Recipes Safety 8 min Updated Sep 30, 2026

Safety, sign-in, and data

OpenAI describes GPT-6 Astra’s scope, secure sign-in, training controls, and read-only proactive research.

This guide restates safety, sign-in, and data material on How we build safety, security, and privacy into dots, plus the matching read-only proactive-research sentence on Introducing dots. It is not a tutorial for attacks.

How OpenAI describes GPT-6 Astra

On How we build safety, security, and privacy into dots, OpenAI says GPT-6 Astra is trained to understand intent, stay in scope, ask when the answer would change what it should do, and refuse harmful requests including biological or cybersecurity misuse.

This page does not expand those refusal categories into a misuse guide.

Prompt injection, as OpenAI names it

On How we build safety, security, and privacy into dots, OpenAI names prompt injection: a webpage, email, or document can contain malicious instructions.

On that safety post, OpenAI says it combines model safeguards, tool restrictions, checks before actions, and monitoring.

This page does not add payload examples.

Secure sign-in

On How we build safety, security, and privacy into dots, OpenAI says that for supported sign-ins the model is paused while you complete a secure login form.

On that safety post, OpenAI says credentials go to the browser environment and are not exposed to the model.

On that safety post, OpenAI says saved-password flows use a dedicated encrypted credential service that supplies the password without passing it to the model.

On that safety post, OpenAI says a secret placed in a readable message or document may still be visible to the model. That limit is part of the official description.

Training controls

On How we build safety, security, and privacy into dots, OpenAI says Business, Enterprise, and Edu workspace content is not used to improve models by default.

On that safety post, OpenAI says that on personal plans, “Improve the model for everyone” controls whether dots’ conversations and work are used.

On that safety post, OpenAI says that when training is enabled this can include actions and automations after personal identifiers are removed.

On that safety post, OpenAI says it does not train directly on proactive research or the dot’s notes to itself.

On that safety post, OpenAI says that if a note is brought into an eligible conversation or task, that brought-in information may be used depending on settings.

OpenAI’s own example on that safety post is a Lisbon trip. This page uses only that official example and does not invent others.

Proactive research stays read-only

On How we build safety, security, and privacy into dots, OpenAI says proactive research is background work that uses read-only tools.

On that safety post, OpenAI says it cannot directly send messages, change connected-app content, or control a browser or desktop.

On that safety post, OpenAI says those limits are enforced in code.

On that safety post, OpenAI says follow-up actions still go through the usual rules.

Introducing dots says the same read-only limit: the dot cannot send messages, change app content, or control the browser or computer in that mode.

What this page does not add

This page does not invent extra training menus or attack recipes. For Activity View and confirmations, see Staying in control of a dot. For Auto-review, see Auto-review and approvals.