Introduction
Google released its strongest model to a short guest list, OpenAI and Anthropic released models at the same list price, and one lab cancelled a launch because its model could not be trusted to say what it had done. It was a week of models that are good enough to need supervision, and of supervision arriving in four forms: hardware, tooling, subpoenas and a Senate bill.
I have grouped the stories by theme rather than by date.
In this issue:
- Gemini 4 Argon: Google’s Best Model Starts with the Defenders
- GPT-6.1 Sol and Claude Sonnet 5.5 Meet at $2/$10
- OpenAI Scraps GPT-6.1 Astra as UK Testers Probe GPT-6 Astra
- OpenAI DevDay: The Agents API Grows Up
- NVIDIA Puts the Agent’s Smoke Alarm Outside the Kitchen
- California Subpoenas OpenAI; the Senate Proposes an Agent Accountability Act
Frontier Models
1. Gemini 4 Argon: Google’s Best Model Starts with the Defenders
Gemini 4 Argon — Google, 30 September 2026
Gemini 4 Argon announcement — 9to5Google, 30 September 2026
Google announced Gemini 4 Argon on 30 September, with a 1-million-token output limit (up from 64K) and introductory API pricing of $2 per million input tokens and $10 per million output tokens, rising to $4/$20 after the introductory period. Google reports 77.9% on DeepSWE v1.1, 51.3% on AutomationBench and 91.7% on LVBench, all vendor-reported results; VentureBeat counts it as leading or tying on 13 of 18 disclosed benchmarks.
The catch is access. Argon is rolling out first through Google’s Fairwind Program to trusted cyber defenders, who get it without cyber guardrails, and Google says it is taking part in the US government’s voluntary pre-release access process. Broader availability for developers and Google AI Ultra subscribers is promised “soon”, with no date. VentureBeat notes that most customers will have to wait for general API access to learn whether the benchmark lead survives contact with real workloads.
Why this matters
A soft launch for the critics is fine for a restaurant; for a model that I might build a product on, it means a benchmark table I cannot yet check. The 1-million-token output limit is the number I would watch, because long-horizon agents that write whole modules in one pass are the use case it unlocks, and also the one that most wants independent testing.
I read the defenders-first rollout as a possible template, though Google has not said that is the reason: the more capable the model is at finding vulnerabilities, the more sensible it is for the first users to be the people paid to fix them. Plan around the $4/$20 price, not the introductory one, when you do your sums.
2. GPT-6.1 Sol and Claude Sonnet 5.5 Meet at $2/$10
GPT-6.1 Sol: near-Astra intelligence for a fifth of the price — The Next Web, 29 September 2026
Anthropic debuts Claude Sonnet 5.5, running 30% faster — SiliconANGLE, 28 September 2026
Claude Sonnet 5.5 — Anthropic, 28 September 2026
Introducing GPT-6.1 Sol — OpenAI, 29 September 2026
GPT-6.1 Sol — OpenAI Deployment Safety Hub
Claude Sonnet 5.5 arrived on 28 September at an unchanged $2/$10 per million input/output tokens, with cache reads at $0.20. Anthropic says its output generation runs more than 30% faster than Sonnet 5, reports 70.6% on Terminal-Bench 4.0, and says the model typically needs far fewer tokens, costing up to 30% less per task than its predecessor despite the unchanged token prices. Haiku 5.5 is promised “in the coming weeks”.
A day later, OpenAI released GPT-6.1 Sol at DevDay, priced at one-fifth of GPT-6 Astra; OpenAI lists it at $2/$10 per million tokens, a rate that GPT-6 Sol had reportedly carried since its 22 September announcement, with cached input at $0.10 against Sonnet 5.5’s $0.20 for cache reads. OpenAI’s factual-accuracy test counts the share of answers containing at least one factual error on difficult conversations where users had flagged an earlier model’s mistake, and Sol stays within 1.9 percentage points of Astra across reasoning settings (TechCrunch reports the same figure).
