Saturday, 12 September 2026
ZAR/USDR16.160.06%. Rand weaker against the US dollar
ZAR/EURR18.730.13%. Rand stronger against the euro
ZAR/GBPR21.830.00%. Rand flat against the pound
Tech & Telco

OpenAI’s newest model can find security holes nobody has found yet. That is exactly why South African firms should be paying attention

OpenAI’s newest model can find security holes nobody has found yet. That is exactly why South African firms should be paying attention

A model that can open your accounting software, click through the menus, and reconcile an invoice the way your bookkeeper does on a Tuesday afternoon. A model that, under the right conditions, can also find a security flaw nobody has found yet and work out how to exploit it, without a person walking it through the steps. Both of those are the same product, released in the same week, and neither has had a proper local write-up explaining what it means for a business here rather than a research lab in California.

On 3 September 2026, OpenAI released GPT-6 Astra, its newest and most capable model. OpenAI president Greg Brockman described it as a model that can “zip through spreadsheets, fill out forms, and navigate across web pages often at superhuman speed,” and said it was “not unreasonable to feel that we are now in the AGI era”, AGI being artificial general intelligence, the industry’s term for a system that can perform most cognitive tasks at or beyond human level. That is Brockman’s own framing of his company’s product, not an independent assessment, and it is worth reading in that light.

The rollout started with a limited release to enterprise customers and cybersecurity partners in OpenAI’s Daybreak programme, before opening to ChatGPT Plus, Pro, Business and Enterprise users, and separately through the OpenAI API and Amazon Web Services.

The part that should get more attention than the AGI talk

Buried under the computer use headline is a more concrete, independently verifiable fact. GPT-6 Astra is the first model to cross what OpenAI calls the Critical threshold for cybersecurity capability under its own Preparedness Framework, a scale the company uses to grade how dangerous a model’s capabilities are across categories including cybersecurity, running from Low to Critical.

Crossing that line means, in OpenAI’s own words, that the model can find and exploit previously unknown security flaws in many well protected systems without a person guiding each step, what the security industry calls a zero day, a vulnerability nobody has patched yet because nobody has found it yet. Reaching that capability triggered OpenAI’s own additional safeguards: most users get a restricted version of the model that declines advanced offensive cybersecurity requests, rather than the full capability.

That restriction is the honest, load bearing sentence in the whole announcement, and it deserves to be read carefully. A capability line was crossed, and the response was to restrict access to it, which is itself confirmation that the capability is real enough to need restricting.

Why this matters here, not just there

South African companies are not spectators in this. The country already carries an outsized exposure to cybercrime relative to its economic weight, a pattern security researchers have flagged for years and one this site has covered in the context of organised crime more broadly. A tool that can discover and weaponise unknown vulnerabilities without human oversight raises the ceiling on what a well resourced attacker, state or criminal, can do to a target that has not kept its defences current. A restricted public version does not remove that ceiling. It only says OpenAI is not the one making it freely available.

The more immediate, less dramatic risk for a local business is not a nation state actor. It is the ordinary attacker who now has cheaper access to sophistication that used to require an actual specialist, wherever the underlying capability eventually surfaces in a less restricted form, whether through OpenAI’s own products elsewhere in the world, through open alternatives catching up, or simply through the industry norm shifting. Security budgets that were sized for last year’s threat model are being priced against this year’s tools, and the gap between the two does not close on its own.

The other half of the story: an assistant that can actually drive your computer

Separate from the security classification, the computer use capability is the one with the more direct day to day business relevance. Rather than answering a question in a chat window, an agent with computer use can carry out a multi step task across a real interface: opening an application, filling in a form, moving between browser tabs, the way a human employee would.

For a South African business the honest framing is opportunity and disruption arriving in the same box. The immediate opportunity is in back office and administrative work: the repetitive, rules based tasks that involve moving data between systems that do not talk to each other, which is a large share of what junior administrative staff spend their day doing. The disruption is that this is precisely the category of entry level, first job work that has historically given young South Africans their start in formal employment, in call centres, in administration, in data capture.

That tension is not new to this specific release. McKinsey’s research on the future of work in South Africa has estimated that digitisation and automation could displace roughly 3.3 million existing jobs by 2030 while creating up to 4.5 million new ones, a net gain of up to 1.2 million, with manufacturing and administrative roles among the most exposed on the displacement side, and call centre and business process outsourcing work identified as a particular pressure point because of how many young people use it as an entry point into the formal economy. A single model release does not change that trajectory on its own. It is one more data point confirming the trajectory analysts have already been describing, arriving faster than most local employers have finished planning for the version that came before it.

This is the second frontier AI release this site has covered in a week. The other, Anthropic’s Claude Fable 5.1, is a cost story rather than a capability one, and read alongside South Africa’s own delayed national AI policy, withdrawn after its first draft cited research that does not exist, the three stories together describe a country adopting frontier AI faster than it is regulating it. For a starting point on using these tools without the risk outrunning the benefit, see our practical guide to AI tools for small business.

What a business here should actually do with this

Treat the Critical cybersecurity classification as a signal to review, not to panic over. If your incident response plan or your vendor security questionnaires were last updated more than a year ago, this is a reasonable prompt to check whether they still assume yesterday’s attacker sophistication. If your business handles personal information in a way covered by the Protection of Personal Information Act, an AI agent with the ability to autonomously navigate your systems is a new category of question for your own data governance, not an academic one: who has agreed that an agent can act inside your systems, what it is allowed to touch, and how that access is logged.

On the computer use side, the practical starting point is smaller than the AGI framing suggests. Look at the specific repetitive, multi system administrative tasks your business already struggles to staff or keep consistent, and treat this release as evidence that the tooling to automate parts of that work is arriving faster than expected, not as a reason to make a sweeping decision about headcount before a single local vendor has actually shipped something built on it.

This report is based on a statement available at fortune.com.