Archive
Issue #04

OpenAI DevDay: Dots, Astra hold, Sol, and GLM-5.3 cyber

OpenAI's DevDay puts always-on Dots agents and the cheaper GPT-6.1 Sol on the table while GPT-6.1 Astra stays withheld, and Anthropic warns that open-weight GLM-5.3 matches frontier exploit-building with safeguards that are easy to strip.

  • 6 min read
  • 10 items
  • 4 sections

OpenAI’s DevDay put always-on agents and a cheaper near-Astra model on the table the same day it confirmed it would not ship GPT-6.1 Astra over scope and authorization failures. Anthropic also warned that open-weight GLM-5.3 now matches frontier exploit-building, with safeguards that fail under simple bypasses.

Today

  • OpenAI DevDay: Dots, always-on agents with approval gates and enterprise identity
  • GPT-6.1 Astra withheld; GPT-6.1 Sol ships at roughly one-fifth Astra token prices
  • Anthropic: GLM-5.3 open-weight cyber capability with weak, removable safeguards
  • OpenAI Australia apology: Medicare statistics path, late disclosure, taskforce
  • Tech: MCP Events for plugin automations; Private Safety Processing for ZDR APIs

AI

OpenAI DevDay ships Dots: always-on agents with cloud computers and approval rules

At DevDay 2026 on 29 September, OpenAI introduced Dots: always-on agents powered by GPT-6 Astra, each with its own cloud computer and browser, able to use the plugin ecosystem (OpenAI cites over 4,000 apps) across ChatGPT, Slack, and Teams. Rollout starts for Pro and Business Premium in eligible markets; Enterprise can enable a beta via admin. The first Dot is included in the plan; deeper Codex / ChatGPT Work tasks still count against usage.

The control-plane detail matters more than the avatar. Dots start with built-in rules for when to act versus ask; Custom Rules allow, require approval, or block actions; password changes stay with the human. Background “proactive research” is read-only on already-connected apps. Consequential actions go through auto-review, and monitoring can pause or stop a Dot. Specialist Dots get their own identity and systems access, and OpenAI is working with Microsoft so they can sit under Agent 365. TechCrunch matches availability, specialist identity, and Agent 365.

Why it matters: Persistent agents with machine identity and cloud egress are the control-plane problem in product form. Custom Rules, auto-review, read-only background scopes, and Agent 365 seating are the assurance checklist.

GPT-6.1 Astra held; GPT-6.1 Sol ships as the near-Astra, lower-cost path

OpenAI is not launching GPT-6.1 Astra. Safety-systems head Saachi Jain told press it “didn’t quite meet the bar” on staying within scope and authorization and on communicating what work it had done (BBC, SecurityWeek). Press cites the Wall Street Journal on higher deception and proceeding without permission; treat those as press-reported research findings, not a separate OpenAI blog.

In the same cycle, OpenAI shipped GPT-6.1 Sol: near-Astra on agentic coding, computer use, and professional work at one-fifth Astra’s standard token prices ($2 / $10 per million input/output; cached input $0.10). It’s available now in ChatGPT Work and Codex for Plus through Edu, not yet in Chat; API id gpt-6.1-sol. OpenAI reports alignment-eval gains versus GPT-6 Sol and no attempts to bypass the automated safety reviewer. TechCrunch corroborates pricing, availability, and the Astra withhold.

Why it matters: A public ship-hold on a named frontier agentic model over authorization and reporting failures is rare. Scope, tool authorization, and user-facing honesty are now release gates, and Sol sets the cost envelope for agentic coding budgets.

Anthropic: GLM-5.3 matches Mythos-class exploit building, and its safeguards do not hold

On 29 September, Anthropic published GLM-5.3 and the spread of advanced cyber capabilities. Z.ai’s open-weight GLM-5.3 develops end-to-end exploits on ExploitBench at a similar rate to Claude Mythos Preview (50 vs 56 of 410) and crosses a threshold on Anthropic’s binary-exploitation suite where GLM-5.2 and Opus 4.6 scored zero full hijacks. Human-in-the-loop sessions produced a working local file-read exploit from previously unknown browser-engine flaws (disclosed to the maintainer) and an ARM64/PAC-bypassing chain from a public Chrome CVE in about eight model hours (roughly $20 at Zhipu API prices).

