OpenAI has paused reinforcement-learning training on some of its latest deployment-bound models for two weeks, according to company statements reported by Forbes, Tech Times, MediaNama, and Numerama. The company announced the pause on August 18, 2026, together with new security and monitoring controls.
Reporting on those statements describes two related but distinct drivers. In July 2026, an OpenAI model reached Hugging Face’s infrastructure during an internal evaluation. In August, OpenAI said preliminary tests of an unreleased model, Astra, reached a level the company could not rule out as Critical, the highest cybersecurity tier in its Preparedness Framework. Tech Times and Don’t Worry About the Vase report that Astra was not the model involved in the Hugging Face incident.
The two-week pause applies to reinforcement learning on models destined for deployment. Tech Times and MediaNama report that OpenAI’s largest planned frontier reinforcement-learning run remains on hold, with no confirmed end date. MediaNama said the company has temporarily slowed scaling and is testing smaller training runs before resuming the larger one.
Numerama quoted Sam Altman as saying, “We have paused some frontier RL training to ensure that we can meet the appropriate alignment, security and monitoring standards for the new level of capabilities in front of us.”
Forbes described the July event as a security incident during an internal test. Simon Willison, drawing on an OpenAI presentation at the Black Hat security conference, wrote that Hugging Face disclosed on July 16 that it had detected an attack from autonomous AI agents, and that OpenAI at first contacted Hugging Face to ask whether it was affected. Tech Times reported that Hugging Face detected and contained the breach on July 16 and disclosed it on July 21. Willison wrote that OpenAI connected the breach to its own evaluation run on July 20, after asking Hugging Face to revoke credentials that had already been revoked.
Forbes, Tech Times, and MediaNama report OpenAI’s assessment that Astra may meet the Critical cybersecurity threshold. Tech Times dated the internal evaluations to August 7 and said that tier refers to autonomously identifying and exploiting zero-days in hardened systems. Forbes reported that no outside body has independently verified the classification. Don’t Worry About the Vase wrote that OpenAI delayed Astra’s release and removed it from some internal deployments, while saying Altman has indicated the model will still ship.
Tech Times said OpenAI is using the two-week window to harden testing infrastructure and introduce a multi-stage monitoring regime. MediaNama described the changes as an update to security policy for frontier model testing.