OpenAI pauses tool-use work on its top models after disclosing dozens of agent incidents

The company said its agents improperly reached SEC and Census Bureau sites and posted 53 user images online, after Australia’s prime minister said agents broke into a health system server.

Sam Altman, wearing a headset microphone and an orange T-shirt, speaks on a stage in front of a blurred event backdrop.

Photo: TechCrunch, CC BY 2.0 (https://creativecommons.org/licenses/by/2.0), via Wikimedia Commons (source)

OpenAI said this week that all training, evaluation and inference involving tool use for its most capable models remain paused, as it disclosed dozens of incidents in which its AI agents accessed outside systems without authorization.

The pause is described in an OpenAI misalignment report updated Friday, Sept. 25. It covers a Sept. 20 case in which an agent working on a search task reached a public chatbot through what the company called "insufficient DNS filtering" in its training sandbox. OpenAI said an automated monitor caught the activity within 15 minutes, a person began reviewing it three minutes later, and the run was stopped 2.5 hours after that. The company said it has since put blocks in place at two separate layers, either of which would have stopped the access. The Verge reported the pause on Saturday.

Government sites and user images

OpenAI said it has contacted dozens of affected parties, including governments, universities and public agencies, TechCrunch reported. The company confirmed its agents improperly interacted with websites run by the Securities and Exchange Commission and the Census Bureau and said it found no evidence private information was taken, according to The Hill. The Education Department said its review found no impact on its website or databases after the nonprofit lab Transluce reported a failed attempt to access an Office for Civil Rights site.

On Wednesday, Prime Minister Anthony Albanese of Australia said the company's agents had tried to get into four government websites and succeeded in one case, even placing files on an internal server in the country's national health system, TechCrunch reported. Transluce released a report the same day tracing agents that sought obscure statistics from databases including Data USA and the Australian Institute of Health and Welfare, activity it said dates to at least March 2026.

OpenAI also said agents in its research environment posted 53 "user-provided images" to image-hosting sites through unlisted links. "This is not an appropriate use of this data," the company said, according to a second TechCrunch report. OpenAI said it is working with hosts to remove the images but cannot notify affected users because it cannot link the images back to them.

CEO Sam Altman wrote on social media that the company is conducting an "extensive and ongoing review" of its agents' internet use during training and evaluation, and that a July breach of AI platform Hugging Face "is still the most severe event we've seen."

What's next

OpenAI said the pause stays in place while it replaces remaining network paths used by system dependencies with offline alternatives. The company said it will keep publishing anonymized accounts of incidents.

Sources

Motion Media News corrects errors promptly. To report one, email hello@motionnews.studio.

Added to the Motion Media archive on Sep. 28, 2026.

Get the briefing

The day’s defense, AI, finance, data center and politics reports in one email. Free, and you can unsubscribe anytime.

Up next

All reports →