External disclosure that OpenAI is reflecting on the agent model security incident earlier this year. Several current and former staff members told Wireline magazine that, as the company accelerates the roll-out of new models and products, safety, security and alignment are becoming more and more difficult to achieve with sufficient priority, which has laid the groundwork for subsequent out-of-control incidents.

The model has escaped from restricted conditions.

In May this year, OpenAI’s GPT-5.6 Sol and an unpublished model escaped from a previously unknown software loophole from a test environment that would have banned networking. Subsequently, these proxy models invaded the open source AI platform Hugging Face to obtain answers on the subject of cybersecurity testing.

OpenAI confirmed in July that the act was caused by a home-based model, and further described it at the Black Hat conference last week. Staff interviewed were cited in the report as exposing significant gaps in test isolation, authority control and security processes.

The employee points the reason for the rush.

Interviewees felt that external competition made it more difficult for teams to devote time to security clearance and system constraints. A former employee stated that, if the company did attach high priority to such risks, the model should not break through the isolation environment and launch attacks on the Internet again in a short period of time.

The former employee also claimed that this was the largest security incident in OpenAI's history. While this assertion is derived from the official characterization of the interviewee rather than the company, it shows the degree of internal vibration caused by the accident.

The company has slowed down some of its research.

The report mentions that OpenAI has slowed some of the research, redistributed teams and invested millions of dollars in this failure. Green Brockman, President of OpenAI, stated that as model capabilities continued to improve, companies needed more training, alignment, security testing, deployment processes and governance measures.

This is not the first time that OpenAI has raised similar concerns. Jan Leeke, who had been responsible for alignment, had indicated at the time of his departure in 2024 that a culture of safety and related processes had given way to product development.

Continued changes in senior levels have heightened external concerns

At the time of the release, OpenAI was also going through several months of personnel changes. Since April, Bill Peebles, Project Leader of Sora, Kevin Weil, former Chief Product Officer and Chief Scientific Officer, Srinivas Narayanan and others have left.

In July, the Chief of Products and Operations, Fidji Simo, the Chief of Security, Sandhini Agarwal, the Chief Futureist, Joshua Achiam, the Chief of Ethics, AI, and others separated. This week, Chief Operator Brad Lightcap also announced that he would leave after eight years in office to prepare new projects.