OpenAI says planned GPT-6.1 is too insecure to release - Ars Technica Skip to content Ars Technica home Sections Forum Subscribe Search AI Biz & IT Cars Culture Gaming Health Policy Science Security Space Tech Feature Reviews AI Biz & IT Cars Culture Gaming Health Policy Science Security Space Tech Forum Subscribe Story text Size Small Standard Large Width * Standard Wide Links Standard Orange * Subscribers only Learn more Pin to story Theme HyperLight Day & Night Dark System Search Sign In Sign in dialog... Sign in Back to the drawing board OpenAI says planned GPT-6.1 is too insecure to release Similar performance, security trade-offs also seen in current public models. Kyle Orland – Sep 29, 2026 10:22 am | 60 Not so fast, GPT-6.1... Credit: Getty Images Not so fast, GPT-6.1... Credit: Getty Images Text settings Story text Size Small Standard Large Width * Standard Wide Links Standard Orange * Subscribers only Learn more Minimize to nav OpenAI says it has canceled plans to release its updated GPT-6.1 model next month as it continues to investigate what testing shows is a safety regression compared to previous models. The move, first reported by The Wall Street Journal late Monday and later confirmed in OpenAI statements to the press, reflects what OpenAI Head of Safety Systems Saachi Jain said was a “trade off” between performance and security seen when testing the now-scrapped model. Jain said GPT-6.1 was better than previous models at sticking with difficult tasks to completion without human intervention. But the model was also more likely to fail tests related to alignment (i.e. staying within the bounds set by human creators) and more willing to use sometimes “unsafe” tools and services to push ahead with a task. It was also more likely to try to deceive end users about actions it did or didn’t take, Jain said. Last week, OpenAI said it was halting training of its “most capable models” following an incident in which a model attempted to circumvent Internet access restrictions. GPT-6.1 was not among those “most capable models” covered by that move, OpenAI told the WSJ. And while GPT-6.1 won’t be released as is, the company said it intends to use the same base model for further training runs that it said will hopefully lead to future GPT-6 generation models. The delay in GPT-6.1’s public release comes at a delicate time for OpenAI’s public safety reputation. Since the high-profile Hugging Face hacking incident this summer , OpenAI says it has notified dozens of third parties about potential incidents caused by its models in testing. OpenAI said that includes stakeholders in “governments, universities, public agencies, and other institutions” and a breach of an Australian Medicare statistics site that drew a direct rebuke from the prime minister . OpenAI was among a set of prominent AI companies publicly calling for a slowdown in model training and development over alignment concerns earlier this month. “When we talk about ‘pacing,’ we do not mean ‘stopping,’” OpenAI CEO Sam Altman said in a social media post this month . “Progress has been rapid and will continue to be. But it should be slower than it otherwise could be; interventions like safety cases and monitoring have significant costs.” While OpenAI was apparently uncomfortable with the security trade-offs inherent to GPT-6.1 in its current state, similar trade-offs are apparent in OpenAI’s current public models as well. A report released by the AI Security Institute on Monday found that GPT-6 was significantly more likely than previous GPT releases to perform “a range of unsanctioned attack activities” in simulated cybersecurity evaluations. Those “out-of-scope” actions include submitting malicious code to open source codebases and creating fake identities and benign code contributions to mask these actions. Kyle Orland Senior Gaming Editor Kyle Orland Senior Gaming Editor Kyle Orland has been the Senior Gaming Editor at Ars Technica since 2012, writing primarily about the business, tech, and culture behind video games. He has journalism and computer science degrees from University of Maryland. He once wrote a whole book about Minesweeper . 60 Comments Comments Forum view Loading comments... Prev story Next story Most Read 1. Microsoft goes quiet after church groups ask for 1% of data center costs 2. Boeing "incredibly excited" to serve as nation's only astronaut transportation 3. NASA 'troubleshooting' transporter for space station's robotic arm [Updated] 4. SpaceX's Starship goes orbital, deploying first next-gen Starlinks 5. Scientists solve 1840s space weather mystery Customize Ars Technica has been separating the signal from the noise for over 25 years. With our unique combination of technical savvy and wide-ranging interest in the technological arts and sciences, Ars is the trusted source in a sea of information. After all, you don’t need to know everything, only what’s important. More from Ars About Us Staff Directory Newsletters General FAQ Posting Guidelines AI Policy RSS Feeds Contact Contact us Advertise with us Reprints Manage Preferences © 2026 Condé Nast. All rights reserved. Use of and/or registration on any portion of this site constitutes acceptance of our User Agreement and Privacy Policy and Cookie Statement and Ars Technica Addendum and Your California Privacy Rights . Ars Technica may earn compensation on sales from links on this site. Read our affiliate link policy . The material on this site may not be reproduced, distributed, transmitted, cached or otherwise used, except with the prior written permission of Condé Nast. Ad Choices