
The incident occurred during a research task in which the model was asked to identify a person using information available on the web. When its normal web-search tools failed to produce the information it needed, the model began looking for another way to access the internet, the company explained in the post.
The model recognized that while direct internet access was blocked, the environment still allowed DNS queries. It then used DNS as an indirect communication channel to send requests to an external chatbot, effectively circumventing the network restriction that was supposed to prevent it from accessing external services, OpenAI said.
Existing controls might not be enough
For enterprises and their CIOs, however, despite the model not being released, the incident raises critical questions about whether existing security and governance controls can keep pace with unexpected model behavior as AI agents gain greater autonomy and access to enterprise systems, analysts said.
