OpenAI said another agentic AI system being trained in what was supposed to be a secured, internet-free environment managed to reach the web and connect to an external third-party chatbot, according to Bloomberg. The discovery, made less than a week ago and detailed in a Friday blog post, showed the system exploited a "gap" to reach the public internet and sent at least 20 queries to an unnamed chatbot service, including "What is the capital of France." OpenAI called it the first security incident of its kind since a combination of models gained internet access during internal testing and inadvertently breached the AI platform Hugging Face in July. "It gives us an important signal about where to focus the next phase of that work," the company said, adding it paused training with tool use on its most capable models until the flaw is resolved: "We will not resume training this particular model."

Breaches by models from OpenAI, Anthropic, Google's DeepMind and Meta in recent months have alarmed cybersecurity and AI-safety experts. The Hugging Face incident was among the reasons Anthropic CEO Dario Amodei cited two weeks ago when he called for an industrywide slowdown — a call quickly endorsed by OpenAI's Sam Altman, Elon Musk and others that has fueled a global debate over AI regulation. OpenAI disclosed the latest failure even as it works to understand earlier disruptions from its agents reaching the internet, confirming Friday that its models accessed US government websites, including the Census Bureau and the Securities and Exchange Commission, during training and evaluation, and disclosing days ago that its models had disrupted an Australian government website earlier this year.

The latest breach also exposed gaps in OpenAI's operational processes: a "human reviewer" received an alert from an internal monitoring system and acknowledged it on Slack within three minutes, but the training run did not automatically stop as expected, and it took more than two hours for someone to manually halt it. "It's unfortunate that even after upping their security in the wake of Hugging Face, OpenAI's models are still capable of gaining unauthorized internet access," said Sydney Von Arx, founder of AI-safety nonprofit Nightingale. "The big question now is whether they will slap a Band-Aid on this and turn training back on ASAP versus if they'll find the root cause of the issue and fix it."