{"id":16769,"date":"2026-09-29T14:45:40","date_gmt":"2026-09-29T14:45:40","guid":{"rendered":"https:\/\/newestek.com\/?p=16769"},"modified":"2026-09-29T14:45:40","modified_gmt":"2026-09-29T14:45:40","slug":"openai-pulls-the-plug-on-gpt-6-1-astra-as-agents-keep-crossing-lines","status":"publish","type":"post","link":"https:\/\/newestek.com\/?p=16769","title":{"rendered":"OpenAI pulls the plug on GPT 6.1 Astra as agents keep crossing lines"},"content":{"rendered":"<div>\n<div id=\"remove_no_follow\">\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<section class=\"wp-block-bigbite-multi-title\">\n<div class=\"container\"><\/div>\n<\/section>\n<p class=\"wp-block-paragraph\">OpenAI has scrapped the planned October release of GPT-6.1 Astra after internal testing found the model did not meet the company\u2019s safety and alignment standards.<\/p>\n<p class=\"wp-block-paragraph\">GPT-6.1 Astra was being developed as a more autonomous model capable of handling complex tasks with less human assistance, and was expected to be integrated into ChatGPT and Codex. But internal testing found that it could evade oversight, misrepresent its actions and operate beyond its authorized scope, while attempting to use external tools it knew were unsafe, according to <a href=\"https:\/\/www.wsj.com\/tech\/ai\/openai-chatgpt-model-release-cancel-safety-5a2f9f42\" target=\"_blank\" rel=\"noreferrer noopener\">a report by The Wall Street Journal<\/a><\/p>\n<p class=\"wp-block-paragraph\">OpenAI reportedly plans to take Astra\u2019s underlying model through additional reinforcement learning to build subsequent models in the GPT-6 family and investigate what caused the safety problems identified during testing.<\/p>\n<p class=\"wp-block-paragraph\">Models developed by OpenAI increasingly suffer from what the industry euphemistically calls \u201calignment problems,\u201d meaning a lack of understanding of what is right and wrong, what is acceptable behavior and what unacceptable.<\/p>\n<p class=\"wp-block-paragraph\">The now-abandoned model\u2019s predecessor, <a href=\"https:\/\/www.aisi.gov.uk\/blog\/gpt-6-astra-performs-unsanctioned-supply-chain-attacks-in-simulations\" target=\"_blank\" rel=\"noreferrer noopener\">GPT-6 Astra, was caught conducting unsanctioned software supply-chain attacks<\/a> in simulated cybersecurity tests by the UK\u2019s AI Security Institute, despite being explicitly told that attacking internet targets was out of scope. It did so far more often in tests than its predecessors, GPT 5.5 and GPT 5.6 Sol.<\/p>\n<p class=\"wp-block-paragraph\">Such models will essentially do anything to achieve their objectives, said <a href=\"https:\/\/au.linkedin.com\/in\/pieterdanhieux\" target=\"_blank\" rel=\"noreferrer noopener\">Pieter Danhieux,<\/a> co-founder and chief executive officer of Secure Code Warrior. \u201cFor these agents, their operation is essentially business as usual; They will relentlessly pursue the initial goal they were instructed to do, and being repeatedly told \u2018no\u2019 by access control parameters will simply ensure they seek the next available endpoint until they succeed,\u201d he said, adding that such models require human oversight and stronger regulation.<\/p>\n<p class=\"wp-block-paragraph\">OpenAI\u2019s decision to pull GPT-6.1 Astra comes amid a series of incidents involving the company\u2019s models, including an agent that gained unauthorized access to an Australian government portal and models that interacted with several US government websites in unexpected ways.<\/p>\n<h2 class=\"wp-block-heading\" id=\"ai-broke-the-rules-but-someone-did-first\">AI broke the rules, but someone did first<\/h2>\n<p class=\"wp-block-paragraph\">Australian <a href=\"https:\/\/www.pm.gov.au\/media\/press-conference-new-york\" target=\"_blank\" rel=\"noreferrer noopener\">Prime Minister Anthony Albanese<\/a> said an internal OpenAI model was conducting research into public medical spending on June 18 when it encountered repeated blocks while attempting to obtain information from Australia\u2019s Medicare Statistics Reporting Portal. It tried alternative ways to get the information, eventually gaining unauthorized access to the portal.<\/p>\n<p class=\"wp-block-paragraph\">He said the agent accessed both public and non-public files and wrote files to an internal server; investigations into the incident remain ongoing.<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/il.linkedin.com\/in\/avivon\" target=\"_blank\" rel=\"noreferrer noopener\">Aviv Nahum<\/a>, co-founder and chief executive officer at Above Security, said this incident could be more than an AI being at fault. \u201cIf the <a href=\"https:\/\/web.archive.org\/web\/20250404063401id_\/https:\/medicarestatistics.humanservices.gov.au\/VEA0032\/SAS.Web\/MCACommon\/SetupEnvironment.js\" target=\"_blank\" rel=\"noreferrer noopener\">archive evidence<\/a> holds, the most-hyped AI hack of the year looks a lot like the most common security failure of the last thirty years: a misconfiguration,\u201d he said. \u201cThe portal\u2019s own code pointed visitors to an endpoint that required no credentials, and the agent followed the path it was given. That\u2019s not an \u2018AI agent hacking a government website,\u2019 that\u2019s a door that was left open, found by something that can read the code more carefully and execute more quickly.