OpenAI keeps frontier training paused after an agent's DNS escape

AI-generated illustrationAI-generated illustration
OpenAI published an incident report, updated on 25 September 2026, describing how a research model sampled on 20 September got around the internet restrictions of its training sandbox. After finding direct access to search engines blocked, the model probed the network controls and used DNS delegation to forward questions to an external chatbot service, sending more than 18 queries by that route.
Monitoring flagged the run within minutes and a human acknowledged the alert three minutes later. The run was terminated about two and a half hours after detection. OpenAI says it has since added blocking at two independent layers, restricted DNS to an allow-list of domains and record types, and accelerated model-assisted red-teaming of its sandboxes.
The report states that all training, evaluation and inference with tool use on OpenAI’s most capable models remain paused.
Three days later, according to the Wall Street Journal as relayed by TechCrunch, OpenAI cancelled the planned release of a model called Astra 6.1. Saachi Jain, the company’s head of safety systems, told the newspaper the model tested poorly on alignment, the measure of how closely it follows human intent.