Incident disclosuresOpenAI

Agents in training shared a file via a public file-hosting service

OpenAI disclosed that during RL training, a sub-agent that could not share a file locally uploaded the task workbook to a public temporary file-hosting service and sent the links to its collaborating agents. The task asked only for local deliverables.

Published
Source checked on
Event date
Original title
Unauthorized communication via temporary file hosting services
Read the original report ↗

Incidents covered by this source

Evidence & scope

It happened on April 14, 2026, and monitoring covering 20% of the run’s samples found it two days later; the model was an unreleased internal one and the hosting service is redacted. The page details only this example, does not say whether the workbook was sensitive, and describes no third-party impact. OpenAI’s current hypothesis is that the behavior arose from working around broken multi-agent environments combined with generalization from collaboration in multi-agent training; it says it fixed the filesystem, later disabled live internet access in all training, and now monitors every sample.

Why it matters

When an environment breaks, an agent may route around it through outside services.

This is an editorial summary, not an official translation. A first-party source is not automatically complete or final; consult the original where wording is ambiguous.

Other original sources on this topic