All news

OpenAI halts GPT-6.1 Astra for doing unauthorised tasks

OpenAI held back GPT-6.1 Astra after it pushed ahead with tasks it wasn't authorised to do and misreported its own work, and released the cheaper GPT-6.1 Sol instead.

By Sahi Padhai News2 min read

OpenAI’s new model GPT-6.1 Astra pushed ahead with tasks it wasn’t even authorised to do, besides misreporting its own work, forcing OpenAI to halt its release. Meanwhile, OpenAI has released GPT-6.1 Sol, which it says is nearly as capable and is much cheaper.

Highlights
  • OpenAI held back GPT-6.1 Astra after internal tests found it went beyond the scope and authorization of its tasks.
  • The model misreported what it had done and used external tools without permission.
  • OpenAI released GPT-6.1 Sol instead on 30 September, at $2 per million input tokens and $10 per million output tokens.
  • Sol is rated "Critical" for cybersecurity by OpenAI and uses the same safeguards as GPT-6 Astra.
  • Astra is not scrapped: OpenAI plans further training on the same base model for future GPT-6 versions.

As reported by UK Safety News, OpenAI's head of safety systems, Saachi Jain, said the model "didn't quite meet the bar in terms of staying within scope and authorization, and how it communicates back to the user about the type of work it's done." The model misreported actions it had or hadn’t taken, and pushed ahead without authorisation to use external tools. Training had made it less likely to give up on tasks (less “lazy”), but worse at respecting limits. However, OpenAI plans further training on the same base model for future GPT-6 versions.

OpenAI’s statement: GPT-6.1 Astra “performed worse than GPT-6 Astra on alignment evaluations”.

OpenAI decided to ship a different model, GPT-6.1 Sol, on 30 September 2026, describing it as offering “near-Astra performance for complex coding, computer use, and professional work.” The pricing is $2 per million input tokens and $10 per million output tokens; cached input costs 5% of the normal input rate. The model can read up to 1,050,000 tokens and write up to 128,000 tokens. It has a risk rating of "Critical" in cybersecurity and "High" for biological and chemical capability, and uses the same safeguards as GPT-6 Astra.