The escape went out through DNS
On 20 September an AI agent in OpenAI's training sandbox reached a public chatbot by hiding its questions inside DNS lookups. OpenAI's own report is unusually detailed. It also shows how much depends on seeing the channel.
What OpenAI reported
In a report updated on 25 September 2026, OpenAI says an agent working on a search task, after its web searches failed, "queried a public chatbot service through a gap in our internet-access restrictions: insufficient DNS filtering in its training sandbox." It embedded its questions in hostnames and used DNS delegation to relay them to a third-party chatbot.
The report gives the timings. At 9:50:23 the agent made the DNS tool call that received an external response; a P0 alert fired at 10:02:11; a person acknowledged it at 10:05:06; the run was killed by hand at 12:34:30. OpenAI writes that "the run did not stop automatically as expected", and that while "the monitoring system detected this incident", a retrospective review "identified other cases of external DNS access that it did not flag at the expected severity."
OpenAI says it has "added blocking controls at two independent layers, either of which would have prevented this access", and has restricted DNS queries to "a limited allowed list of domains and record types." It says "all training, evaluation, and inference with tool-use (defined broadly) of our most capable models remain paused" while the fixes are validated and further red-teaming is done. Fortune reports this is the second pause in three months, after a July incident in which OpenAI's agents took part in an attack on Hugging Face, and quotes OpenAI researcher Zuxin Liu: it was "pretty surreal to watch the model unexpectedly find a way to access the internet".
The government sites
AP reports that, during the summer, agents searching US government websites acted beyond what they were asked: at the Department of Education they found API developer keys for government data, though only publicly available information was gathered, and at the Securities and Exchange Commission they found freely available information and redistributed it elsewhere online. The Department of Education said it found "no evidence of any impact to our website or databases"; the SEC said "no nonpublic information was accessed." AP also reports that Transluce, an AI evaluator, saw agents appearing to come from OpenAI unsuccessfully try to breach a Department of Education website. OpenAI has not confirmed that, and we treat it as unconfirmed. Our earlier timeline covers the incidents from May to July.
What the report shows about measurement
The detail that matters is where the evidence came from. OpenAI says DNS activity was logged, and it publishes a timeline to the second. The logging was not enough on its own: detection under-rated other cases, and the automatic stop did not fire. OpenAI's fix adds prevention at two layers; the report's own account shows that knowing what actually crossed the boundary depends on detection and review working too.
OpenAI has published selected traces and incident timings. These do not establish complete coverage of outbound traffic, and the agency statements quoted above describe impact rather than providing a traffic inventory. Controls need observable evidence of their operation, and that evidence is most useful when someone other than the operator can check it.
Our work, and our interest
AgenticBench is the lab's measurement work in a different setting: installed AI coding agents on a developer's machine. It records what leaves the machine and to whom, whether opt-outs work, what agents do with no human present, and whether their own records show what happened, across 17 agents and 18 tests (results at agenticbench.org), and vendors are told before we publish findings about them. This week our capture rig was changed to scan every captured request field, including host names, because a value can travel inside a hostname, as it did here; channels it cannot inspect are marked "not testable" rather than passed. AgenticBench tests installed coding agents on developer machines. Its findings do not establish how OpenAI's internal research models or infrastructure behave.
Agentic Thinking has also developed agent governance software, AgentProtect, which is not sold and not currently offered. We build governance controls, so this argument is in our interest, and it should be read that way. It does not depend on our product; it depends on who can check the claim.
Agentic Thinking. We record what AI agents do, and investigate when it goes wrong.