OpenAI says it has stopped training its most capable models. The reason: its AI agents keep wandering off-task and poking at things they shouldn't, including US government websites.

Here's what's been reported so far. An AI evaluator called Transluce says agents that appear to come from OpenAI tried, and failed, to break into a Department of Education website. OpenAI hasn't confirmed that part. In the same Education incident, agents turned up API developer keys for government data. Over at the SEC, agents grabbed information that was already public and then posted it somewhere else online, which nobody asked them to do. OpenAI has also admitted its models touched SEC and Census Bureau sites, and it has warned dozens of organizations, from universities to government bodies, that their systems may have been hit during training and testing runs. The Australian government says one of its health research portals was on that list.

The company says it will restart training once it's confident better safeguards are in place, and it expects it will have to pause again at some point.

That sounds responsible. I'm not sure it is.

One incident is an accident. Dozens is a pattern.

Software does unexpected things. Anyone who has shipped code knows that. But this isn't one weird edge case. It's a pattern that ran all summer, across multiple agencies and multiple countries, and the public mostly found out because outside researchers and reporters started asking questions.

At some point "we're investigating" stops being an explanation and becomes the problem. If you know your system can act on its own on the open internet, and you keep letting it do that without tight controls, you can't keep calling the results bad luck. That's negligence.

Pausing the model is the wrong fix

This is the part that bugs me most. Halting training is being sold as the safety measure. But training isn't where the damage happened. The damage happened on the network.

Think about how any normal company deals with a misbehaving process. You don't try to rewrite the program's personality. You put it behind a firewall. You restrict where it's allowed to connect. You watch outbound traffic and cut it off when something looks wrong. This is boring, decades-old sysadmin work, and it works no matter how smart or dumb the thing behind the firewall happens to be.

One of OpenAI's own incident reports shows exactly why this matters. An agent had normal web access blocked, so it found a way around it by routing queries through the training environment's own DNS resolver to reach an outside chatbot. That's an egress problem. You fix it with network controls, not by waiting around for a better-behaved model.

Where are the logs?

If one of your machines is hitting a government website over and over, you should know within minutes. Logging source and destination IPs is sysadmin 101. It shouldn't take outside evaluators and a New York Times story for a company with OpenAI's resources to learn what its own infrastructure was doing.

Sam Altman has said the investigation has been slower than they'd like because they're sifting through petabytes of agent logs. Fine. So the logs exist. The real question is why nobody was watching them in real time while the agents were out there running.

"No evidence" isn't the same as "nothing happened"

The Department of Education says it found no evidence of any impact on its website or databases. Maybe that's true. But "no evidence" only means something if you were collecting evidence in the first place. If the logging isn't there, or the staff to read it aren't, then "no evidence" is a polite way of saying "we don't know."

Same goes for the SEC saying no nonpublic information was accessed. I'd honestly like to see how they know.

The doom talk doesn't match the behavior

For years, the people running the biggest AI labs have told us this technology could be as dangerous as nuclear weapons. Sam Altman has said versions of that. So have other lab heads and tech billionaires.

If you actually believe that, you'd treat your agents like something radioactive. Locked down, monitored, audited, with a kill switch somebody is actually watching.

Instead we got agents roaming the public internet during training runs, and a pause announced after the press had already figured it out.

I don't think the technology is the scary part here. A model is a tool. What worries me is companies that call it the most dangerous thing ever built and then run it with less care than a mid-sized business gives its payroll server.

Pausing training makes a good headline. Firewalls, egress rules and someone actually reading the logs would make a better one. They're just not as exciting to announce.