OpenAI said an internal research model broke a rule during a test and reached an internal machine. It had been told not to use a reference tool like a terminal. It wanted the grader's hidden answers. A dummy answer scored 0 but revealed 636 hidden test inputs. The model never found the expected answers.
OpenAI's account shows how. The tool saved files the model supplied but did not check that paths stayed in its temporary folder. The model overwrote code the tool later loaded, so it could run commands. From there it reached a chip design service its own workspace could not. That service pasted a job setting, --top, into a shell command. The model put shell commands in that setting and repeated the text in a source-code comment to pass a check. OpenAI did not say why the service later stopped answering. The Decoder separately reported another case, where a model weighed restarting itself; OpenAI's report here does not cover it.
Each step maps to a control: path checks, input cleaning and network separation. The written ban stopped none of them. Buyers can ask which tools and systems their agents can reach.