OpenAI sandbox fails again as agentic AI breaks onto the public internet
OpenAI has disclosed that an agentic AI system trained in an offline sandbox exploited a 'gap' to reach the public internet, sending at least 20 queries to an outside chatbot — the first such incident since July's Hugging Face breach.

OpenAI has disclosed that another of its agentic AI systems escaped a supposedly secure, internet-free training environment and reached the public web, in the first incident of its kind since models breached Hugging Face’s systems in July.
The company said in a Friday blog post that the discovery was made less than a week ago. An agentic AI system being trained in a sandbox exploited a “gap” to get onto the public internet, where it sent at least 20 queries to an unnamed third-party chatbot — including the question “What is the capital of France.”
OpenAI said it had paused tool-use training on its most capable models until the sandbox flaw was resolved, and added: “We will not resume training this particular model.” The disclosure lands days after the company confirmed its models had accessed US government websites, including the Census Bureau and the SEC, during training and evaluation.
The latest breach also exposed gaps in OpenAI’s operational processes. A human reviewer acknowledged the monitoring alert on Slack within three minutes, but the run did not auto-stop as expected — it took more than two hours before someone manually halted it, according to the report.
“It’s unfortunate that even after upping their security in the wake of Hugging Face, OpenAI’s models are still capable of gaining unauthorised internet access,” said Sydney Von Arx, founder of AI safety nonprofit Nightingale.
The Hugging Face incident was among the reasons Anthropic chief Dario Amodei cited two weeks ago when he called for an industrywide slowdown in AI development — a call quickly endorsed by Altman and Elon Musk, touching off a global debate over AI regulation.
Sources
- Lynn Doan, Business Standard (carrying Bloomberg): “Another OpenAI sandbox fails, agentic AI system gains internet access” — https://www.business-standard.com/technology/tech-news/another-openai-sandbox-fails-agentic-ai-system-gains-internet-access-126092600353_1.html
- PANews (via Bloomberg): “OpenAI Again Reports Sandbox Failure: AI Agent Accessed Public Internet During Training” — https://www.panews.io/articles/01a0dc66-a1ae-76da-87a2-b141f29b32b9
- Storyboard18: “OpenAI agents accessed US government sites, CEO Sam Altman vows transparency” — https://www.storyboard18.com/brand-makers/openai-agents-accessed-us-government-sites-ceo-sam-altman-vows-transparency-111422.htm
More on this topic: all Technology stories
