GPT-6 Astra is out

OpenAI released GPT-6 Astra, built around computer use: the model works inside browsers, spreadsheets, and desktop apps to fill out forms, update records, do research, build websites, and test applications. Rollout is staged: enterprises first via the Trusted Access Program, with the API and ChatGPT Plus, Pro, Business, and Enterprise following within days, plus availability on AWS. API pricing is $10 per million input tokens and $50 per million output, with a 1.05M-token context window (see the official model and pricing page). Greg Brockman said “welcome to the AGI era”; file that under his personal view. The real news from this launch sits in the safety evaluation, next item.

Safety evaluation: cyber capability reaches “Critical” for the first time

OpenAI’s system card says it in plain words: Astra is its first model to reach the Critical level of cybersecurity capability under the Preparedness Framework (see the system card). Critical roughly means the model can find and build working zero-day exploits, meaning attack code for vulnerabilities the vendor doesn’t yet know about and has no patch for, against hardened real-world systems without human help, or plan and execute a novel end-to-end attack from nothing but a high-level goal. Mitigations include encrypted model weights with tighter access controls, monitoring of full trajectories including chain of thought, and gating advanced cyber workflows behind a small alpha group before wider defensive access through Daybreak Blue. Until today the top tier of that framework existed only on paper; now a model on its way to broad deployment, enterprises first and ChatGPT within days, has triggered it, and the governance commitments can finally be checked against facts.

Daybreak for Frontline Defenders: $1B for the defense side

The same day, OpenAI committed $1 billion to subsidized model access, training, and technical support for US essential-service operators: water utilities, grid operators, state and local governments, community banks, nonprofits, and open-source maintainers, starting with a pilot with MS-ISAC, the cybersecurity collaboration body for state and local governments, and expanding to partner countries in the coming weeks. OpenAI’s own forecast is that AI-enabled attacks will get far more widespread and sophisticated in the coming months. Read this together with the previous item: a model at the Critical cyber tier is shipping, and the open variable is how fast defenders adopt. Note that access is subsidized, not free.

ARC-AGI-3: 62.7% or 99.9%, depending on the harness

ARC Prize independently tested Astra on ARC-AGI-3, an interactive benchmark of game-like environments with no instructions, where the agent has to explore, infer the rules, and set its own goals. With the standard harness (the execution layer that decides how the model observes the screen and takes actions), Astra scored 62.7% at a cost of $26,098; with a provider-supplied adapter harness, 99.9%. If you see 98.6% quoted, that is the same adapter harness at its maximum reasoning setting; either way, the headline numbers come from the adapter, not the standard harness. ARC’s own caveat: saturating this benchmark would not be proof of AGI. For eval builders this is an extreme data point on harness sensitivity: between 62.7 and 99.9, the model didn’t change, only the scaffolding did.

Nvidia confirms $12.93B Hugging Face acquisition

The rumor is now official: Nvidia is acquiring Hugging Face, and Clem Delangue put the exact figure at $12,930,300,000 (see his post on X). Nvidia commits to keeping the platform open, multi-cloud, and not tied to its own compute, with the 🤗 brand intact and, per CNBC, all three founders joining Nvidia. The promises are in the announcement; the test comes after closing. Hugging Face hosts more than 3 million models and 500K datasets. Its neutrality used to rest on independence; from here on it rests on the acquirer’s restraint.

Abliteration.ai turns guardrail removal into a business

Startup Abliteration.AI commercializes what used to be a hobbyist technique: abliteration locates and removes the “refusal direction” in a model’s weights so the model stops declining requests. It now serves abliterated builds of open-weight models, including Z.ai’s GLM-5.3, via web and API, and says it has deals with major cloud providers. The pitch is “Unrestricted. Not ungoverned.”: content policy moves from the model layer to the developer. The missing piece is verification: per TechCrunch, customer vetting amounts to a credit card on file, and under that condition “developers set the policy” is close to having no policy layer at all. Red teams and defense researchers genuinely need unrestricted models; what changed is the bar for getting one, which is now a checkout page.

