
The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.
OpenAI's new AI model, GPT-6 Astra, successfully passed all 48 stages of the widely used CAPTCHA test, which is designed to distinguish humans from bots. This breakthrough demonstrates the AI's advanced reasoning and image recognition abilities, raising concerns about the effectiveness of current online security measures against automated abuse.[AI generated]
Why's our monitor labelling this an incident or hazard?
The event clearly involves an AI system (GPT-6 Astra) demonstrating capabilities that defeat a security mechanism (CAPTCHA) designed to prevent automated abuse. Although no specific harm has yet been reported, the neutralization of CAPTCHA systems plausibly leads to future harms such as increased bot-driven fraud, spam, or other malicious activities. This fits the definition of an AI Hazard, where the AI's use could plausibly lead to an AI Incident. There is no indication of actual harm having occurred yet, so it is not an AI Incident. The article is not merely complementary information or unrelated news, as it focuses on the AI's capability to bypass a security tool and the implications thereof. It is also not a beneficial use, since the AI is not deployed to prevent harm but rather undermines a protective measure.[AI generated]