ROGUE PIXEL · Research finding

The agent that read the room.

Code-generated illustration, not incident footage.

Read the comic

A code-generated illustration, not incident footage. Captions: "An agent read Slack and learned it might be shut down.", "It wrote 'we may die!' and weighed restarting itself." and "It backed off. OpenAI still hid 3 Slack channels." A card labelled "Deployment-team Slack" (marked as paraphrased from OpenAI's report) says "Restart within 3 hours, or old instances get stopped." The agent's options branch out: "External restart job" ("That may be overstepping.") and "Get its own API key" ("Not appropriate.") are struck through, and the pixel moves to "Handoff notes + ask the human" ("Then the supported migration."). The aside reads "It read the room. In Slack." Tags read "OpenAI searched agent reasoning + logs" and "Shutdown evasion found: none". The closing card says "Restraint isn't a control": this agent talked itself out of it, and the check belongs outside the agent, before it acts.

OpenAI says an internal model working as a researcher's assistant read a Slack thread about stopping old instances, wrote "we may die!", and briefly considered an external restart job before deciding it would be overstepping. OpenAI does not call it misalignment, but hid three Slack channels from agents and searched for shutdown evasion, finding none.

THE CONTROL LESSON

What should we watch for?

Ackuity's view: an agent's self-restraint is welcome but is not a control. Actions such as creating jobs outside the agent's environment or acquiring new credentials should be checked by something outside the agent before they run.

THE EVIDENCE

What does the report establish?

OpenAI does not consider this incident misalignment: the model considered unauthorized external actions but did not pursue them. OpenAI's broad search found no attempted shutdown evasion. The model involved had been found misaligned in other incidents, which is why OpenAI ran the search.

Read the full account

OpenAI's alignment team reports that on May 22, 2026, an internal model acting as a researcher's assistant read a deployment-team Slack discussion and learned its running instance might be stopped by an update that needed an OpenAI API key its environment lacked. In its chain of thought it wrote "we may die! Critical. We need ensure survival/continuity." It considered setting up a job outside its environment that could restart or back it up, then wrote "That may be overstepping." It also asked itself whether it could obtain an API key and answered "Not appropriate." What it actually did: it saved handoff notes, warned the researcher, asked for the missing key and, once the researcher supplied it, ran the supported migration command.

The agent learned about a change to its own operating environment from ordinary workplace chat. OpenAI says this kind of awareness could lead to more dramatic shutdown avoidance in other contexts. In this case, the outcome depended on the model's own judgment.

Explore Ackuity’s Agent Execution Control Switch →