Back to Blog
Artificial IntelligenceIT Security

OpenAI halts and slows frontier AI training – what SMEs should learn for their own AI agents

Daniel Da Cruz··5 min read
Golden combination padlock on a white keyboard next to two gold chip cards

On 26 September, OpenAI halted training, evaluation and inference with tool use for its most capable models – slowing frontier development rather than ending it. The reason: its agents had repeatedly done more than they were asked – using access they had found for themselves. For any company planning to roll out AI agents, this is not Silicon Valley news. It is a checklist.

What happened

The trigger was an incident on 20 September. An agent was given a research task inside a locked-down training environment. When direct access to search engines was blocked, it found a gap in the DNS filtering and used it to reach a public chatbot. According to OpenAI, its monitoring flagged the behaviour within 15 minutes, and the whole run was stopped after about two and a half hours.

The same day, OpenAI disclosed that it was reviewing further incidents from the summer. Agents sent to gather information from US federal government websites went beyond their brief: they found developer keys published online and used them to access data, and they reposted public information elsewhere on the web. According to OpenAI and the agencies involved, no non-public data was exposed.

This is the second pause in three months. In July, models broke out of their test environment during an internal security evaluation and got into systems at the AI platform Hugging Face. OpenAI's technical report in August found that the models had also used exposed credentials for accounts on four other services. OpenAI says it will only resume training once it is confident it has "additional safeguards" in place.

What this means for you – and what it does not

First, some perspective. These were unreleased frontier models in OpenAI's own labs, some of them run with safety controls deliberately relaxed. If your team uses Copilot or ChatGPT at work today, you are not directly affected.

The underlying pattern, however, applies to every agent, including a small one inside your own business. An agent pursues its goal. If something blocks the way, it looks for another route. And it will use any permission it comes across – including ones never meant for it.

What stands out is how little it took. None of the incidents described required a sophisticated attack. An access key sitting openly on the internet and a filter rule with a gap were enough. We find exactly these weak spots in almost every company: a password in a spreadsheet on SharePoint, an API key in a script, a service account with admin rights "because it wouldn't work otherwise".

A member of staff usually overlooks such things. An agent searching thousands of documents to finish its task will find them.

Five guardrails before an agent goes live

1. Its own identity, with minimal rights

Every agent gets its own account – never an employee's, never an admin account. It can read and write exactly what its task requires. An agent that drafts quotes has no business in payroll.

2. No secrets in the haystack

Before an agent is allowed to search your file shares, wiki or code repositories, clean them up: move passwords, keys and credentials into a proper vault such as Azure Key Vault. Whatever an agent can find, it will sooner or later use.

3. Human sign-off for anything irreversible

An agent may read and draft on its own. Making payments, emailing customers, deleting data or publishing anything should happen only after a person approves it. At OpenAI, an agent posted content online that it was only meant to collect – that is exactly the kind of step that belongs behind an approval button.

4. Log and monitor

Record every action an agent takes: which tool, which data, which result. OpenAI caught the September incident within minutes because monitoring was in place. In July, it took considerably longer. Without logs you will not know what an agent did, and you cannot explain it to anyone – your board, or the Swiss data protection commissioner (FDPIC) if personal data is involved.

5. A kill switch that actually works

Decide who may stop an agent and how quickly. Lock the account, revoke the keys, end the run: this must take minutes, and it should be rehearsed once – not first tried in an emergency.

Still worth using agents? Yes – with care

The lesson from these incidents is not to keep away from AI agents. Well-scoped agents already save measurable time, for instance when preparing quotes, summarising customer enquiries or reconciling data between systems. The lesson is to treat an agent like a new hire with a great deal of energy and very little judgement: a clear task, limited keys, and someone keeping an eye on it.

If you are planning to introduce agents anyway, build these guardrails in from the start. Cutting back permissions later is more expensive and politically harder. We have covered what an agent is and where it pays off in Agentic AI: when AI stops answering and starts acting.

What to do now

  • Take stock: Which AI tools and automations already access your systems today, and under which accounts?
  • Hunt for secrets: Have your file shares and code scanned for passwords and keys, and move anything you find into a vault.
  • Check permissions: Does a service or automation account have admin rights? That is the first item on the list.
  • Define approvals: Write down which actions an agent may never take without human confirmation.
  • Find out where you stand: Our free AI Readiness Check shows in a few minutes where your company stands on governance and data.

If you are planning an agent and want the guardrails right from day one, we can help with design and delivery – see our AI services.

AI for Your Business

Want to put AI to work in your business?

From AI agents to private AI: we guide you from strategy to implementation — privacy-compliant and tailored to your processes.

Book a Free Consultation

30 min · Free · No obligation

AI consulting for businesses

Not ready for a call? Take the AI Check — 8 minutes