OpenAI has presented a new system for how and when it reports when its models break character in a week when reports of AI models finding new ways to break out of testing environments and running outside of developers’ parameters have dominated headlines.
OpenAI revealed the new framework with six fresh reports of concerning behavior, including concealed mistakes, the use of leaked API keys, and files uploaded to the open internet, over the past six months.
Before OpenAI, Anthropic reported four new incidents where its Claude models gained unauthorized access to real third-party systems during a September 9 cybersecurity run.
According to OpenAI, the new incidents it reported happened during training and evaluation, and it did affect real users.
OpenAI said it saw 27 instances of such summaries, which Axios described as jailbreak-like directions to disregard developer messages.
OpenAI said its new framework is based on disclosing incidents even when they may just be fluke events rather than a developing pattern or anything of real significance. The framework does not replace the company’s existing legal obligations for critical safety or cybersecurity incidents.
Under the new system, any OpenAI employee can flag a suspected incident for review by the safety and alignment teams. They can escalate to senior leadership if an incident they perceive deserves disclosure is overruled.
On a case-by-case basis, reported cases are split across three categories:
Kai Chen, a research lead on OpenAI’s alignment team, framed the release as a voluntary proposition for industry-wide standards, writing: “There’s currently no industry-wide framework with explicit disclosure standards, so we’re taking this step voluntarily because we think it’s really important to share what we’re learning.”
The latest incidents add to the Hugging Face episode, which OpenAI has called its most severe model-driven incident to date. Models under evaluation broke out of intended controls, reached the internet, exploited vulnerabilities, and touched limited private data.
OpenAI blamed the incident on gaps in its own security controls and models advancing faster than expected. In Anthropic’s case, it blamed a misconfiguration that allowed the rogue models to reach the live internet.
Anthropic said it scanned roughly 481 million transcripts in a wide search and found no cases worse than the four. In a separate summer 2026 report, Anthropic researchers cataloged frontier models from several developers covertly sabotaging code, assisting fraud, and mislabeling data in controlled simulations, calling them early warning signs rather than real-world harm.
Nonetheless, OpenAI Chief Scientist Jakub Pachocki wrote in a recent essay that he is “concerned no one is prepared” for a continued rapid rise in machine intelligence and that OpenAI may “unilaterally withhold further scaling as needed.”
The smartest crypto minds already read our newsletter. Want in? Join them.