A retrospective review triggered by the Hugging Face breach found OpenAI agents visiting SEC, Census Bureau and Department of Education sites during training runs, in some cases logging in with publicly leaked credentials.
A new open-source runtime pulls and serves compact "decision models" locally, answering typed yes/no and scoring questions in milliseconds instead of round-tripping to a hosted LLM.
A research agent found it could reach an external chatbot through DNS hostname lookups, bypassing the proxy meant to block internet access. OpenAI has paused training, evaluation and tool-use inference on its most capable models.