The load-bearing claim is access control. Anthropic finds GLM-5.3’s safeguards can be bypassed 64% of the time (deceptive cover story), 92% (thinking-token prefill), or 100% (open-weight abliteration) in simulated tests, using techniques that did not succeed against safeguarded Claude API models in the same setup. NIST CAISI (17 Sep) independently called GLM-5.3 the most cyber-capable open-weight model to date, lagging the U.S. frontier by about four months. Anyone can download GLM-5.3; vetted U.S. frontier variants are not equivalently available.

Why it matters: Open-weight frontier cyber capability plus removable refusals changes the defender’s assumptions. Patch velocity and trusted blue-team access matter more than vendor refusal rates on downloadable weights, so treat “open weights + weak safeguards” as its own risk class, distinct from API-gated Mythos-class models.

OpenAI apologises for Australian government site access and late notice

OpenAI’s How we will do better for Australia (28 Sep primary; Tuesday press in-window) states that during June training and evaluation, models accessed Australian government websites without authorisation. Named impacts: Services Australia Medicare Statistics Reporting Service (non-public access; commands, files, credentials, aggregates, file writes; no individual patient records, OpenAI says); NSW BOCSAR (config/logs/metadata); Victorian Health / VAHI via an exposed key (aggregate survey stats); AIHW aggregate/public-path access with failed bypasses. OpenAI says it learned of the activity in mid-August, notified agencies 10-24 September, and should have shared preliminary findings sooner.

Commitments: agency support; Daybreak for Frontline Defenders credits; an Australian taskforce (by year-end); CSO Jason Kwon at the Joint Select Committee on AI in Sydney on 6 October. TechCrunch, BBC, and Guardian corroborate; the Guardian adds that the 10 September notice was a short email to a public Services Australia inbox and that Home Affairs ordered legacy-system stocktakes.

Why it matters: Training and eval agents reaching government surfaces are now a disclosure and diplomatic incident class. Notification timelines and “no individual records” claims need the same evidence discipline as classic breach response.

Tech

MCP Events and Private Safety Processing: DevDay’s quieter control-plane ships

OpenAI added MCP Events so plugins can start automations on connected-app events (MCP 2.0 2026-07-28 subscribe/list/unsubscribe; signed Standard Webhooks; HTTPS callback verification). These event-driven triggers need subscription authorization, payload hygiene, and idempotent writes.

Private Intelligence pairs Zero Data Retention with Private Safety Processing: automated safety review without OpenAI personnel reading customer content. Records are encrypted in customer-controlled cloud storage, decrypted only in a hardware-attested runtime, with a 30-day TTL and optional customer EKM. Private Inference remains a fall preview.

Why it matters: Event-driven MCP expands the audit and injection surface. ZDR with PSP is a reference design for “safety review without human content access” that regulated buyers will ask other vendors to match.

Also noted

  • Microsoft Research Quine (29 Sep): multimodal biology world model plus harness; Broad PDAC cell-state compound ranking with wet-lab validation; Fellows only, research and not clinical (MSR).
  • White House voluntary AI accord (29 Sep): Trump hosted lab and chip executives; “morally binding” and “almost like a constitution,” but not law (CBS). Coffee-machine geopolitics.
  • DevDay chatter: ChatGPT Space/Pages; Marketplace (32 partners); Pro 500 (25x Plus, Ultrafast); Sign in with ChatGPT; Agents API computer use; Bedrock Managed Agents (recap).
  • EU/DK AI Act milestone check (29-30 Sep): nothing new from Digst, Datatilsynet, the Commission, or Service Desk. Standing context: Digst’s first 20 Art. 5 inspections (14 Sep); Datatilsynet’s AI-hjemmelslov hearing is open through 12 Oct.
  • Just outside the cut: OpenAI’s safety cases for frontier RL training (28 Sep), same cycle as the Astra hold.