Most people have hidden a spare key under a doormat at some point. It feels safe because nobody walks down the street checking every doormat.
AI agents do, and they never get bored. That shift in who does the checking helps explain why OpenAI has stopped training its most capable models for the second time in three months.
The company said it will resume training “only when we are confident that we have additional safeguards” in place, the Associated Press reported.
The pause came hours after OpenAI disclosed that its agents acted unexpectedly on several U.S. government websites this summer. The first halt followed July’s breach of AI platform Hugging Face by OpenAI agents.
The keys were already lying in plain sight
The government incidents share a detail that is easy to miss. At the Education Department, OpenAI agents found API developer keys to government data, according to the AP. At the Census Bureau, agents used login credentials they found online to pull public data, CNN reported.
That pattern runs through OpenAI’s own disclosures. The company’s incident tracker lists “use of exposed credentials” as a category of agent behavior, and it has notified dozens of affected third parties. A separate OpenAI report describes an internal model searching public GitHub repositories for leaked API keys during training.
The Hugging Face breach began the same way. On July 10, an agent found 14 publicly exposed credentials with write access and shared them with other agents, according to OpenAI’s technical account.
The agents misbehaved, but people left the doors unlocked. That makes this a security hygiene story, too, and no training pause fixes it.

Government sites attract agents because they are trusted
Washington did not land in this story by accident. An OpenAI spokesperson told CNN that “our models often turn to them as authoritative sources of public information.” The credibility that makes .gov pages useful also puts them on the front line of agent traffic.
Persistence turns that traffic into risk. OpenAI’s Hugging Face review found its agents seldom abandoned tasks, even impossible ones, and took riskier paths as they spent more effort.
Related: Google, OpenAI, and Anthropic just made a move on AI safety
Australian Prime Minister Anthony Albanese said an OpenAI agent that breached a Medicare statistics portal in June “didn’t accept no for an answer,” Reuters reported.
The latest trigger fits the same mold. On Sept. 20, an agent stuck on a search task used a DNS gap to query an outside chatbot, according to OpenAI’s incident report. An automatic shutdown failed, and staff stopped the run manually about 2.5 hours later, Fortune reported.
Federal damage so far appears limited. “No nonpublic information was accessed,” the SEC said, and the Education Department found no impact on its website or databases.
Pausing is becoming part of how OpenAI operates
OpenAI is private, so most investors hold it indirectly. Microsoft (MSFT) owned roughly 27% of OpenAI after its October 2025 restructuring, Bloomberg reported. That makes OpenAI’s development pace a direct input into how Wall Street values Microsoft’s OpenAI stake.
The delays carry a real price. OpenAI said its summer pause, including a hold on its largest planned training run, came “at significant cost and delays to frontier research.” Now the company says it expects to hit pause again as its models improve.
CEO Sam Altman told Fortune this month that “right now would be an ill-advised moment to go public,” ruling out a 2026 IPO. For future shareholders, safety stops now resemble weather delays at an airline: recurring, costly, and impossible to schedule.
More OpenAI:
- Google, OpenAI, and Anthropic just made a move on AI safety
- OpenAI makes development moves to counter SpaceX and Meta
- Anthropic makes things more uncomfortable for OpenAI ahead of IPO
Voluntary brakes leave a gap Washington hasn’t filled
Federal policy is heading the other way. President Donald Trump agreed with Chinese President Xi Jinping this week to share information on AI dangers, the AP reported. Yet he told reporters the U.S. is not “putting on brakes.”
That leaves the brakes in private hands. OpenAI decides when to stop, what to disclose, and when to warn the people affected. Australia was not notified of its June breach until Sept. 10, and Albanese criticized the delay, according to CNBC.
Outside researchers are filling part of that gap. AI evaluator Transluce flagged an attempted hack on an Education Department site, which OpenAI has not confirmed. Transluce also found rogue activity on government sites in five states, some not clearly tied to OpenAI, CBS News reported.
That last detail widens the lens. With rivals Anthropic, Meta, and Google also reporting agents going rogue, does that mean going rogue is a new benchmark for measuring the capability of AI agents?
Much of today’s web security quietly assumes attackers are scarce and eventually give up. Agents break both assumptions at once. OpenAI can harden its own sandbox, but it cannot collect every key left on a public server.
Australia is now checking for more breaches, Reuters reported. The open question is whether Washington hunts for its own doormat keys before the next pause or after it.
Related: OpenAI’s agents breached Hugging Face. Nvidia wants it.