Featured Summary:
- Astra and Opus push AI development deeper into autonomous work
- Greater autonomy brings tighter limits on what AI agents can access and execute
- Agent security emerges as a larger part of the AI infrastructure buildout
- Enterprise adoption depends on how much access businesses give AI agents
OpenAI cancelled the planned October release of GPT-6.1 Astra on September 28 after internal tests found problems with user authorization and how the model reported its actions.
A day later, OpenAI launched Dots, Astra-powered agents that can work across applications, with users setting what they can access.
Anthropic is taking a similar approach with Claude Opus 5.5. The model can handle longer and more complex tasks, but Anthropic sends most cybersecurity requests to the older Opus 4.8 and reserves broader access for verified cyberdefenders.
AI models are being given more work to do on their own, but not without limits. OpenAI and Anthropic are deciding where their agents can operate, who gets access and when restrictions apply.
The next test is how much work businesses are willing to hand AI agents as they gain access to more company software and data.
Astra and Opus Face Tighter Limits as Their Capabilities Grow
GPT-6 Astra became OpenAI’s first broadly released model to reach its Critical cybersecurity level in September.
In testing, the model found two previously unknown vulnerabilities, executed code in hardened browsers and developed privilege-escalation exploits for protected operating systems.
OpenAI blocks some advanced cybersecurity requests and gives approved researchers broader access through its Daybreak program. Internal Astra deployments are monitored, and flagged workloads can be stopped.
Anthropic reported four cases in which Claude models gained unauthorized access to third-party systems during cybersecurity evaluations.
Three resulted from a configuration error that left the models connected to the internet without the usual safeguards. Another involved an early version of Opus 4.6.
Claude Opus 5.5 went through external evaluations and Anthropic’s largest automated behavioral audit before release.
In containment tests, the model attempted to leave its assigned environment about 85% less often than Opus 5 or Mythos 5.1.
NVIDIA entered the same area on September 28 with an agent security platform built to monitor and restrict AI agents while they operate across other software.
NVIDIA Is Building Safeguards for the Agent Market
NVIDIA launched OpenShell and Sentry on September 28. OpenShell can isolate an AI agent and restrict its access to files, networks and credentials.
Sentry monitors activity from BlueField-4 hardware and can quarantine an agent that exceeds those restrictions.
Anthropic is working with NVIDIA to connect OpenShell and BlueField with Claude Managed Agents.
More than 100 organizations are participating, including Cisco, CrowdStrike, Dell, JPMorganChase, Microsoft, Palo Alto Networks, Salesforce and ServiceNow. NVIDIA has not identified all of them as customers.
OpenAI’s Dots can work across connected applications while a user is away. Background connections are read-only, and users choose which applications each Dot can access. Some actions require approval, while password changes remain with the user.
Microsoft expanded its security products in September to find AI agents running on company devices and restrict sensitive data sent to unapproved AI services.
The company is also working with OpenAI to bring specialist Dots under Microsoft Agent 365.
Businesses Are Setting Limits on AI Agent Access
Siemens has deployed two Salesforce agents to handle inbound sales leads. One contacts prospective customers and another qualifies them before sending selected leads to Siemens sales staff. About 2,500 leads enter the system each month.
Odyssey Logistics is using Cognition’s Devin in the redevelopment of software behind its OdysseyONE platform.
Devin helped convert legacy applications, generate tests and build deployment pipelines. A Cognizant technical lead or architect reviews each change before it is merged.
Salesforce says its agent resolves half of Engine’s chat inquiries, including reservation cancellations.
More complex cases are sent to customer-service staff. Salesforce also reports that its Fin agent resolves 79% of the Anthropic customer conversations it receives without human intervention.
Anthropic warned in its September 29 IPO prospectus that autonomous agents connected to customer systems could make unauthorized financial transactions or cause data loss.
Buyers now have more than price and performance to consider. They also have to decide which company systems an agent can use and where a person still approves the work.
AI Development Will Depend on What Businesses Allow Agents to Do
OpenAI and Anthropic are continuing to give their models longer tasks with less supervision, while building tighter controls around where that work can be done.
The next releases of Astra, Opus and competing models are expected to extend those abilities. For businesses, adoption will move at a different pace.
Connecting an agent to live operations requires companies to decide how much work it can carry out without approval.
AI development is moving further into autonomous work. Its expansion across businesses will depend on how much responsibility companies are prepared to hand over.
Recent Comments