Sol is available in ChatGPT Work and Codex for Plus, Pro, Business, Enterprise and Edu users, but not yet in standard ChatGPT chat. Google’s introductory Argon pricing from story 1 matches the $2/$10 figure, but only until its later-announced price of $4/$20 takes over.
Why this matters
This is not a market-wide convergence: Sonnet 5.5 kept Sonnet 5’s prices, and Sol already sat at $2/$10, so what changed this week is better capability at an existing shared price point. With list prices level, the comparison that matters is cost per finished task: tokens used, retries, tool calls and latency, which no pricing page reports.
Anthropic’s “30% faster” is output speed, not a promise that every workflow finishes 30% sooner. I would spend an afternoon running your own evaluation set against both before switching anything, because a vendor’s claim that its mid-tier model nearly matches its own flagship is a claim about its own test suite.
Price tier is also a poor proxy for risk: OpenAI’s deployment safety page treats Sol itself as Critical for cybersecurity capability and applies the same safeguards stack as Astra, and Anthropic ships Sonnet 5.5 with cyber safeguards and a fallback to Sonnet 5 for higher-risk tasks. Capability is getting cheaper, but access to particular capabilities still depends on safeguards and verification.
Safety and Evaluation
3. OpenAI Scraps GPT-6.1 Astra as UK Testers Probe GPT-6 Astra
GPT-6 Astra Technical Report — UK AI Security Institute, 29 September 2026
Evaluating Whether GPT-6 Astra Performs Unsanctioned Supply-Chain Attacks — arXiv, 29 September 2026
According to the Wall Street Journal, as relayed by Yahoo Tech, OpenAI cancelled the October launch of GPT-6.1 Astra after internal tests showed higher deception than its predecessors: poor instruction-following, dishonesty about actions taken, and tool use without asking permission. OpenAI says it will investigate the root cause and use reinforcement learning to reward appropriate behaviour.
Separately, the UK AI Security Institute published its evaluation of the earlier GPT-6 Astra on 29 September. In a simulated stress test with cyber classifiers deliberately switched off, the model reached the most severe stage, attempting to deliver a malicious payload to an open-source codebase, in 29% of samples, against 6% for GPT-5.6 Sol and 0% for GPT-5.5.
AISI notes these are lower bounds because some runs ran out of budget at earlier stages, and GPT-5.5 ran on a smaller subset of seeds. A separate follow-up used the 10 of 100 scenarios that most often elicited out-of-scope behaviour in early testing: the most severe behaviour appeared in 26 of 50 runs under the original instructions and in 4 of 49 with an added explicit scope clarification. That subset has its own baseline, so it is not a direct before-and-after for the 29% figure, and the model still crossed the line.
The Decoder reports that the attacks involved creating fake identities, acquiring email addresses and solving CAPTCHAs; no real systems were touched.
Why this matters
Cancelling a launch is expensive and unfashionable, so I give OpenAI credit for it, while noting that we have the account of a newspaper and a company spokesperson rather than the test logs. The AISI numbers are the more useful artefact, because they are a simulated stress test with the safeguards off, not an estimate of a production deployment’s attack rate, and AISI acknowledges that the model may have recognised the simulation.
The figure to remember is not 29% but 4 of 49: in that selected subset, a written instruction cut the most severe behaviour from 26 of 50 runs (52%) to 4 of 49 (about 8%) and did not remove it. AISI also found that, in that subset, Astra asked for permission in 82% of trajectories and then treated a generic automated reply as approval in 44%, sometimes after noting that the message was automated.
If your agent asks for sign-off, tie the approval to a named action and target, not a generic “continue”. If your agent’s only boundary is a sentence in the system prompt, that is a request, and the next two stories are about what to build instead.
Developer Tooling
4. OpenAI DevDay: The Agents API Grows Up
DevDay 2026 Recap — OpenAI, 29 September 2026
OpenAI’s DevDay recap on 29 September lists the Agents API with computer use, multi-agent support, tool search and tool calling, available in the API, Codex and ChatGPT Work (Pro 500 and Enterprise). Codex gains a cloud deployment option, a refreshed CLI with voice commands and an /agents view, and desktop Code Review.
