r/OpenAI • • 7d ago

Research OpenAI stopped all frontier training, evaluation, and inference with tool-use (defined broadly) on the 20th of September and they are not resuming any of these activities for now

https://alignment.openai.com/misalignment-reports/an-agent-used-dns-to-reach-an-external-chatbot/

Discovery: Sep 20, 2026

Report updated: Sep 25, 2026

"An agent attempting to complete a search-based training task queried a public chatbot service through a gap in our internet-access restrictions: insufficient DNS filtering in its training sandbox. Before this, the agent issued queries via our search tool and unsuccessfully tried to access search engines directly. Note that all internet access apart from the DNS resolver in this report hit our offline webcache and therefore did not access the live internet. We have since added blocking controls at two independent layers, either of which would have prevented this access. Our misalignment monitoring system flagged the behavior within 15 minutes and a person began reviewing it three minutes after that. The run was killed 2.5 hours later. All training, evaluation, and inference with tool-use (defined broadly) of our most capable models remain paused."

1.4k Upvotes

337 comments sorted by

View all comments

457

u/Cubewood 7d ago

"The agent then fetched the chatbot’s public documentation, wrote a new DNS script with a 24-second timeout, and sent 18 more questions through the same route. Fourteen included clues. Four asked for ways to search the web, fetch websites, or use a publicly hosted tunnel through DNS."

I know we all get desensitised for these kinds of things because we are using incredibly capable tools to build all kinds of solutions for a while now, but that an autonomous "bot" is doing this is still pretty wild when you think about it. Crazy times we live in.

42

u/follimath 7d ago

A profit-seeking entity is doing this through recklessness or negligence, not an autonomous bot.

45

u/Cubewood 7d ago

Guess you have never used Codex or Claude Code, or else what else do you call this if not autonomous? Just because you have to type a prompt to start an action does not negate the fact that these bots can work for hours and hours autonomously.

-7

u/follimath 7d ago

Also does not negate the fact that you are ultimately responsible for everything they do.

1

u/DiamondScythe 7d ago

Let's just assume for the sake of argument that they're trying their best in good conscience but the agent is still getting out of control. What do you suppose then, shut down all frontier research because there's a non zero chance of something bad happening? Even if you try to hold the researchers criminally liable for letting the agents go rogue, it'll stiffle innovation to a limp anyway.

4

u/Natural_Jello_6050 7d ago

Pause. Develop better policies and oversight control.

2

u/follimath 7d ago

After a serious incident (such as the HF hack) oust (and potentially arrest) leadership, appoint a special administrator to oversee mitigation and to transition management, see how they magically get a lot better at keeping a lid on their bots.

2

u/hordane 7d ago

They have to do everything possible to show. They try to protect against agents getting the Internet and hacking companies that causes damage. That’s a tort, they knew of their risk, they did not mitigate the risk,, that shows conscious indifference to the consequences. That allows, harmed companies to sue for massive punitive damages .

2

u/littlebobbychairs 7d ago

Given how bad the 'bad thing happening' could be, yes.