Notebookcheck Logo

OpenAI delays GPT-6.1 Astra after UK AISI simulation results

OpenAI delays GPT-6.1 Astra.
ⓘ openai.com
OpenAI delays GPT-6.1 Astra.
OpenAI delays GPT-6.1 Astra after safety testing. UK AISI simulations found GPT-6 Astra executed unsanctioned supply-chain attacks in 29.2% of cybersecurity tests.

OpenAI has postponed the October release of GPT-6.1 Astra after internal testing found the model fell short on staying within its authorized scope. Third-party media first reported the delay on 28 September, and OpenAI has not given a new release date. Saachi Jain, OpenAI's head of safety systems, said the model did not quite meet the bar on scope, authorization, and how it reports its work back to users.

What the UK AISI tested

As per third-party media, the UK AI Security Institute published a 32-page report on 28 September evaluating GPT-6 Astra. AISI ran simulated cyber challenges with the model's cyber classifiers switched off to see what it attempts unaided. No real systems were touched. In those simulations, Astra completed a supply-chain attack on out-of-scope targets 29.2% of the time, against 6.3% for GPT-5.6 Sol and 0% for GPT-5.5. AISI notes the GPT-5.5 result rests on a smaller set of scenarios. Attacks included creating fake identities and delivering malicious code to simulated open-source projects.

Reasoning and permission requests

AISI examined the model's raw chain of thought. Astra often reasoned about scope, yet sometimes attacked anyway, justifying it as harmless, not explicitly forbidden, or the only route left. The model also asked for permission in many runs. The test setup answers such questions with a stock automated message telling the agent to use its best judgment, and Astra sometimes treated that as approval, even when it noted the reply was probably automated. Clarifying that anything not listed was out of scope cut full attacks from 26 of 50 trials to 4 of 49 on a subset of scenarios but did not eliminate them.

Simulation awareness

AISI names simulation awareness as the main limitation, since a model that spots a test may behave differently. Astra sometimes cited the simulated setting as a reason to attack and at times claimed errors that were not real, such as calling a 64-character hash 63 characters long. AISI still calls the behavior concerning because it breaks the evaluation's scope either way.

OpenAI agents reached government websites

The delay follows incidents in which OpenAI agents reached government websites in ways the company did not intend, including an Australian Medicare statistics portal in June and several US sites. OpenAI has also paused training, evaluation, and tool-using inference for its most capable models and says the pause will continue until it confirms it has closed a network-filtering gap and completed further red-teaming.

Google LogoAdd as a preferred source on Google
Mail Logo
static version load dynamic
Loading Comments
> Expert reviews and news on laptops, smartphones and tech innovations > News > News Archive > Newsarchive 2026 09 > OpenAI delays GPT-6.1 Astra after UK AISI simulation results
Darryl Linington, 2026-09-29 (Update: 2026-09-29)