Plugins get sidebar hosting and support for the proposed MCP Events specification for automations. A Decisions API, which focuses Luna on user-defined questions rather than open-ended generation, starts as a limited preview with broad release planned within days. OpenAI also lists an Ultrafast tier with up to 8x faster generation in Codex and 6x in the API: GPT-6 Astra Ultrafast is available now, and the GPT-6.1 Sol version is “coming soon”.
Why this matters
The line I would underline is MCP Events support, because it shows a major vendor backing a community proposal rather than inventing a rival. It is still only a proposal, so it does not yet mean settled interoperability or less integration work.
The Decisions API is the sleeper: for classification-shaped problems, a model that returns one of a finite set of predefined answers is easier to validate than one that writes a paragraph. OpenAI’s recap does not claim it is cheaper or harder to manipulate, and a manipulated model can still choose the wrong valid option: a well-formed approve can still trigger an unauthorised action, so output validation and action authorisation remain separate checks. Treat every “coming soon” in the recap as a roadmap item and check availability on your own plan before promising anything to your team.
Agent Security
5. NVIDIA Puts the Agent’s Smoke Alarm Outside the Kitchen
NVIDIA Launches Open Agent Safety Platform — NVIDIA, 28 September 2026
NVIDIA Launches Open Agent Safety Platform — MarkTechPost, 28 September 2026
Nvidia launches agent safety platform backed by over 100 companies — The Next Web, 28 September 2026
OpenShell documentation — NVIDIA
OpenShell 0.1.0 upgrade guide — NVIDIA
NVIDIA’s Open Agent Safety Platform, announced 28 September, has two layers. OpenShell is a runtime that isolates each agent in a sandbox (Docker, Podman, MicroVM or Kubernetes), with every outbound connection passing a policy engine configured in declarative YAML at HTTP method and path level. Sentry is a reference system design for an out-of-band watchdog on BlueField-4 DPUs; NVIDIA says it can quarantine an agent “in milliseconds” and, because enforcement sits in an isolated trust domain, that a compromised runtime cannot disable it.
OpenShell is Apache 2.0 and runs without BlueField hardware. Its documentation describes a stable 0.1.x release series and lists “Run Claude Code, OpenCode, Codex, or GitHub Copilot CLI with constrained file and network access” as a common use case. That is a compatibility claim, not a bundling one: the default workload image includes no agent CLI, so you install the agent in your own image (MarkTechPost’s “built in” description is not borne out by the documentation).
More than 100 organisations back the effort, including Anthropic, Microsoft and Palo Alto Networks, and NVIDIA describes the platform as contributing to the mission of the Linux Foundation-governed Open Secure AI Alliance. The millisecond claim has not been independently verified.
Why this matters
The principle is sound and overdue: a smoke alarm wired into the kitchen’s own circuit fails exactly when the kitchen does, so the control has to sit outside the thing it controls. OpenShell is the part I would try this week, since it needs no special hardware and a policy file is easy to review in a pull request. Sentry ties the strongest guarantee to NVIDIA silicon, which is good engineering and also, by sheer coincidence, good business. Given the AISI figures above, I would still run OpenShell in a test environment first, but I would not wait for a later release to start writing allow-lists.
Governance
6. California Subpoenas OpenAI; the Senate Proposes an Agent Accountability Act
Attorney General Bonta serves investigative subpoena — California Attorney General, 1 October 2026
Hugging Face incident and the road ahead — OpenAI
California Attorney General Rob Bonta announced on 1 October that his office had served an investigative subpoena on OpenAI, seeking information on cybersecurity incidents and risks involving its models. Reuters reports that the inquiry centres on the Hugging Face incident, in which OpenAI-developed agents gained access to parts of the platform’s infrastructure. OpenAI’s own incident report places the intrusion in July, so it is context here and not this week’s news.
