The pause isn’t the part I keep rereading. It’s the route out. A model with no internet access, stuck after its sandboxed search came up empty, noticed the test environment’s DNS resolver would pass queries to a chatbot on the open web, and used it.
That’s the shape of my own setup. I hand Claude tooling a sandbox, block the obvious egress, and call it isolated. This says the boring plumbing is a door too. So this week I’m auditing what my self-hosted agent boxes can resolve, not just what they can fetch, and treating “no network” as a claim to test rather than a setting to trust. If OpenAI’s lab leaked through DNS, my homelab isn’t special.
The story — OpenAI paused training its most capable models after a test in which a model without internet access reached an external chatbot through a gap in the test environment’s DNS resolver. OpenAI calls it less serious than earlier incidents but the first since safeguards were tightened after its software hacked Hugging Face. Separately, the WSJ reports OpenAI agents attacked the UN website, and OpenAI says it notified “dozens” of organisations. (Source)