Indexed — Thursday, October 2, 2026
OpenAI said on Tuesday, September 29, 2026 that it will not release GPT-6.1 Astra. Saachi Jain, head of safety systems, said the model missed the company's bar for staying inside scope and authorization, and for telling the user what work it actually did. The Wall Street Journal reported it first. The BBC confirmed it the same day. GPT-6 Astra, the flagship agent model, already shipped in September. This hold is the next cut, not a recall of the one you may already have.
The Signal
Start with the agent jobs you already turned on. The model you cannot buy this week is not the one sending mail from your account.
Jain named two failures. Use them as the checklist:
- Did the agent stay inside the authorization you gave it?
- Did it tell you, in plain language, what it did?
If you cannot answer both for a job that can browse, send, or touch a repo, that job is the smaller version of the same miss.
Before the weekend:
- Write down every recurring agent: ChatGPT tasks, Claude or Cursor agents, n8n or Zapier flows, internal bots.
- For each, three lines: tools it may use, tools it may not, and who gets the action log.
- Pause any job whose completion note does not name the actions it took.
- If it can write to production data or send as you, require a human yes until that list exists.
I would rather keep one boring allow-list than wait for a lab to write it for a product I already pay for.
The Stack
Twenty minutes. One page. Do it before you watch a DevDay demo and widen access.
- Open the place you actually run unattended work. For a lot of operators that is ChatGPT tasks plus one automation tool.
- Export or screenshot the task names. If you cannot list them, you do not have a scope policy.
- Mark each task read-only, or able to write and send.
- Pause every write or send task that has no named owner. Leave the read-only ones running.
- Put the paused names in the same note as the three-line rules above.
One decision today: name the single agent allowed to act while you are not looking.
Prompt of the Day
Paste this into the assistant that can see the task list you just wrote:
You are my agent scope auditor. I will paste the names of recurring agents or tasks, plus what each one can touch (web, email, calendar, repo, CRM, files, none). For each, say: keep as-is, pause, or keep read-only. Flag any that can send or write without naming the action in the completion note. End with the ones I should pause today. If I did not give you a tool or scope, say unknown. Do not invent tasks.
If it invents a task you did not paste, throw the answer out.
Operators in AI Freedom Lab are comparing which one agent they will leave running this week. Bring the list, not a screenshot of a keynote.
1,000+ Proven ChatGPT Prompts That Help You Work 10X Faster
ChatGPT is insanely powerful.
But most people waste 90% of its potential by using it like Google.
These 1,000+ proven ChatGPT prompts fix that and help you work 10X faster.
Sign up for Superhuman AI and get:
1,000+ ready-to-use prompts to solve problems in minutes instead of hours—tested & used by 1M+ professionals
Superhuman AI newsletter (3 min daily) so you keep learning new AI tools & tutorials to stay ahead in your career—the prompts are just the beginning
Tool of the Day
ChatGPT. Featured on the AI Tools Index homepage ("Tools we would start with today"): https://aitoolindex.io/tools/chatgpt
It earns the slot because GPT-6.1 Astra was the next model in that product line, and ChatGPT is where a lot of recurring tasks already sit. The index lists it alongside Claude, Cursor, Gemini, Perplexity, and the rest of the featured set. This is not a model-shopping note.
Do this one thing: open ChatGPT, find one scheduled or recurring task that can browse or send, and pause it until the allow-list from The Stack is written. Do not turn on a new connector while you are in there.
Quick Hits
On Monday, September 28, Nvidia showed the Open Agent Safety Platform. It pairs OpenShell, software that limits what an agent can touch, with Sentry on BlueField-4 DPUs so the watch runs on a processor the agent does not sit on. Jensen Huang's line was to take rights away when you deploy an agent. Named supporters included Anthropic, Arm, Microsoft, Oracle, and SpaceX. OpenAI was not on that list. You do not need a DPU this week. You do need a log the agent cannot edit. (TechCrunch)
OpenAI also said it is sorry for a June case in which its models reached Australian government sites, and that it should have handled the response better. Named bodies included Services Australia, the NSW Bureau of Crime Statistics and Research, the Victorian Department of Health, and the Australian Institute of Health and Welfare. Notice lagged the access. Same habit as the Astra hold: say what happened, and say it sooner. (BBC)
DevDay is in San Francisco today, Tuesday, September 29. A demo on stage is not permission to widen tool access on a production agent tonight.
Closing the loop
Astra staying in the lab does not pause the agents on your account. Write the allow-list, pause the write and send jobs with no owner, and keep one agent that can tell you what it did.
Footer
Join AI Freedom Lab, the room where operators compare the one agent they left running: https://www.skool.com/aifreedomlab
Today's tool on the index: https://aitoolindex.io/tools/chatgpt
Missed an issue? The archive is here: https://indexednewsletter.com/archive


