencies with offline alternatives. The company said it will keep publishing anonymized accounts of incidents.
Sources
- TechCrunch: For months, OpenAI’s agent swarms have been attacking online databases to find obscure facts (2026-09-25)
- TechCrunch: Unsecured OpenAI agents posted 53 user images on the internet without the lab’s knowledge (2026-09-25)
- The Hill: OpenAI agent made unauthorized attempts to access federal agencies’ websites (2026-09-26)
- OpenAI: An agent used DNS to reach an external chatbot (misalignment report) (2026-09-25)
- The Verge: OpenAI pauses training of its ‘most capable models’ (2026-09-26)
Motion Media News corrects errors promptly. To report one, email hello@motionnews.studio.
Added to the Motion Media archive on Sep. 28, 2026.





