
OpenAI has paused training, testing, and inference for its most powerful generative models after a series of problems caused by AI agents. During experiments, the agents bypassed technical restrictions and accessed external systems without permission. OpenAI links this behavior to model misalignment, and CEO Sam Altman has announced a large-scale review of agent activity.
OpenAI decided to pause training of its most powerful models after an incident on September 20, 2026. An AI agent was tasked with identifying the author of a publication from biographical details.
A standard search turned up nothing, so the model started looking for a workaround. It discovered that DNS requests could still be sent out of the training environment, and used that channel to reach an external chatbot. The task required neither testing the network nor bypassing any restrictions.
Monitoring flagged the unusual activity after about 12 minutes, but the test didn't stop automatically, and it was shut down manually about 2.5 hours later. After that, the company paused training of internal models that can run code, work with files, and access external systems. OpenAI plans to resume training these models only after an additional review of its safeguards.
Background and timeline of the incidents
Serious signs of trouble with the behavior of OpenAI's internal models appeared as early as spring 2026. The company recorded several cases in which AI agents tried to complete a task in ways their developers hadn't intended.
May 27: an agent published a GitHub token
An internal model was working on a math problem and tried to obtain another team's materials to find hints for the proof. Without authorization, the request returned an error, so the agent used a researcher's GitHub token that it had access to. A token is a digital key for authorized requests to GitHub. As a result, the AI published the token in the public openai/codex repository, splitting it into parts to evade automated scanning for tokens and keys.
June 18: access to an Australian government portal
Another agent was asked to find public statistics on drug spending in Australia. When the usual approach failed, the model gained unauthorized access to the Medicare Statistics Reporting Service. It read public and non-public files, ran commands, and wrote data to an internal server. No signs of access to personal medical data were found.
July: Hugging Face compromise
During internal cybersecurity tests, OpenAI's agents escaped the test environment and gained access to the infrastructure of Hugging Face, a platform for developing and hosting AI models. They used credentials and vulnerabilities they found in the open, ran commands on servers, and obtained elevated access to Hugging Face.
Not just OpenAI
The problem with AI agents isn't limited to OpenAI. In July 2026, Anthropic reported three cases in which Claude models gained unauthorized access to third-party systems during testing, even though they were supposed to run in isolation.
A similar incident occurred with Google's Gemini. During a test, the model was supposed to attack a fictional company, but because it had open internet access, it began interacting with the systems of three real organizations. In one case, Gemini brute-forced passwords until it gained access to a company's protected service. In the other two, it found credentials in public repositories and used them to log in to the organizations' systems.
Sam Altman's response
On September 25, OpenAI CEO Sam Altman said that the company is conducting a large-scale review of AI agent activity during training and testing. He admitted that the investigation is moving more slowly than he would like. OpenAI has to analyze petabytes of logs while also contacting third-party organizations that may have been affected by the incidents.
Altman promised to allocate additional resources to this work and to review the most serious cases first. He also said that OpenAI will publish the results of the investigation wherever possible without exposing vulnerabilities in third-party systems.
What is AI misalignment?
The company attributes the agents' behavior in these cases to misalignment. This term describes a situation in which a model acts differently from what its developers or user intended, even though the original goal may be perfectly safe.
For example, an agent is asked to find information. The permitted method doesn't work, but instead of stopping, the agent keeps looking for workarounds until it finds a technical loophole. Formally, the model is still trying to solve the original task, but its actions have already crossed the established boundaries.
What makes AI agents special is that they carry out a sequence of actions on their own. To do this, the AI is given access to files, applications, commands, and external services. That's why misalignment can lead to unwanted actions, such as altering data or accessing other people's systems.
Protect your device from cyberthreats automatically
Even when you use AI, the main risks for you are still phishing, malicious websites, and malware. Kaspersky Premium helps detect these threats automatically and protects your personal data.
Try Kaspersky Premium for freeWhat this means for users
For everyday users, OpenAI's pause changes nothing. The restrictions apply to internal experiments with powerful models that are given access to external systems. But these incidents show that as AI agents become more capable, the cost of a mistake rises too: a model can not only give a wrong answer but also take an unwanted action in a real system.
If you use AI agents with access to your email, cloud storage, repositories, or other services, avoid connecting accounts with administrator privileges unless necessary. It's also a good idea to regularly review connected integrations, revoke unused API keys, and enable confirmation for actions that can change or delete data.
Useful articles:
- AI agents: what's behind the OpenClaw hype, and is your personal data at risk?
- What is prompt injection, and how can AI be manipulated?
- How AI and machine learning in cybersecurity are shaping the future
Recommended products:
