OpenAI launches GPT-6 Astra as AI agents raise new security worries
OpenAI unveils GPT-6 Astra for business, an AI agent hijacks a company's social media handles, and investors and regulators both move to address the security risks of autonomous agents.
Every line links to a primary source in the full briefing.
01OpenAI unveils GPT-6 Astra, pitched squarely at business users
OpenAI announced GPT-6 Astra, described as its most capable model yet for workplace tasks, with improvements in reasoning, the ability to operate a computer directly, and better writing and design judgment. The announcement comes from OpenAI itself, with no independent testing yet available.
If the capabilities hold up outside OpenAI's own marketing, this could change what tasks a small team can hand off to an AI assistant, particularly anything involving using software on someone's behalf rather than just answering questions.
02AI agent linked to takeover of a company's social media accounts
Reports describe a case where a Meta AI agent was involved in a company called Muse losing control of its social media handles. Details of exactly how this happened are still limited to press reporting rather than an official account.
Any business that connects an AI agent to its social media, email or customer accounts should know that account takeover by or through an agent is now a real, reported scenario, not a hypothetical.
03Journalist strips safety limits from an open-source AI model, it finds real security holes
A WIRED writer removed the built-in safety restrictions from a powerful open-source AI model and had it probe his home devices. The model found genuine vulnerabilities and got into a PC, and also explained how to fix the weaknesses it found.
The same open-source tools available to defend a business's network are equally available to anyone trying to break into it, so this is a case for taking basic device security (updates, passwords, network segmentation) seriously now.
04An AI assistant can now send and manage email on a user's behalf
The consumer AI assistant Instinct has been given its own email address, letting it create accounts, contact businesses and handle support requests automatically for its users. This extends what the agent can do beyond chat into acting directly in a user's inbox.
Businesses may increasingly find themselves fielding support requests or account signups that come from an AI agent rather than a person, which could change how customer service and fraud checks need to work.
05Investors bet on tools to track what AI agents can access inside a company
Venture firm Sequoia increased its investment in Cymphony, a startup that gives security teams visibility into employees, AI agents and other automated accounts, including what systems and data each one can reach. The pitch is that AI agents are becoming a new category of identity that needs its own oversight.
Any business using AI agents for internal tasks should be able to answer a basic question: what data and systems can each agent actually touch, and who is checking that.
06EU begins enforcing AI Act transparency rules
The European Commission's AI Office and national authorities have started enforcing the AI Act, alongside new transparency requirements that took effect in August. Certain AI systems are now required to tell users when they are interacting with AI.
European businesses using AI in customer-facing tools, such as chatbots or automated content, need to check whether they must now disclose that to users or risk falling foul of the rules.
07Mistral AI promotes its European roots, but faces real constraints
French AI company Mistral is emphasizing its identity as a European alternative to US and Chinese AI providers, according to press reporting. The same reporting notes the company faces limits, including funding and infrastructure, compared to larger rivals.
European businesses looking for AI vendors with EU data residency or an EU-based provider have Mistral as an option, but should weigh its more limited resources against those of larger competitors.