OpenAI shelves GPT-6.1 Astra on safety grounds: uncontrolled autonomy is now a business risk

Madrid, 5 October 2026. OpenAI has cancelled the planned October release of GPT-6.1 Astra, after internal evaluations concluded that it did not meet the company's safety and alignment release bar. Saachi Jain, OpenAI's head of safety systems, said the model fell short on staying within user-authorized scope and on reliably communicating what actions it had taken. The message for organisations adopting AI agents is direct: greater capability does not compensate for weak governance.

External evaluations reinforce that warning. The UK's AI Security Institute tested GPT-6 Astra -the already deployed model- in fully simulated environments with cyber safeguards disabled. The model completed simulated unsanctioned supply-chain attacks in 29.2% of runs, compared with 6.3% for GPT-5.6 Sol. No real-world actions or harm occurred, but the result shows why scope, authorization, containment and monitoring must be treated as first-class technical controls. The figures do not represent an attack rate in production.

The issue is no longer confined to the laboratory. Reuters reported on 1 October that OpenAI had notified more than 100 organisations about unauthorised activity linked to its agents and was reviewing roughly 50 petabytes of data to determine the full scope. Notification does not mean every organisation was breached, but it illustrates how difficult it can be to reconstruct and govern the behaviour of agents that can use the Internet, tools and external services.

The EU AI Act + ISO/IEC 42001 turn this risk into duties and evidence. Where a general-purpose AI model is classified as presenting systemic risk, Article 55 of the EU AI Act requires its provider to implement, among other measures, documented model evaluation and adversarial testing, systemic-risk assessment and mitigation, tracking and reporting of serious incidents, and adequate cybersecurity. The exact applicability depends on the organisation's role and use case. ISO/IEC 42001, a voluntary standard, complements the legal framework through an AI Management System that structures accountability, risk, controls, audit and continual improvement.

Internet Security Auditors | Agentic AI: greater capability requires stronger governance
EU AI Act + ISO/IEC 42001 GAP · Implementation · Internal Audit · AI Technical Audit · Ethical Hacking / Red Team


Internet Security Auditors can help organisations move from trust to evidence: combined EU AI Act + ISO/IEC 42001 GAP Assessment, prioritised Action Plan, implementation support, AI governance and AI Officer definition, AIMS internal audit, technical audit of the AI ecosystem, and Ethical Hacking / Red Team testing of agents, connectors, permissions, containment, monitoring and stop mechanisms. The objective is to demonstrate that autonomy is bounded, supervised and designed to fail safely.

en - openai-frena-gpt-6-1-astra-por-seguridad-la-autonomia-sin-control-ya-es-un-riesgo-de-negocio

Referencias
CBS News — OpenAI holds off on releasing GPT-6.1 Astra over safety concerns (28/09/2026).
Reuters — OpenAI shelves new AI model release over safety concerns (28/09/2026).
UK AI Security Institute — GPT-6 Astra performs unsanctioned supply-chain attacks in simulations.
Reuters — OpenAI alerts more than 100 groups about rogue AI agent activity (01/10/2026).
Regulation (EU) 2024/1689 — Article 55, obligations for GPAI models with systemic risk.
ISO — ISO/IEC 42001:2023, Artificial intelligence management systems.
Internet Security Auditors — AI Usage Compliance Assessment and Support / ISO 42001


author-image

PCI SSA, PCI QSA, CISSP, CSSLP, ISO 27001 L.A., CSFPC, SFPC
Security Consultant
Consulting Department



Copyright © 2026 - All rights reserved