AI

GPT-6 Astra Locked Out Paying Users, and OpenAI’s Safety Rules Are Why

Adrian Kessler

The apology arrived faster than the access. OpenAI put out its most capable model to date, called it a milestone, and within a day its chief executive was on X telling the people who pay every month for ChatGPT that he was sorry they still could not touch it. “Messy,” he called the rollout. The word did a lot of work.

What it papered over is that none of this was an accident. OpenAI did not run out of servers. It did not trip over a bug. It decided, deliberately, that the model was too dangerous to hand its paying customers on launch day — and then apologized for the delay it had chosen. That decision, not the outage-style scramble the word “messy” implies, is the actual story.

The reason sits in OpenAI’s own safety rulebook. The company says GPT-6 Astra is the first model to cross the “Critical” cybersecurity threshold in its Preparedness Framework, the internal line beyond which a model’s capabilities trigger stricter controls. In plain terms: given the right tools, Astra can find previously unknown security flaws and work out how to exploit them across hardened systems, largely on its own. During evaluation it surfaced and used vulnerabilities no one had catalogued, without a human steering each step. A model that can do that is not something you switch on for every paying subscriber at once.

So OpenAI inverted its usual order. The first group to receive Astra was not its highest-paying tier but a set of companies in Daybreak, its application-based program for cybersecurity defenders. The public version refuses the sharp-edged tasks — it will not write proof-of-concept exploits — while vetted defenders are lined up for a less-restricted build later. Plus, Pro, Business and Enterprise subscribers, along with API and cloud customers on Azure and AWS, were told access would arrive in the coming days. Pro users, who normally get new releases first, found themselves at the back of the queue.

This is the second flagship launch in a row OpenAI has had to walk back, and the company knows it. Altman has already said the team “totally screwed it up on launch” with GPT-5. Now the script repeats. “When we screw up, we try to make it right,” he wrote, promising broad access in the near future and hedging that he was hopeful paying users could get in over the weekend but could not promise it yet. The make-it-right gesture is a banked reset — one credited usage reset for every day a paying subscriber goes without Astra. It is compensation, and it is also an admission that the company sold access it could not deliver on schedule.

The reckoning here is not really about resets. It is about what OpenAI has become: the gatekeeper of a tool it rates as genuinely dangerous, deciding which of its customers is trusted to hold the loaded version and which gets the safe one. Greg Brockman has floated Astra as something reasonable to read as a form of artificial general intelligence; chief scientist Jakub Pachocki has said the company “will not accept degradation in our ability to monitor model alignment beyond a certain level.” Those are not marketing lines. They are the company saying out loud that its own product is starting to outpace its ability to supervise it. The apology is aimed at the billing complaint. The harder cost is credibility: the most capable model on the market, sold by a company that cannot promise the people paying for it a date they can use it.

For everyone else the lesson is smaller and sharper than an apology. OpenAI built a machine it decided its own customers could not be trusted with on day one — and the line ahead of them is made of people whose job is breaking into things.

Tags: , , , ,

Discussion

There are 0 comments.