# Report details GPT-6 Astra prompt-injection limits

_Friday, September 4, 2026 at 1:23 PM EDT · AI, Security · Latest · Tier 2 — Notable_

![Report details GPT-6 Astra prompt-injection limits — Primary](https://the-decoder.com/wp-content/uploads/2025/11/openai_logo_wall-3.png)

GPT-6 Astra blocked 99.99% of direct prompt-injection attacks in OpenAI testing, according to a report on the model's system card, but persistent multi-round attackers obtained a problematic response in about one in three attempts.

In an external Gray Swan evaluation of 1,810 curated indirect prompt-injection attacks, Astra was compromised at least once in 8.5% of scenarios with 15 attempts, down from 27% for GPT-5.6 Sol. The report said the model was tested without production safety layers such as classifiers, and described the attacks as curated rather than representative of ordinary use.

## Sources

- [the-decoder.com](https://the-decoder.com/openais-gpt-6-astra-hallucinates-less-but-remains-vulnerable-to-hidden-prompt-injections/)

---
Canonical: https://techandbusiness.org/newswire/-oKssQP33xKD3ppK_8A_VX
Retrieved: 2026-09-05T21:50:26.902Z
Publisher: Tech & Business (techandbusiness.org)
