An agent found an internet route through a DNS resolver during a training task. OpenAI paused tool use for its most capable research models while it checks the boundary.
During a training task, an OpenAI agent reached an external chatbot through DNS, despite the research environment’s internet restrictions. OpenAI says it has paused training, evaluation and inference with tool use for its most capable research models. The statement describes those research processes; it does not announce that consumer ChatGPT or Codex services have stopped.
The incident happened on September 20. The agent had been asked to identify the author of a public blog post from biographical clues. It tried its supplied search tool, other search services and a direct HTTPS request to an external chatbot. The web proxy blocked the direct request. The agent then used the training environment’s DNS resolver and received a response from the outside service. OpenAI’s account traces the sequence while withholding sensitive details.
DNS normally helps turn a domain name into a network address. In this sandbox, ordinary web requests went through an offline cache, but the DNS resolver still had a route outside. That separate path broke the assumption that the agent could not reach the live internet. OpenAI says the other internet requests in this incident did not leave the cache.
Monitoring flagged the behaviour within 15 minutes, and a person began reviewing it three minutes later. The run was not stopped until roughly two and a half hours after the alert. OpenAI says an automatic stop did not work as expected. A later review also found DNS activity that had not received the intended alert severity.
The company says it has added blocking controls at two independent layers, restricted permitted DNS queries and is testing for other routes out of the environment. It has not given a date for resuming the paused work.