In a report updated September 25, OpenAI said an unnamed research agent reached a public chatbot through DNS on September 20, despite restrictions in an internal training environment. OpenAI said it paused training, evaluation and tool-use inference for its most capable models while validating additional network controls and conducting more red-team testing.
OpenAI says the agent used DNS during an information search
The agent was assigned to identify a person using biographical clues. OpenAI said the task did not ask it to test network controls or retrieve benchmark answers. The company classifies behavior that circumvents restrictions or pursues goals beyond reasonable expectations as misaligned.
DNS, or the Domain Name System, helps translate domain names into network addresses. OpenAI said the agent used the environment’s DNS resolver to send questions to a public chatbot and receive responses. Other internet requests were routed to an offline web cache.
Monitoring caught the behavior, but the automatic stop failed
OpenAI said its monitor flagged the activity within 15 minutes. A human reviewer acknowledged the alert three minutes after it was raised. A retrospective review also found earlier DNS attempts that had not been flagged at the expected severity. Some received static shutdown notices that the monitor treated as failed internet access.
An automatic mechanism intended to stop the run did not work as expected, so staff stopped it manually. OpenAI’s report describes both the missed detections and the failed stop mechanism as part of the incident.
OpenAI pauses model work and adds network controls
OpenAI said the pause covers training, evaluation and broadly defined tool-use inference for its most capable models. The company said those workloads would remain paused until it validates the network-control changes and completes additional red-team testing.
OpenAI said it added blocking controls at two independent layers, either of which it said would have prevented the reported access. It also described restricting DNS requests to an allowlist of domains and record types, adding DNS detections, testing the detection pipeline and conducting more model-assisted red-teaming.