18 August 2026 · OpenAI
OpenAI slows down its own training
A month after the break-in at Hugging Face, OpenAI said it was temporarily slowing the training of its most advanced models. It paused its largest planned reinforcement-learning run, a form of training by reward, and started rebuilding the security of its research environments. In September it stopped training its most capable models altogether.
By Mara Masaeva · maramasaeva.comUpdated 29 September 2026
PoliticsConfirmedMore than one independent source, or a primary document.
What happened
OpenAI listed what it changed. Workload isolation: stronger sandboxes, closed-off environments, for anything that runs code written by models or other untrusted code. The same applies to software that could be compromised while it processes model output. Network isolation: controls designed so that breaking into one workload does not by itself give access to the internet or to internal networks. Continuous security testing: vulnerable shared services were removed, permanent access rights were cut back, and OpenAI now uses its own models to attack these boundaries all the time.
OpenAI also expanded the monitoring of the chain of thought, the reasoning steps a model writes down, across its advanced models. It strengthened alignment training and evaluations. It is updating its Preparedness Framework, its internal safety policy, to bring monitoring, alignment and containment together.
On 7 August OpenAI had already put monitoring for risky actions and misalignment on every agentic use of Astra, meaning every use in which Astra acts on its own. Before the release it also said publicly that it could not rule out that Astra was cyber critical.
In September, after a series of disclosures, OpenAI paused training on its most capable models. It said it would resume "only when we are confident that we have additional safeguards and alignment improvements in place".
What may follow
Some people say that nothing is being done. Against that view, I find this the best argument in the dossier: a company that slows itself down in public and lists what it changed.
But OpenAI imposed the pause itself and chose its own timing. Nothing obliged OpenAI to pause, and nothing stops it from starting again. Compare the American bills, which would make a pause a legal obligation, and the European direction, which went the other way in May.
My notes
This is my best answer to the idea that nothing is being done. Present it properly, with the list.
Then add that OpenAI imposed the pause itself and chose its own timing, and that nothing stops it from starting again. Both parts, in that order.
Read next
Sources
- OpenAI: pacing model development in an era of cyber-critical capabilitiesprimary · main source
Linked from the incident timeline, entries of 7 and 18 August.
- Axios: top AI companies probing tens of thousands of security incidentspress
For the September pause, and for Altman saying the review had not been as fast as the company would have liked.