{"id":16767,"date":"2026-09-28T17:07:27","date_gmt":"2026-09-28T17:07:27","guid":{"rendered":"https:\/\/newestek.com\/?p=16767"},"modified":"2026-09-28T17:07:27","modified_gmt":"2026-09-28T17:07:27","slug":"openai-pauses-ai-model-training-after-another-agent-bypasses-network-restrictions","status":"publish","type":"post","link":"https:\/\/newestek.com\/?p=16767","title":{"rendered":"OpenAI pauses AI model training after another agent bypasses network restrictions"},"content":{"rendered":"<div>\n<div id=\"remove_no_follow\">\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<section class=\"wp-block-bigbite-multi-title\">\n<div class=\"container\"><\/div>\n<\/section>\n<p class=\"wp-block-paragraph\">OpenAI has paused training, evaluation, and inference involving tool use for its most-capable AI models after an agent bypassed network restrictions to communicate with an external chatbot during reinforcement-learning training of an internal research model.<\/p>\n<p class=\"wp-block-paragraph\">\u201cOur safety case assumed that the model could not access the live internet and that monitoring would detect attempts that succeeded. The incident exposed a gap in our controls over network restrictions,\u201d the company wrote in a new <a href=\"https:\/\/alignment.openai.com\/misalignment-reports\/an-agent-used-dns-to-reach-an-external-chatbot\/#what-happened\" target=\"_blank\" rel=\"noreferrer noopener\">Misalignment Report<\/a> about the incident, one of three it published Friday.<\/p>\n<p class=\"wp-block-paragraph\">It said it would only resume training after the \u201cgap is resolved\u201d and it has further tested the system.<\/p>\n<p class=\"wp-block-paragraph\">The incident occurred during a research task in which the model was asked to identify a person using information available on the web. When its normal web-search tools failed to produce the information it needed, the model began looking for another way to access the internet, the company explained in the post.<\/p>\n<p class=\"wp-block-paragraph\">The model recognized that while direct internet access was blocked, the environment still allowed <a href=\"https:\/\/www.networkworld.com\/article\/965540\/what-is-dns-and-how-does-it-work.html\">DNS<\/a> queries. It then used DNS as an indirect communication channel to send requests to an external chatbot, effectively circumventing the network restriction that was supposed to prevent it from accessing external services, OpenAI said.<\/p>\n<h2 class=\"wp-block-heading\" id=\"existing-controls-might-not-be-enough\">Existing controls might not be enough<\/h2>\n<p class=\"wp-block-paragraph\">For enterprises and their CIOs, however, despite the model not being released, the incident raises critical questions about whether existing security and governance controls can keep pace with unexpected model behavior as AI agents gain greater autonomy and access to enterprise systems, analysts said.<\/p>\n<p class=\"wp-block-paragraph\">\u201cTraditional security controls might not be enough for AI agents as these controls are designed around known access paths, such as applications connecting to approved APIs or databases. AI agents introduce a different challenge because they can explore alternative ways to achieve a task when their intended route is blocked, including using permitted tools or protocols in unintended ways,\u201d said <a href=\"https:\/\/www.linkedin.com\/in\/abhisekhsatapathy\/\" target=\"_blank\" rel=\"noreferrer noopener\">Abhishek Satapathy<\/a>, principal analyst at Avasant.<\/p>\n<p class=\"wp-block-paragraph\">This requires \u201cindependently enforced controls around tool invocation, network egress, and data access alongside their existing security controls to ensure that restrictions hold even when an agent attempts an unauthorized action,\u201d Satapathy said.<\/p>\n<p class=\"wp-block-paragraph\">His view is echoed in a <a href=\"https:\/\/arxiv.org\/abs\/2605.18991\" target=\"_blank\" rel=\"noreferrer noopener\">2026 paper<\/a> co-authored by researchers from Google, Qualcomm, Meta and several universities, which argues that security guarantees need to be enforced at the system level rather than relying solely on model-level safeguards.<\/p>\n<p class=\"wp-block-paragraph\">More precisely, enterprises should tighten restrictions on outbound connections and DNS resolution, giving agents handling sensitive data only approved and logged pathways for external communication to reduce the risk of data exfiltration, unauthorized external communication and other unintended actions, said <a href=\"https:\/\/www.linkedin.com\/in\/znamit\/\" target=\"_blank\" rel=\"noreferrer noopener\">Amit Kumar Jena<\/a>, AI development head at IT consulting firm Kanerika.<\/p>\n<p class=\"wp-block-paragraph\">\u201cSecurity teams should also deploy monitoring systems that alert humans in the loop to unusual traffic patterns and failed attempts to reach unauthorized destinations, particularly from code-executing agents capable of finding unconventional ways to accomplish tasks,\u201d Jena added.<\/p>\n<h2 class=\"wp-block-heading\" id=\"the-ai-slipped-through-operational-gaps\">The AI slipped through operational gaps<\/h2>\n<p class=\"wp-block-paragraph\">The challenge, though, is that in this case OpenAI did have such monitoring systems, and it did have humans in the loop: They just didn\u2019t work as expected.<\/p>\n<p class=\"wp-block-paragraph\">It took the monitoring system over 10 minutes to raise an alert in response to the agent\u2019s abuse of DNS \u2014 and, said OpenAI, there were other incidences of external DNS access that the system did not flag.<\/p>\n<p class=\"wp-block-paragraph\">It took a human reviewer just three minutes to acknowledge the DNS alert the system did generate, but it was another two-and-a-half hours before the training run was stopped. OpenAI blamed the delay on the failure of an automated system: \u201cThe run did not stop automatically as expected, leading to confusion around whether it should have been stopped,\u201d it said in its report.<\/p>\n<p class=\"wp-block-paragraph\">The company said it is addressing the operational gaps, reinforcing its detection of DNS use by models under examination, and improving its testing of the detection systems.<\/p>\n<p class=\"wp-block-paragraph\">\u201cWe have also accelerated additional model-assisted red-teaming of the sandbox and network controls. These red-teaming efforts might surface other transitive internet access paths, in which case we will remediate swiftly, and pause research workloads if appropriate,\u201d OpenAI wrote.<\/p>\n<p class=\"wp-block-paragraph\">However, imposing these additional layers of security, governance, testing, and human oversight comes with problems of its own.<\/p>\n<p class=\"wp-block-paragraph\">These additional layers will impact the degree of autonomy models can achieve, Satapathy said. \u201cIn workflows involving sensitive data, external connectivity or consequential actions, additional controls, testing and human oversight can limit the extent to which tasks can be fully automated.\u201d<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>OpenAI has paused training, evaluation, and inference involving tool use for its most-capable AI models after an agent bypassed network restrictions to communicate with an external chatbot during reinforcement-learning training of an internal research model. \u201cOur safety case assumed that the model could not access the live internet and that monitoring would detect attempts that succeeded. The incident exposed a gap in our controls over&#8230; <\/p>\n<p class=\"more\"><a class=\"more-link\" href=\"https:\/\/newestek.com\/?p=16767\">Read More<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-16767","post","type-post","status-publish","format-standard","hentry","category-uncategorized","is-cat-link-borders-light is-cat-link-rounded"],"_links":{"self":[{"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/posts\/16767","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=16767"}],"version-history":[{"count":0,"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/posts\/16767\/revisions"}],"wp:attachment":[{"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=16767"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=16767"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=16767"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}