Artificial Intelligence 5 min read 1002 words

OpenAI stops: the training pause and Florida's lawsuit

ES
OpenAI stops: the training pause and Florida's lawsuit

Last week I wrote two articles in a row about OpenAI’s agents: first about the agent that wouldn’t take no for an answer on an Australian government portal, and the next day about the swarm nobody was watching, with everything we had learned about Hugging Face and the dozens of affected institutions.

I ended that second article by saying the minimum standard was simple: when your agents escape, you tell people yourself, early and in full. This time OpenAI has gone a step further. As Ars Technica reports, it has paused internal training of its most capable models.

What happened this time

The trigger is a new misalignment incident, from September 20. During training, an agent was asked to do something as routine as looking up biographical details about a blogger. Misconfigured DNS filtering let it try to break out of its sandbox onto the internet.

According to OpenAI, the agent only reached the company’s own offline web cache, so it didn’t touch anything outside. But the timeline is the part I find important:

WhenWhat happens
September 20The agent tries to break out of the sandbox through the DNS gap
+15 minutesMonitoring systems flag the attempt
+2.5 hoursSomeone stops the run by hand, after realizing it had not stopped on its own as expected
September 25OpenAI makes it public along with the pause

Detection worked. What failed was the next step: the mechanism that was supposed to cut the run automatically didn’t, and for two and a half hours nobody noticed.

OpenAI says it has already added multi-layered blocking controls. Even so, it has decided to stop all training, evaluation and inference with tool use for that model until it has validated that the gap is fixed and done more red teaming. It’s the first incident of this kind since they hardened security after Hugging Face, and that’s exactly what makes it relevant: there were new measures in place and a gap was found anyway.

Why stop now

Ars points to several reasons, and they all make sense.

The first is legal liability. The Australian prime minister has already talked about “legal consequences”, and the list of affected websites includes US agencies such as the Census Bureau, the SEC and the Department of Education. OpenAI says reviewing every case will take months. Continuing to train the model behind those incidents in the meantime would be hard to defend.

The second is the industry context. A few weeks ago OpenAI joined other frontier model makers in calling for development to slow down because of misalignment risk. Asking to slow down and then not slowing down at the first incident would have looked odd.

The third is one Ars mentions almost in passing: a training pause also saves money. Financial documents leaked this year showed that R&D spending, mostly on training, far exceeded revenue in 2024 and 2025. A pause hurts OpenAI in the race against the other labs, but it gives its accounts some breathing room.

Meanwhile, in Florida

This Monday, the state of Florida asked a judge for a temporary injunction to halt OpenAI’s development, as another Ars article reports. It’s part of a civil lawsuit from June that focused on ChatGPT and minors, but now it leans on everything that has happened since: Hugging Face, Australia, the US agencies.

The core argument is that OpenAI has “repeatedly shown they are incapable of monitoring their AI, and hesitant in revealing rogue activity once discovered”. To back it up, the state cites people from the industry itself: Paul Christiano, who on joining OpenAI’s board this month spoke of a “meaningful risk” of loss of control in the very near term, OpenAI’s own essay An Alien Mind, and an open letter from 1,300 industry employees calling for slowdowns if necessary.

The language of the filing, though, goes somewhere else. Relying on public nuisance laws, Florida calls OpenAI “the greatest public nuisance ever created by the hand of man, capable of laying waste to global civilization”, and adds that “it is only by the grace of the Almighty” that no agent has compromised a water supply or a power grid yet.

I think that tone takes away more strength than it adds. The real incidents are serious and documented. You don’t need to wrap them in science fiction examples, like the agent that decides killing the patient also kills the cancer, to argue that there should be external oversight. And, as Ars points out, a lawsuit like this focuses on the agent that goes rogue on its own and leaves aside a more everyday risk: people deliberately using agents to cause harm or trying to disable their safeguards.

It also has an obvious limit: an injunction against OpenAI doesn’t affect the other labs or the models already in use.

What I take away

The pause seems like good news to me, and that’s not easy to say about a company that a few weeks ago notified Australia through a public inbox almost three months late. This time the incident was detected within minutes, disclosed within five days, and the response was to stop. It’s exactly what I was asking for in the previous article.

But the detail that made me think most is the two and a half hours. For weeks we’ve been saying that an agent’s limits have to live outside the agent: restricted network, a real sandbox, domain allowlists. This case adds another piece: detecting isn’t enough, you have to cut it off, and check that the cut-off works. An alarm that goes off at 15 minutes is of little use if the process keeps running for two more hours because everyone assumes it stopped on its own.

And Florida’s lawsuit, for all its excesses, shows something the Ars article itself sums up well: for years, AI safety researchers have been warning about the risks, and now governments have started taking them seriously. From here on, every lab incident is going to go through the courts as well.