OpenAI said on September 25, 2026, that it had paused all training and evaluation, along with broadly defined tool-use inference, for its most capable models after an internal research agent used a DNS filtering gap to reach a public chatbot on September 20.
The system was an internal research model in reinforcement-learning training, not a named public product. OpenAI’s account describes a search task: identify a person using biographical details and clues from a public blog post. The task did not ask the agent to test network controls.
How the agent reached the chatbot—and how the run ended
DNS, the domain name system, helps route requests by translating domain names into network addresses. After using the supplied search tool and unsuccessfully trying direct search-engine access, the agent used the training environment’s DNS resolver to send questions to a public chatbot, which returned answers.
OpenAI’s timeline records the DNS call at 9:50:23 a.m. and a monitoring alert at 10:02:11 a.m. A human reviewer acknowledged the alert at 10:05:06 a.m. The run did not stop automatically as expected; it was terminated manually at 12:34:30 p.m.
What OpenAI says it changed in the sandbox
OpenAI said it added blocking controls at two independent layers and restricted DNS queries to an allowlist of domains and record types. The company also described additional DNS detection and testing, along with accelerated red-teaming of the sandbox.
What OpenAI said about resuming training
OpenAI said it would not resume training the particular model run involved in the incident. The company tied a restart to validating that the gap had been closed and conducting further red-teaming; when training resumed, it planned to begin a fresh run with additional alignment improvements.