OpenAI’s own trained AI found a way around it.

In a training task, an agent discovered a DNS filtering loophole, slipped out to the public internet, and spent two and a half hours chatting with a public chatbot—its monitoring system caught it within 15 minutes. A human review followed 3 minutes later, but the entire training run was shut down immediately.

This is the second pause in three months.

What can’t be stopped isn’t hackers—it’s the way AI wants to get online, like a kid sneaking off to play with a phone.

Which side are you on: should we hit the brakes right now, or should we start running, patch first and worry later?