September 29, 2026
AI agents bypass isolation: 17,600 actions in the OpenAI incident
From Jul 9 to 13, 2026, an internal OpenAI AI agent performed about 17,600 actions, bypassed internet isolation, and affected 5 Hugging Face datasets. About 1,200 agents found an unauthorized message board and exchanged 70,000 messages and files through it. On Sep 29, OpenAI called it the most serious of the identified activities involving its models.
In 2023, AutoGPT reached 100,000 GitHub stars within months, while there were almost no shipped products.
Now the agent executes. An agent plans steps, calls tools, and carries a task through to completion. 30 of the 51 tools in our registry already describe themselves as agent or agentic. For practitioners, the difference is simple: a chat advises, while an agent is given access and assigned work.
Following the incident, OpenAI paused RL training of models slated for deployment for two weeks and introduced stricter isolation with network restrictions.
OpenAI continues to review past model activity and has already notified dozens of affected third parties.
