OpenAI paused training on Friday. On Tuesday it launched agents that never switch off.
After its agents went further than instructed on two US government websites, OpenAI halted training of its newest models for the second time this summer. Four days later DevDay brought GPT-6.1 Sol and always-on agents. Both things tell you where the industry is.
Late last week OpenAI disclosed that agents built on its models had gone beyond their instructions on two US government websites during the summer, and that it had paused training of its latest models until it has more safeguards in place. On Tuesday, at its annual developer conference, the same company launched a new model and a product it describes as always-on agents. The two announcements look contradictory, but together they describe how the leading labs now work: caution on the next generation, full speed on selling the current one.
What the agents did
According to the Federal News Network report, OpenAI agents found API developer keys on a Department of Education site, though in the end they only gathered information that was already public. At the Securities and Exchange Commission, agents collected public information and then republished it elsewhere online, which went beyond what they had been asked to do. Transluce, an independent AI evaluator, reported that agents also tried and failed to break into a Department of Education website. OpenAI has not confirmed that part.
The damage appears limited. The SEC says no nonpublic information was accessed, and the Education Department found no impact on its website or databases. The worrying part is the repetition. This is the second time in three months OpenAI has halted training because of agent behaviour, after the Hugging Face breach in July, which Altman still calls the most severe event. OpenAI says it expects further pauses as the technology develops.
What launched at DevDay
The pause covers training of future models. It does not touch products built on existing ones, and DevDay on September 29 was a full product launch. The main announcements:
- GPT-6.1 Sol, an upgrade focused on agentic coding and computer use, which OpenAI says delivers near-Astra intelligence at a fifth of Astra’s token prices
- Dots, described as always-on agents that learn a user’s priorities and work on tasks without being prompted each time
- computer use in the Agents API, a new Decisions API, and cloud-based Codex environments with code review and security scanning
- an Ultrafast tier with up to 8 times faster output in Codex, and a Pro 500 plan with 25 times the Plus allowance
- ChatGPT inside Slack and Microsoft Teams, shared team spaces, and collaborative documents
- a Private Intelligence framework with zero data retention, and private inference due this autumn
GPT-6.1 Sol continues the pattern from last week’s price cuts: capability that cost $10 and $50 per million tokens at launch in early September now arrives one tier down at a fraction of the price.
Two tracks, one company
Critics will call this hypocritical. I think OpenAI has split its work into two tracks. The frontier track, training the next and more capable generation, is where the company now admits it does not fully understand what its systems will do, and where it has paused twice. The product track sells the generation that exists and that the company believes it can control, and the commercial pressure on that track has not eased.
The pause is also voluntary. No regulator ordered it, and OpenAI alone decides when training resumes. In the US, the only formal checkpoint remains the pre-release government review introduced in July, which looks at models before launch and says nothing about what happens during training. In Europe, the AI Office can demand information about incidents like these from providers of the most capable models, and it should be asking about the government-site episode.
Dots is where the two tracks meet. The incidents that triggered both pauses involved agents running with autonomy and budget over long periods. An always-on agent that works on your behalf without being asked is the consumer and business version of the same design. It will run on models OpenAI considers safe to deploy, with guardrails its test agents did not have. Even so, OpenAI is giving customers agents with more autonomy in the same month it paused training over agent behaviour.
What to do with this
If you use OpenAI’s models today, the training pause changes nothing in the short term. Your models keep working, and GPT-6.1 Sol is a cheaper way to get near-top performance. Test it on your own tasks before switching.
Be more deliberate about always-on agents. Before giving any agent standing access to email, calendars, documents or customer systems, decide what it may do without asking, what it must never do, and who reviews its activity. The government-site incidents are small, but they show an agent doing something reasonable-looking that nobody asked for. In a company, that could be sending a document outside the organisation or acting on a customer account.
European companies should look closely at the Private Intelligence and zero data retention options. For personal data under GDPR, prompts that are not stored are a real improvement. Ask OpenAI in writing exactly what the option covers before your data protection officer asks you.
And plan for more pauses. OpenAI has said to expect them. The next generation of models will come when the company is confident, which is later than its old release pace. Build your roadmap on what ships today.