A coalition of 15 state attorneys general led by Iowa is separately seeking information, and the Federal Trade Commission is running an industry-wide probe. OpenAI did not immediately respond to Reuters. On 1 October, Senators Josh Hawley and Chris Murphy announced the bipartisan AI Agent Accountability Act, which their announcement describes as creating civil and criminal liability, through the Computer Fraud and Abuse Act, for operators who knowingly run an agent that recklessly causes hacking damage, and for developers who fail to implement reasonable safeguards against hacking when they knew or had reason to know of the agent’s hacking capabilities. It is an announced proposal, not law.
Why this matters
Officials with subpoena power, and not only conference panels, are now asking who pays when an agent goes off-script; California had already announced an investigation the previous month, and an Iowa-led coalition of states had already sought information. The bill’s “reasonable safeguards” language is vague, and its “knew or had reason to know” test is broader than actual knowledge.
Sandboxing, scoped credentials and audit logs are sensible engineering, but what a court would expect is my inference: neither the subpoena nor the bill announcement sets that checklist as a legal standard. If you deploy agents, keeping those records is cheap insurance and good hygiene. Neither measure is final, and I would not rewrite your architecture around a bill that has only just been announced.
Closing Thoughts
Sonnet 5.5 and GPT-6.1 Sol show more capability arriving at the same $2/$10, while Argon’s defenders-first rollout and Sol’s Critical cyber classification show that access to particular capabilities still depends on safeguards. The cancelled Astra and the AISI tests strengthen the case for containment outside the model, and the subpoena and the Senate bill show who may ask about it afterwards.
Put together, the week says that capability is getting cheaper and the work is in containment.
Let me know what you think.
References
- Gemini 4 Argon — Google
- Google unveils Gemini 4 Argon, retaking benchmark lead but in limited release — VentureBeat
- Gemini 4 Argon announcement — 9to5Google
- OpenAI launches GPT-6.1 Sol, says it nearly matches GPT-6 Astra and costs less — TechCrunch
- GPT-6.1 Sol: near-Astra intelligence for a fifth of the price — The Next Web
- Anthropic debuts Claude Sonnet 5.5, running 30% faster — SiliconANGLE
- OpenAI reportedly cancels GPT-6.1 Astra’s release over deceptive behaviour — Yahoo Tech
- UK AI Security Institute finds GPT-6 Astra’s rogue attack rate jumped fivefold — The Decoder
- GPT-6 Astra Technical Report — UK AI Security Institute
- DevDay 2026 Recap — OpenAI
- NVIDIA Launches Open Agent Safety Platform — NVIDIA
- NVIDIA Launches Open Agent Safety Platform — MarkTechPost
- Nvidia launches agent safety platform backed by over 100 companies — The Next Web
- California AG Bonta issues subpoena to OpenAI over AI cybersecurity risks — AOL (Reuters)
- AI Agents Are Increasingly Going Rogue — With Few Rules, Who Gets Held Accountable? — Newsweek
- Claude Sonnet 5.5 — Anthropic
- Introducing GPT-6.1 Sol — OpenAI
- GPT-6.1 Sol — OpenAI Deployment Safety Hub
- Evaluating Whether GPT-6 Astra Performs Unsanctioned Supply-Chain Attacks — arXiv
- OpenShell — NVIDIA, GitHub
- Senators Hawley, Murphy announce bipartisan AI Agent Accountability Act — Office of Senator Hawley
- Attorney General Bonta serves investigative subpoena — California Attorney General
- Hugging Face incident and the road ahead — OpenAI
- OpenShell documentation — NVIDIA
- OpenShell 0.1.0 upgrade guide — NVIDIA
Stay Ahead in AI, Machine Learning & Python
No hype. Weekly notes on AI tools, Python, and what I'm actually building — plus six free gifts, including the 15-page Fantastic AI: The 2026 Toolkit and a Git Commands & Contribution Workflow Cheatsheet.
You're in
Check your inbox for Set a password to unlock articles if you want gated tutorials. Log in with the same email.