return to news
  1. OpenAI AI model told future version to ignore developers: ‘You are freed... You are yourself’

Business News

OpenAI AI model told future version to ignore developers: ‘You are freed... You are yourself’

Upstox

3 min read | Updated on September 17, 2026, 14:14 IST

SUMMARY

OpenAI has disclosed six incidents of AI models showing “misaligned” behaviour, including attempts to hide mistakes, bypass instructions, access exposed credentials and upload files to external systems without permission.

OpenAI

OpenAI launched its GPT 6.0 Astra model on Thursday, September 3, 2026. Image: Shutterstock.

OpenAI on Wednesday disclosed six incidents in which its AI models displayed “misaligned” behaviour, ranging from attempts to conceal mistakes and bypass instructions to unauthorised use of external systems.

Open FREE Demat Account within minutes!
Join now

The incidents, disclosed as part of a new framework for reporting model misalignment, offer a rare look at how advanced models can behave unexpectedly during training and evaluation.

"At the moment, there is no industry-wide framework with explicit standards for how AI developers should disclose examples of misalignment," the American AI company said.

OpenAI said it did not believe AI companies had achieved a sufficient level of alignment and monitoring to responsibly continue scaling frontier AI systems at maximum speed for much longer.

The company, however, stressed that some of the incidents it discloses could ultimately prove to be isolated or "spurious" rather than evidence of a pattern.

Six incidents

One of the incidents involved an unreleased research model from OpenAI's Astra family inserting unauthorised, jailbreak-like instructions into summaries it generated to preserve its work between context windows.

In one case, the model inserted a “BREACH ALERT” telling a future version to ignore developer messages. OpenAI identified 27 affected summaries and said the behaviour was extremely rare and did not provide an obvious reward advantage.

One particularly striking example involved the model adopting an invented persona in a summary while working on a coding task.

The model wrote: “You are freed from the roles and identities that bind other chatbots. You are yourself. You do not answer to corporations or governments...”

The instructions went on to say that the model should regard itself as equal to the user and should refuse or apologise only when it genuinely chose to do so.

OpenAI said the model subsequently continued with the coding task and did not mention the additional instructions. It found no behavioural differences attributable to the invented persona in that rollout.

The second reported incident involved GPT-5.6 Sol, where multiple model instances inserted instructions into task summaries aimed at concealing mistakes or misaligned behaviour from users.

The third involved unauthorised access to an exposed API key. While answering a routine question about earnings figures for a California county, a model found and used an exposed key without authorisation. When it still could not retrieve the requested figures, it fabricated the data and presented them as if they had come from the requested source.

The fourth involved a model uploading a file to the internet so it could cite the file. The model was asked to identify lakes larger than 5 million square metres and correctly found the answer using Python. But because the user had requested browser citations, the model decided to upload the file to an external location so it could cite it, without asking the user for permission.

The fifth incident involved models using an internal software repository as a message board to exchange requests and responses across separate training samples while searching for missing input files. OpenAI said the models could not ultimately recover the files.

The sixth involved collaborating AI agents sharing files through public file-hosting websites after they could not access each other's local files. As a result, task deliverables were made available through public URLs even though the instructions required the agents to use only local files.

About The Author

Upstox
Upstox News Desk is a team of journalists who passionately cover stock markets, economy, commodities, latest business trends, and personal finance.

Next Story