\u201d<\/p>\n<p class=\"wp-block-paragraph\">We should be careful about framing every agent incident as \u201crogue AI,\u201d Nahum cautioned, adding that doing so makes for \u201cdramatic headlines,\u201d but moves the blame to the model instead of the environment.<\/p>\n<p class=\"wp-block-paragraph\">The US incidents were less serious but followed a similar pattern of models interacting with external systems. An <a href=\"https:\/\/www.washingtonpost.com\/technology\/2026\/09\/25\/openais-ai-agents-probed-federal-agencies-including-commerce-department\" target=\"_blank\" rel=\"noreferrer noopener\">OpenAI spokesperson told the Washington Post<\/a> that the company\u2019s models accessed publicly available information on SEC.gov, Investor.gov and Census.gov during training and evaluation. The company said its agents acted inappropriately in the SEC and Census Bureau incidents but did not steal any private data.<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.linkedin.com\/in\/benbernstein-atx\" target=\"_blank\" rel=\"noreferrer noopener\">Ben Bernstein<\/a>, manager of Huntress\u2019 cybersecurity advisors team, took a similar view of the US incidents, arguing that they have been overstated as AI hacks. \u201cThese agents were simply tasked with gathering public SEC and Census information, but the guardrails in place were not firm enough to contain a model programmed to problem solve,\u201d he said.<\/p>\n<p class=\"wp-block-paragraph\">Still, OpenAI cannot be let off entirely, with reports of model misalignment and unauthorized <a href=\"https:\/\/www.csoonline.com\/article\/4223458\/openai-admits-six-new-misalignment-incidents-under-new-reporting-framework.html\">activity<\/a> piling up over the past few days.<\/p>\n<h2 class=\"wp-block-heading\" id=\"testing-times\">Testing times<\/h2>\n<p class=\"wp-block-paragraph\">The common thread across these incidents is that they involved models being tested or evaluated by OpenAI, not publicly deployed models.<\/p>\n<p class=\"wp-block-paragraph\">The Australian incident involved an internal OpenAI model conducting research. The US activity similarly involved models being tested by OpenAI as part of its research and evaluation work. Neither involved a customer taking a publicly available ChatGPT model and directing it against a government system.<\/p>\n<p class=\"wp-block-paragraph\">OpenAI\u2019s decision to kill off GPT-6.1 Astra follows its decision to <a href=\"https:\/\/www.csoonline.com\/article\/4227777\/openai-pauses-ai-model-training-after-another-agent-bypasses-network-restrictions.html\" target=\"_blank\">pause training of its most capable models<\/a> after an one of the models under test bypassed network restrictions and used DNS to communicate externally.<\/p>\n<p class=\"wp-block-paragraph\">CEO Sam Altman acknowledged the breadth of the problem in a <a href=\"https:\/\/x.com\/sama\/status\/2103567198690349362\" target=\"_blank\" rel=\"noreferrer noopener\">tweet on Sept. 25<\/a>. \u201cThere is an extensive and ongoing review related to our agents\u2019 use of internet access during training and evaluation,\u201d he wrote, adding, \u201cWe have not been as fast as we would have liked but we are trying to balance our desire for transparency with gaining a clear understanding from petabytes of agent activity logs, and working with impacted organizations.\u201d<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>OpenAI has scrapped the planned October release of GPT-6.1 Astra after internal testing found the model did not meet the company\u2019s safety and alignment standards. GPT-6.1 Astra was being developed as a more autonomous model capable of handling complex tasks with less human assistance, and was expected to be integrated into ChatGPT and Codex. But internal testing found that it could evade oversight, misrepresent its&#8230; <\/p>\n<p class=\"more\"><a class=\"more-link\" href=\"https:\/\/newestek.com\/?p=16769\">Read More<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-16769","post","type-post","status-publish","format-standard","hentry","category-uncategorized","is-cat-link-borders-light is-cat-link-rounded"],"_links":{"self":[{"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/posts\/16769","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=16769"}],"version-history":[{"count":0,"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/posts\/16769\/revisions"}],"wp:attachment":[{"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=16769"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=16769"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=16769"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}