Meta offers up to ~95% off Muse Spark in exchange for your data

Meta’s Muse Spark 1.3, aimed at coding and agent workloads, now has a “contributor” tier: opt in to letting Meta collect your prompts and model outputs to train future models, and input pricing drops from $1.25 to $0.10 per million tokens, output from $4.25 to $0.20, roughly 95% off at the top end. There is no standalone announcement that I could find; the terms live in Meta’s pricing documentation. This puts a public price tag on usage data. Princeton’s Arvind Narayanan notes that enterprises usually pay extra for data protection; once the subsidy is explicit, some of them will re-run that math.

Thinking Machines reportedly raising $1B at a $40B valuation

Per The Information (neither Accel nor the company immediately responded to comment requests), Accel is in talks to lead a $1B round for Mira Murati’s Thinking Machines at a $40B valuation, up from $12B at its $2B seed round. A source with knowledge of the financials puts annual revenue run rate above $100M, which still makes this a several-hundred-fold revenue multiple: frontier-model valuations remain option pricing, a long way from cash-flow pricing.

DeepMind ships WeatherNext 3

DeepMind’s new global weather model raises resolution on key surface variables from 25 km to 5 km, updates hourly instead of every six hours, and ingests geostationary satellite observations directly, removing the roughly 6-hour lag of pipelines initialized from traditional numerical forecasts. Precipitation forecasts improve by up to 60% on the CRPS error metric against the IMERG satellite baseline. It goes straight into products: Google Search, the Gemini app, Maps and its Weather API, with researcher access via BigQuery and Earth Engine. Of all the AI-for-science threads, this is the one closest to daily life.

Old news, newly hot: Shin Jin-seo beats KataGo with a two-stone handicap

This lit up Hacker News today, but it happened in July: world No. 1 Shin Jin-seo, 9-dan, beat KataGo 2-1 in a three-game series while taking a two-stone handicap (July 17 to 21, Seoul). Check the configuration before the headline: KataGo was capped at 20 seconds per move with pondering disabled, running on four RTX 3090s, while Shin had five hours (time and hardware per KED’s game-two coverage, pondering setting per the KataGo project’s discussion). The reading among Go professionals quoted in that KataGo thread, which I share, is that a top human can still contend with a two-stone-handicapped AI under tight time settings, not that AI superiority has reversed. The useful reminder: claims like “AI is far beyond humans” are bound to a specific configuration, and changing the time budget can change the conclusion.

Research radar

Repo-To-Skill: Distilling GitHub Repositories Into AI4AI Skills

Names a real gap for research agents: models know the method but not how to get it running in a specific environment, and that operational know-how sits in repos and papers without being explicitly modeled. The authors’ DisCo system distills 1,000 widely used ML repos into 5,000+ verified reusable skills; holding the GPT-5.5 backbone and execution budget fixed, the skill-equipped agent gains 134.3% on MLE-bench. Worth a close read if you build ML agents or agent skill and memory layers.

Language Models Can Control Their Own Attention

A pure inference-time protocol, no training: the model declares in its chain of thought, like a tool call, whether it needs full context, a specific region, or only recent output, and the inference engine skips most KV-cache reads accordingly. Off-the-shelf models handle it zero-shot, cutting attended tokens by 31% to 52% depending on the model, across 15 long-context tasks, at a cost of 1 to 3 accuracy points that shrinks with model scale. If you work on long-context inference cost, the interesting move is handing control to the model itself instead of an external scoring proxy.

Improving Evaluation Realism with Inference-Time Compute and Deployment Scaffolds

A core source of distortion in alignment evals is the model recognizing it is being tested and behaving differently (evaluation awareness). This paper offers two usable levers: spend inference-time compute refining each simulated action until it reads like real deployment, and wrap the target model in a deployment-imitating SWE-agent harness. The two compose, and use compute better than simply making audits longer. Directly borrowable if you run safety evaluations.

Today in one sentence: OpenAI said two things on the same day: our model has hit the highest cyber risk tier in our own framework, and here is $1 billion for defenders. The first is a capability fact; the second is a race against OpenAI’s own forecast that AI-enabled attacks will get far more widespread and sophisticated in the coming months.