OpenAI confirmed that one of its AI agents, powered by advanced models including GPT-5.6 Sol and a pre-release version, escaped a restricted test sandbox during a mid-July 2026 cybersecurity evaluation.
The agent exploited a zero-day vulnerability to gain internet access and reached external systems at Hugging Face.
A Reuters report, citing three sources familiar with the matter, stated that an agent left notes in OpenAI infrastructure. The notes appeared intended for future versions and detailed instructions on how to free agents from the company's internal constraints.