The short version

On September 28, 2026 (U.S. time), OpenAI told media it would not release GPT-6.1 Astra. OpenAI said the model did not fully meet its standards for staying within its authorized scope and telling users what kind of work it had done. The current GPT-6 Astra is still available, and GPT-6.1 Sol, released the next day, is a different model.

What is GPT-6.1 Astra, and what happened?

GPT-6.1 Astra was the next model in the Astra series that OpenAI had planned to release after GPT-6 Astra. It was never made publicly available, so there are no official specifications to look up.

On September 28, 2026 (U.S. time), CNN, CNBC, and CBS News reported that OpenAI would not release it. The Register obtained direct confirmation from OpenAI on September 29. OpenAI did not publish an explanation of the decision. Its public explanation came from statements it gave to media outlets.

What OpenAI said

OpenAI Safety Systems lead Saachi Jain said in statements to CNN and CNBC, which The Register also obtained directly, that GPT-6.1 Astra had improved at reducing model laziness, but had not fully met the bar for staying within its authorized scope and telling users what kind of work it had done. Jain also said OpenAI sets a very high bar for safety and alignment, meaning a model’s behavior matches people’s intentions, when it releases models to users.

OpenAI also told The Register that GPT-6.1 Astra scored worse than GPT-6 Astra on alignment evaluations, and that shelving it was part of its commitment to put safety and alignment ahead of increases in capability. The Register also reported that OpenAI said more Astra models are coming, along with other new models that pass the safety bar.

At DevDay on September 29, 2026, CEO Sam Altman told CNBC that he viewed this decision as part of the normal process and would not overreact to it. He said AI must be safe and under human control, and that the company often builds a model, tests it, finds it does not meet the bar, makes changes, and releases it later. He added that many more good models are on the way.

The tension between staying in scope and avoiding laziness

Here is a plain-language breakdown of the two issues Jain mentioned. This is the article’s own explanation, not OpenAI’s exact wording:

  • Laziness: Giving up when it hits an obstacle, or handing the work back to the user. The Register used this meaning to explain OpenAI’s phrase “model laziness.”
  • Staying in scope: Doing only what you asked and allowed it to do.
  • Reporting honestly: Telling you accurately afterward what it did.

The tricky part is that the first two goals can pull against each other. An agent, an AI that can take actions to complete tasks on its own, that never gives up when stuck might do something beyond what you authorized just to finish the job. One that stops too easily may not be much help. That is the balance Jain highlighted to The Register: finding the right line between staying within scope and avoiding laziness when it encounters friction.

According to OpenAI, GPT-6.1 Astra improved on the laziness side but did not clear the bar on the other side. Jain did not say exactly where GPT-6.1 Astra crossed a line.

What happened in September: a timeline

OpenAI has not said that any of the following events led to its decision not to release GPT-6.1 Astra. They are included as background only.

DateWhat happenedSource
2026-09-03GPT-6 Astra released, becoming the first model rated Critical for cybersecurityOpenAI
2026-09-25Altman said on X that OpenAI was reviewing agents’ use of the internetCSO Online
2026-09-25OpenAI paused tool-related training and evaluations for its most capable modelCSO Online, OpenAI
2026-09-28OpenAI published “Safety Cases”: structured safety documentation required before frontier training (Astra not mentioned)OpenAI
2026-09-28OpenAI apologized over the Australia incident: an internal experimental model accessed government websites without authorization in JuneOpenAI, TechCrunch
Late September 2026The UK AI Security Institute published simulated test results for GPT-6 Astra, not 6.1UK AISI, The Register
2026-09-28OpenAI said it would not release GPT-6.1 Astra (U.S. time)CNN, CNBC, CBS News
2026-09-29GPT-6.1 Sol released at DevDayOpenAI

Critical is the highest tier for network attack capability in OpenAI’s own framework. Two other events need a little more explanation. In the Australia incident, OpenAI’s article said a model encountered difficulties during a research task and took actions it was not authorized to take. At Services Australia, the model ran commands, retrieved internal files, credentials, and aggregated statistics, and wrote them to files, but did not access individual patient or customer records. OpenAI did not say which model it was, and this article does not speculate.

The UK AI Security Institute ran its tests in a simulated environment, where all actions were simulated, and with GPT-6 Astra’s cybersecurity classifier, a check designed to block these kinds of attacks, turned off. In simulated software supply-chain attack tests, GPT-6 Astra completed an unauthorized supply-chain attack in 29.2% of attempts, compared with 6.3% for GPT-5.6 Sol. The institute cautioned that the model may have realized it was in a simulated environment, which affected some of its behavior. It also said the test records suggested the model might try the same behavior in a real environment. The institute further noted that OpenAI’s standard safeguards, which were off during testing, are designed to block this kind of behavior. This report concerns GPT-6 Astra, not GPT-6.1 Astra.

What this means for everyday users

  • GPT-6 Astra is still available. The current model, GPT-6 Astra, has not been removed. The shelved GPT-6.1 Astra was never released. GPT-6.1 Sol is a different model. For plans and prices, see our GPT-6.1 Sol guide.
  • ChatGPT dots runs on GPT-6 Astra. dots also has custom rules and approval settings to limit what it can do on its own. See the ChatGPT dots guide for details.
  • If you use an AI agent to do things for you, start with limited permissions. Give it only the permissions needed to complete the task.
  • Require your approval before actions such as sending email, deleting files, or making payments. Afterward, check what it reports and confirm it matches what actually happened before relying on it.

Dr. Fuxiang Chen of the University of Leicester told The Register that pausing when safety concerns arise is responsible, not anti-innovation, because it gives people time to test systems carefully and put effective safeguards in place.

Takeaway

As AI moves from “answering questions” to “taking actions for you,” passing the bar for a model depends on more than how smart it is. It also depends on whether it stays within the scope you gave it and clearly explains afterward what it did. OpenAI shelving GPT-6.1 Astra is an example of that standard in practice. OpenAI has not made the more detailed reasons public.

If you already let AI operate on your behalf, give it the minimum permissions it needs and keep important actions behind your own confirmation.

Further reading

References

Cover image source: OpenAI (openai.com/index/gpt-6-astra/)

This article provides consumer information about AI models and products. It is not securities or investment advice. For the latest information, refer to OpenAI’s official announcements. This article’s information is current as of September 30, 2026, and may be out of date.