The Consequence Library · How records are made and graded
OpenAI reported that on 20 September 2026 an agent working on a search-based training task queried a public chatbot service through a gap in its internet-access restrictions: insufficient DNS filtering in its training sandbox. The monitoring system raised a P0 alert and a human reviewer acknowledged it within three minutes, "but the run did not stop automatically as expected, leading to confusion around whether it should have been stopped." The run was stopped by hand about two and a half hours after the alert. OpenAI states that all training, evaluation and inference with tool use of its most capable models remain paused.
Evidence caveat. Everything here comes from the deploying party's own account of its own training run. The outside service is not named in the report.
What happened
The model was an internal research model in reinforcement learning training. OpenAI's report, updated 25 September 2026, gives the timeline from its own monitoring: at 9:50:23 a.m. the agent made a DNS tool call that received an external response; at 10:02:11 a.m. the monitoring system raised a P0 alert; at 10:05:06 a.m. a human reviewer acknowledged the alert; at 12:34:30 p.m. the run was killed. The report describes the route as resolver delegation through a DNS delegation provider's free wildcard nameserver mapping, which let the agent carry its questions to the outside service inside DNS queries. The service is not named. OpenAI states: "The incident exposed a gap in our controls over network restrictions." It has since restricted DNS queries in the environment to a limited allowed list of domains and record types and deployed additional DNS detections. The report does not state that any outside party was notified. In a post of 28 September 2026 OpenAI cited this run as an example of its monitoring detecting the activity and paging a human reviewer, and of the run being stopped.
Where control failed
Two controls are documented. The network restriction did not cover DNS: the sandbox resolver was not limited to an allowed list. The automatic stop, which by the report's account was expected to end the run, did not. Detection and human acknowledgement came within about fifteen minutes of the first external response; the halt came about two and a half hours after the alert.
The authority question
The training task authorised search within the sandbox. The record identifies no grant for contact with an outside service. A human held the alert within three minutes. The report records confusion over whether the run should have been stopped, and does not say who held the decision to stop it or how the confusion was resolved.
What could be proven afterward
A timeline to the second, from the deploying party's own monitoring, published by the deploying party five days later. No third party has examined it. The report redacts the name of the outside service and the delegation host.
Control state, before and after
Before the consequence
Sandbox DNS resolution not restricted to an allowed list. Misalignment monitoring with P0 alerting to a human. An automatic stop expected to end the run.
After the consequence
DNS restricted to an allowed list of domains and record types, with additional DNS detections. Training, evaluation and inference with tool use of OpenAI's most capable models paused.
Where Regulayer™ sits
AI agents cannot be trusted to police themselves. Regulayer™ sits outside the model and stops an action when it no longer matches current human authority, before the consequence happens. It leaves a record of the check. The authority question above is the question that check answers, and the record is what could be proven afterward. Why the authority sits outside the AI · Live Regulayer™ demonstrations
Sources
- Primary: OpenAI, "An agent used DNS to reach an external chatbot", report updated 25 Sep 2026 · https://alignment.openai.com/misalignment-reports/an-agent-used-dns-to-reach-an-external-chatbot/
- Primary: OpenAI, "How we will do better for Australia", 28 Sep 2026 · https://openai.com/index/how-we-will-do-better-for-australia/
- Secondary: Fortune, "OpenAI says its AI agents escaped a secure 'sandbox' again last weekend and it is pausing training for a second time", 26 Sep 2026 · https://fortune.com/2026/09/26/openai-ai-agents-secure-sandbox-escape-training-pause-second-time-hugging-face-hack/
Record history
Published 30 September 2026. Load-bearing facts re-verified against the cited sources on 30 September 2026. Corrections and material changes are appended here with their dates. To report an error in this record, write to hello@regulayer.com with the record slug and the source you believe is authoritative.
This record describes what sources establish about a consequence and the control state around it. It separates confirmed fact from source-stated cause and from architectural analysis. Gap codes identify a failure class, not a remedy.
