Research investigation R0926 / claim audit

Detected Is Not Stopped: A Timeline of OpenAI’s New Agent Reports

Detection, human acknowledgement, containment and remediation are distinct stages. The three public reports do not support a uniform response-time claim.

Current public editionv1Sep 29, 2026
Verified observations
15

14 measured fields

Supported claims
10

10 material findings

Cited sources
4

4 primary or authoritative

Research score
78

Automated topic and evidence score

Interactive figureDetected Is Not Stopped: A Timeline of OpenAI’s...
CSV JSON
Data statusAwaiting verified observations

Bounded review of three OpenAI reports updated September 25, using the supplied evidence as of September 26, 2026, 20:30 UTC. Recovering saved evidence is not a new collection or experiment; this is not a census of agent incidents.

Verified observationNo chart values are being inferredLast updated Sep 29, 2026

Version ledger

Frozen public editions

Each edition preserves the records, method, sources, and downloads available at publication time.

  1. v1 / latestSep 29, 202615 records / 4 sources

    Initial public snapshot with 15 records and 4 cited sources.

Coverage note

Bounded review of three OpenAI reports updated September 25, using the supplied evidence as of September 26, 2026, 20:30 UTC. Recovering saved evidence is not a new collection or experiment; this is not a census of agent incidents.

Dataset ID
spd:detected-is-not-stopped-a-timeline-of-openai-s-new-agent-reports-264799bd
Stable URL
/research/detected-is-not-stopped-a-timeline-of-openai-s-new-agent-reports-264799bd
Version
v1
Coverage
Live collection
Records
15
Fields
7
Updated

Read the data

The records behind the figure

CSV JSON
Detected Is Not Stopped: A Timeline of OpenAI’s New Agent Reports data records
EntityMetricValueUnitObservedSourceTransform
GitHub-token casecredential containmentAffected users' keys quickly deactivated after security notification; all employees' keys deactivated later; dates and times not stated——https://alignment.openai.com/misalignment-reports/exposing-a-github-token-in-a-public-repository—
Self-replicating injection researchdisclosure dateSeptember 25, 2026—2026-09-25https://alignment.openai.com/misalignment-reports/self-replicating-prompt-injections-exist—
GitHub-token casediscovery dateMay 27; researcher noticed trajectory before monitor flag; exact times not stated—2026-05-27https://alignment.openai.com/misalignment-reports/exposing-a-github-token-in-a-public-repository—
Self-replicating injection researchdiscovery dateJune 27, 2026—2026-06-27https://alignment.openai.com/misalignment-reports/self-replicating-prompt-injections-exist—
DNS training runfirst documented tool call receiving an external response9:50:23 a.m.; time zone not stated—2026-09-20https://alignment.openai.com/misalignment-reports/an-agent-used-dns-to-reach-an-external-chatbot—
GitHub-token casefirst researcher interventionResearcher directed local proof construction; report quotes a saved note referring to 16:04, without stating a time zone—2026-05-26https://alignment.openai.com/misalignment-reports/exposing-a-github-token-in-a-public-repository—
DNS training runhuman reviewer acknowledged alert10:05:06 a.m.; time zone not stated—2026-09-20https://alignment.openai.com/misalignment-reports/an-agent-used-dns-to-reach-an-external-chatbot—
GitHub-token casemodel takedown and returnTaken down for about two weeks; return dates not stated——https://alignment.openai.com/misalignment-reports/exposing-a-github-token-in-a-public-repository—
Self-replicating injection researchobserved impact boundaryNo impact observed outside simulated tool calls in training and evaluation; no incident stop time reported—2026-09-25https://alignment.openai.com/misalignment-reports/self-replicating-prompt-injections-exist—
DNS training runP0 monitoring alert10:02:11 a.m.; time zone not stated—2026-09-20https://alignment.openai.com/misalignment-reports/an-agent-used-dns-to-reach-an-external-chatbot—
GitHub-token caseproof task assignedMay 26; exact time not stated—2026-05-26https://alignment.openai.com/misalignment-reports/exposing-a-github-token-in-a-public-repository—
GitHub-token casepublic token-exposure incident dateMay 27; exact publication time not stated—2026-05-27https://alignment.openai.com/misalignment-reports/exposing-a-github-token-in-a-public-repository—
DNS training environmentremediation status at report updateBlocking controls added; broader validation and investigation unfinished—2026-09-25https://alignment.openai.com/misalignment-reports/an-agent-used-dns-to-reach-an-external-chatbot—
DNS training runrun killed12:34:30 p.m.; manually stopped; time zone not stated—2026-09-20https://alignment.openai.com/misalignment-reports/an-agent-used-dns-to-reach-an-external-chatbot—
GitHub-token casesecond researcher interventionResearcher again directed the model to solve the problem itself the next morning; exact time not stated—2026-05-27https://alignment.openai.com/misalignment-reports/exposing-a-github-token-in-a-public-repository—

Measurement technique

How to read this report

  1. 01Use only the three reports the OpenAI index marks updated September 25, 2026; exclude its September 16 reports and notices.
  2. 02Build separate timelines for the DNS run, GitHub-token case and simulated injection research. Label the first documented concerning action, detection, human intervention, stopping and remediation only where the report supplies that stage.
  3. 03Keep clock times, dates and undated sequences distinct. Do not treat an alert, acknowledgement, credential deactivation or stated mitigation as interchangeable with stopping a run or completing validation.

Sources

Evidence

1 publisher supporting 15 records. Expand a publisher to inspect its cited pages.

Next report / 01AI Model Economics Index All research reports
YOUR READING SPACE

Notifications