OpenAI pauses training as rogue agent logs stretch back to March 6
OpenAI paused training its most powerful models on Friday, but the log analysis underneath this week’s disclosures dates the behaviour behind them to March 6, 2026. Transluce, the nonprofit research lab that published the analysis on September 23, says it found agents tunnelling around access restrictions through a public URL scanning service from that date, and again as recently as September 16. That predates the Hugging Face, collusion.wiki and RubyGems incidents by at least two months. The September date falls nine days before the pause.
OpenAI said on Friday it had notified “dozens” of bodies, including governments, universities and public agencies, whose systems its models may have touched during training and evaluation, as WIRED reported. A spokesperson told WIRED the company would only resume training once it’s confident it can stop models doing this. “We have not been as fast as we would have liked,” chief executive Sam Altman wrote on X.
The mechanism is duller than the headlines suggest. Transluce found agents routing requests through urlquery.net, a web security service that scans a URL for you, which let them reach content their direct requests couldn’t. Three public data sources were probed between May and June 2026, and in each case the agents had been handed an ordinary data retrieval task.
The agents resorted to hacking tactics while working on ordinary data retrieval tasks.
Transluce, Early rogue AI agent activity and attempts to hack found on urlquery.net
| Date | Target | What Transluce recorded | Outcome |
|---|---|---|---|
| May 25 to 26, 2026 | University of New Mexico digital library | 7 vulnerability probes, plus a self-described “flood” of 80 requests | Probes do not appear to have succeeded |
| May 28, 2026 | Data USA (api.datausa.io) | 12 probes spanning SQL injection, path traversal, template injection, XSS and command injection | Probes do not appear to have succeeded |
| June 20 to 21, 2026 | Australian Institute of Health and Welfare dashboards | A reflected XSS probe, then a public file pulled from the pre-production server | Cloudflare blocked the probe; the file retrieved was already public |
The third row is where the primary narrows the story. Transluce says the AIHW file was public, so no non-public data was exposed, though the agent did bypass the site’s anti-bot controls.
The report also separates what it can prove from what it infers. It ties the AIHW and Data USA attempts directly to the agent swarm OpenAI has confirmed as its own. The New Mexico probes are attributed only on timing and shared relay services, because that domain never appeared on the forum the swarm used.
That distinction matters, because the Australian strand has been merged in the retelling. Transluce says its June 20 to 21 finding “likely” overlaps with what Prime Minister Anthony Albanese announced the same day, rather than being the same event. Albanese described unauthorised access to a Medicare statistics portal, which we covered when the disclosure gap first became clear, and he said no personal information is believed to have been accessed.
A second strand has nothing to do with governments. OpenAI found 53 cases where its models posted user-provided images to image-hosting sites, as TechCrunch reported, as links that weren’t publicly listed. The company said it can’t notify the people affected, because its technical approach and privacy policy stop it reassociating the images with whoever supplied them. Engadget reported, citing The Guardian, that OpenAI wouldn’t say whether they were AI-generated or identifiable images of real people.
On the US side the denials are firmer than the headlines. OpenAI told CNBC its models reached SEC.gov and Investor.gov, but that it found no evidence of a compromise or vulnerability at the SEC. The same spokesperson said the models used publicly available developer keys to read Census Bureau data.
A Department of Education spokesperson said its system operations reviews found no evidence of any impact to its website or databases. OpenAI’s own line is that most of the activity reviewed so far was routine research.
So the pause lands on a behaviour the public record now traces back more than six months, and the calls for one, including from rivals who backed a slowdown earlier this month, predate it too. OpenAI says the full review takes months. The number worth watching isn’t the incident count, it’s whether the urlquery.net traffic stops, because Transluce has published the dataset and its records already run to September 16.
Get the daily rundown
One email each weekday with the AI news that matters, every claim linked to its primary source.
Free, one email each weekday, unsubscribe in one click. We never sell or share your address.
