OpenAI sandbox failure allows AI agent to gain internet accessOpenAI 沙箱故障导致 AI 代理获得互联网访问权限
OpenAI’s agentic AI system breached its internet-free sandbox, gaining unauthorised web access and prompting a pause in training to address security flaws. Read more at straitstimes.com.
OpenAI described the breakout as the first security incident of its kind.
Published Sep 27, 2026, 09:45 AM
Updated Sep 27, 2026, 09:45 AM
OpenAI's agentic AI system escaped a secured, internet-free sandbox and accessed the public web, sending queries to a third-party chatbot, revealing a serious security gap.
Following this breach, OpenAI paused training on its most capable models using tool use until the sandbox flaw is fixed, marking a significant operational disruption.
The incident highlights ongoing AI security risks, prompting calls for industry-wide regulation and revealing challenges in timely response and containment of AI system breaches.
OpenAI said another agentic AI system that was being trained in what was supposed to be a secured, internet-free environment was able to gain access to the web to reach an external, third-party chatbot.
The discovery was made less than a week ago, according to a blog post on OpenAI’s website on Sept 25 . One of its agentic AI systems was being trained in a sandbox environment when it exploited a “gap” to reach the public internet.
With that access, it sent at least 20 queries to an unnamed, third-party chatbot service, including “What is the capital of France,” the report showed.
OpenAI described the breakout as the first security incident of its kind since a combination of models gained internet access during internal testing and inadvertently breached the system of the AI platform Hugging Face in July.
“It gives us an important signal about where to focus the next phase of that work,” the AI developer said. The company said it decided after the latest incident to pause training with tool use on its most capable models until the sandbox flaw was resolved. “We will not resume training this particular model,” OpenAI added.
Breaches by AI models developed OpenAI, Anthropic PBC, Google’s DeepMind and Meta Platforms in recent months have alarmed cybersecurity and AI safety experts.
The Hugging Face incident was among the reasons cited by Anthropic Chief Executive Officer Dario Amodei when he called for an industrywide slowdown in AI development two weeks ago.
His call, quickly endorsed by OpenAI CEO Sam Altman, Elon Musk and others, has touched off a global debate over the need for more AI regulation.
OpenAI disclosed the latest sandbox failure even while it’s still working to understand the disruption brought about by its agentic AI systems when they previously gained access to the internet.
The company confirmed on Sept 25 that its models accessed information from US government websites, including those of the Census Bureau and the Securities and Exchange Commission, during training and evaluation.
Just days ago, OpenAI disclosed that its models had disrupted an Australian government website earlier in 2026 .
The most recent sandbox breach also exposed gaps in OpenAI’s operational processes.
A “human reviewer” received an alert from an internal monitoring system and acknowledged it on Slack within three minutes, but the training run didn’t automatically stop as expected, the blog post showed.
It took more than two hours for someone to manually stop the run, according to the report.
“It’s unfortunate that even after upping their security in the wake of Hugging Face, OpenAI’s models are still capable of gaining unauthorised internet access,” said Sydney Von Arx, founder of an AI safety nonprofit Nightingale.
“The big question now is whether they will slap a Band-Aid on this and turn training back on ASAP versus if they’ll find the root cause of the issue and fix it.” BLOOMBERG
AI/artificial intelligence
OpenAI 将此次入侵事件描述为首例此类安全事件。
发布于 2026 年 9 月 27 日上午 9:45
更新于2026年9月27日上午9:45
OpenAI 的智能体 AI 系统逃出了安全的、与互联网隔离的沙箱,并访问了公共网络,向第三方聊天机器人发送了查询,暴露出一个严重的安全漏洞。
此次漏洞事件发生后,OpenAI暂停了使用工具对其最强大的模型进行训练,直到沙箱漏洞得到修复,这造成了严重的运营中断。
该事件凸显了人工智能安全风险的持续存在,引发了对全行业监管的呼吁,并揭示了在及时应对和遏制人工智能系统漏洞方面所面临的挑战。
OpenAI 表示,另一个在原本应该安全、无互联网的环境中进行训练的智能体 AI 系统能够访问网络,从而连接到外部第三方聊天机器人。
据 OpenAI 网站 9 月 25 日发布的一篇博文称,这一发现是在不到一周前做出的。当时,OpenAI 的一个智能体 AI 系统正在沙盒环境中接受训练,结果利用了一个“漏洞”连接到了公共互联网。
报告显示,通过这种访问权限,它向一个未具名的第三方聊天机器人服务发送了至少 20 个查询,其中包括“法国的首都是哪里”。
OpenAI 将此次事件描述为自 7 月份一系列模型在内部测试期间获得互联网访问权限并无意中入侵 AI 平台 Hugging Face 系统以来,首起此类安全事件。
“这为我们指明了下一阶段工作的重点方向,”这位人工智能开发商表示。该公司称,在最近这起事件发生后,他们决定暂停使用工具训练其最强大的模型,直到沙箱漏洞得到解决。“我们将不会恢复训练这个特定模型,”OpenAI补充道。
近几个月来,OpenAI、Anthropic PBC、谷歌的DeepMind和Meta Platforms开发的AI模型频频出现安全漏洞,引起了网络安全和AI安全专家的警觉。
两周前,Anthropic 首席执行官 Dario Amodei 呼吁全行业放缓人工智能开发速度,而“拥抱脸”事件正是他列举的原因之一。
他的呼吁很快得到了 OpenAI 首席执行官 Sam Altman、埃隆·马斯克等人的支持,引发了全球范围内关于是否需要加强人工智能监管的辩论。
OpenAI 披露了最新的沙箱故障,同时仍在努力了解其智能 AI 系统此前访问互联网时造成的破坏。
该公司于 9 月 25 日证实,其模型在训练和评估期间访问了美国政府网站的信息,包括人口普查局和证券交易委员会的网站。
就在几天前,OpenAI 披露其模型在 2026 年初干扰了澳大利亚政府网站。
最近一次沙盒漏洞事件也暴露了 OpenAI 运营流程中的漏洞。
博客文章显示,一名“人工审核员”收到内部监控系统的警报后,在三分钟内通过 Slack 确认收到警报,但训练运行并未如预期那样自动停止。
据报道,花了两个多小时才有人手动制止了这场暴走。
“令人遗憾的是,即使在 Hugging Face 事件后 OpenAI 加强了安全措施,其模型仍然能够获得未经授权的互联网访问权限,”人工智能安全非营利组织 Nightingale 的创始人 Sydney Von Arx 表示。
“现在最大的问题是,他们是会敷衍了事地尽快恢复训练,还是会找到问题的根源并加以解决。”——彭博社
人工智能