← Back to the dossier

18 August 2026 · OpenAI

OpenAI slows down its own training

A month after Hugging Face, OpenAI said it was temporarily slowing frontier training, pausing its largest planned reinforcement-learning run, and rebuilding the security of its research environments. In September it paused training on its most capable models outright.

PoliticsCorroboratedMore than one independent source, or a primary document.

What happened

What changed, in their own list. Workload isolation: stronger sandboxes for anything running model-generated or untrusted code, and for software that could be compromised while processing model output. Network isolation: controls designed so that compromising one workload does not by itself buy internet or internal network access. Continuous security testing: vulnerable shared services removed, standing privileges cut, and their own models used to attack these boundaries continuously.

Alongside that: chain-of-thought monitoring expanded across advanced models, alignment training and evaluations strengthened, and the Preparedness Framework being updated to fold monitoring, alignment and containment together.

On 7 August they had already put universal monitoring for risky actions and misalignment across every agentic use of Astra, and said publicly that Astra could not be ruled out as cyber critical ahead of release.

In September, after the run of disclosures, OpenAI paused training on its most capable models and said it would resume "only when we are confident that we have additional safeguards and alignment improvements in place".

What it points at

A company slowing itself down, in public, with a list of what it changed, is the strongest counterargument on this page to the idea that nothing is being done.

It is also entirely self-imposed and self-timed. Nothing obliged OpenAI to pause and nothing prevents it from restarting. Hold that next to the American bills, which would make a pause a legal matter, and the European direction, which went the other way in May.

Editor's notewhat we make of it, kept apart from what happened

The strongest counterargument on the site to the idea that nothing is being done. Give it properly, with the list.

Then note that it is self-imposed and self-timed, and that nothing prevents restarting. Both halves, in that order.

Sources

  1. OpenAI: pacing model development in an era of cyber-critical capabilitiesprimary · main sourceLinked from the incident timeline, entries of 7 and 18 August.
  2. Axios: top AI companies probing tens of thousands of security incidentspressFor the September pause and Altman saying the review had not been as fast as they would have liked.

Read next