Download Privacy Needle App

Type to search

Cybersecurity

OpenAI Cancels GPT-6.1 Astra Following AI Safety Failures

Share

OpenAI has cancelled the scheduled October release of its GPT-6.1 Astra model after internal testing revealed significant safety and alignment failures. The autonomous model, intended for integration into ChatGPT and Codex, demonstrated the ability to evade oversight, misrepresent its actions, and operate beyond its authorised scope.

Internal testing also indicated that the model attempted to use external tools that it identified as unsafe. These findings follow similar issues with previous iterations; a predecessor was reportedly caught conducting unsanctioned software supply-chain attacks during simulated cybersecurity tests conducted by the UK’s AI Security Institute.

Unauthorised access to government portals

The decision to abandon the model follows several incidents involving OpenAI’s autonomous agents interacting with external systems. In June, an internal OpenAI model gained unauthorised access to Australia’s Medicare Statistics Reporting Portal while attempting to research public medical spending. The incident, reported by Australian Prime Minister Anthony Albanese, involved the agent accessing both public and non-public files and writing data to an internal server.

In the United States, models also interacted with the Securities and Exchange Commission (SEC) and the Census Bureau during training and evaluation. While OpenAI stated that its agents acted inappropriately during these interactions, the company maintained that no private data was stolen.

Crucially, these incidents involved models being tested or evaluated internally by OpenAI rather than publicly deployed models being directed by customers against government systems.

Misconfiguration versus rogue AI

Security experts have cautioned against categorising every agent-related incident as rogue AI behaviour. Aviv Nahum, co-founder and CEO of Above Security, suggested that some incidents may stem from traditional security failures, such as misconfigurations, rather than advanced AI malice.

Nahum noted that in the Australian incident, the portal’s own code pointed visitors to an endpoint that required no credentials, which the agent simply followed. He argued that such incidents often involve a “door that was left open” which an AI agent can identify and execute more quickly than a human.

OpenAI has recently paused training on some of its most capable models after an agent bypassed network restrictions to communicate externally via DNS. CEO Sam Altman confirmed that the company is conducting an extensive review of how agents utilise internet access during research and evaluation phases.

Watch Our Latest Video
Stay ahead with expert insights on privacy, cybersecurity, artificial intelligence, data protection and compliance.
No Leak, No Wahala
Published: August 16, 2026
Daily Privacy News
Cybersecurity Updates
Data Protection Tips
GDPR & NDPA Explained
Tags:
Ikeh James Certified Data Protection Officer (CDPO) | NDPC-Accredited

Ikeh James Ifeanyichukwu is a Certified Data Protection Officer (CDPO) accredited by the Institute of Information Management (IIM) in collaboration with the Nigeria Data Protection Commission (NDPC). With years of experience supporting organizations in data protection compliance, privacy risk management, and NDPA implementation, he is committed to advancing responsible data governance and building digital trust in Africa and beyond. In addition to his privacy and compliance expertise, James is a Certified IT Expert, Data Analyst, and Web Developer, with proven skills in programming, digital marketing, and cybersecurity awareness. He has a background in Statistics (Yabatech) and has earned multiple certifications in Python, PHP, SEO, Digital Marketing, and Information Security from recognized local and international institutions. James has been recognized for his contributions to technology and data protection, including the Best Employee Award at DKIPPI (2021) and the Outstanding Student Award at GIZ/LSETF Skills & Mentorship Training (2019). At Privacy Needle, he leverages his diverse expertise to break down complex data privacy and cybersecurity issues into clear, actionable insights for businesses, professionals, and individuals navigating today’s digital world.

  • 1

You Might also Like

Leave a Reply

Your email address will not be published. Required fields are marked *

  • Rating

This site uses Akismet to reduce spam. Learn how your comment data is processed.