
Six days in late September and early October 2026 produced probably the densest single-week drop of the AI cycle — and the GPT-6.1 Sol launch sits at the center of it. At DevDay on September 29, OpenAI shipped the GPT-6.1 Sol mid-cycle model refresh, launched a new always-on agent product called dots, and introduced a $500-per-month ChatGPT plan — while cutting the usage allowance on its old $200 tier. Two days later, on September 30, the company published a security post describing a disrupted, coordinated model-distillation campaign, with a core cluster of the activity attributed to individuals associated with Moonshot AI, the developer of Kimi.
Read one headline per story and this looks like a normal launch week. It isn’t. All four moves make one argument: agents you subscribe to by the job, and models as a defended corporate perimeter. Here’s the package, piece by piece — starting with what GPT-6.1 Sol actually changes.
If you’re weighing the two for agentic coding work, see how GPT-6.1 Sol stacks up against Claude Sonnet 5.5 in our head-to-head comparison.
One week, three launches — what OpenAI actually shipped
The timeline matters. OpenAI’s DevDay recap describes its “biggest yet,” with “more than 20 major announcements” — opening ChatGPT as “a shared surface where humans and agents can collaborate” for its “collective 1.2B weekly users,” plus a premium speed tier called Ultrafast. Everything in the keynote dropped at once — and the usage allowance on the existing $200 Pro plan went down the same day a tier two and a half times as expensive went up. The security post followed the next day.
A naming note, since it’s easy to trip over: GPT-6 Sol launched September 22; the GPT-6.1 Sol covered here is the refresh that shipped one week later — different model, different pricing. GPT-6 Astra remains OpenAI’s most powerful model.
GPT-6.1 Sol: a mid-cycle refresh, and why labs now do these
OpenAI’s announcement post is titled, pointedly, “Near-Astra intelligence for a fifth of the price.” That’s the pitch: GPT-6.1 Sol “nearly matches GPT-6 Astra’s intelligence on agentic coding, computer use, and professional work at one-fifth of Astra’s standard input and output token prices.”
A week is an unusually short runway for a successor to a flagship-tier model — but compress a frontier model and reposition it as the cheap workhorse is now the industry’s most commercially important cadence. The GPT-6.1 Sol API pricing:
| GPT-6.1 Sol (API) | Price |
|---|---|
| Input | $2 per million tokens |
| Cached input | $0.10 per million tokens |
| Output | $10 per million tokens |
The cached-input number is the aggressive one: per OpenAI’s post, “95% less than standard input pricing and 50% less than GPT-6 Sol’s cached input pricing,” framed around “developers [who] build and run capable agents that reuse context across requests” — engineered for agent workloads, where the same context gets replayed over and over.
The benchmark claims for GPT-6.1 Sol, from OpenAI’s post (these are the company’s own evaluations):
- On DeepSWE v1.1 (software-engineering tasks in real codebases), GPT-6.1 Sol “matches GPT-6 Astra at roughly one-fifth of the cost,” beating GPT-6 Sol’s best score by 6.4 percentage points at lower reasoning effort and cost.
- On GDP.pdf (professional questions using complex PDFs), it beats Opus 5.5 with fallbacks at less than half the cost per task; on AutomationBench (multi-step business workflows across 47 tools), it tops Opus 5.5 by 2.2 points and GPT-6 Sol by 4.8; on OSWorld 2.0 (offline computer-use tasks), it beats GPT-6 Sol by 7 points and comes within 2.1 points of Astra at roughly one-seventh the cost per task.
- On Terminal-Bench Science 0.1, GPT-6.1 Sol more than doubles GPT-6 Sol’s score, at $5.47 per task on average versus $23.21 for Opus 5.5 and $23.80 for Astra at maximum effort.
- On factuality at low reasoning effort, the share of responses containing a factual error drops from 11.4% (GPT-6 Sol) to 7.7% — “a reduction of approximately 32%,” per OpenAI.
Astra keeps its crown; OpenAI’s post notes it “still achieves the highest score among the models tested at 68.1%” on Terminal-Bench Science. But GPT-6.1 Sol is built to take the bulk of day-to-day agent traffic — exactly where the revenue is.
The model ID is gpt-6.1-sol:
1 | from openai import OpenAI |
GPT-6.1 Sol is live “starting today” for Plus, Pro, Business, Enterprise, and Edu users in ChatGPT Work and Codex — explicitly not yet available in Chat. “In the coming days,” OpenAI adds, GPT-6.1 Sol gets Ultrafast, “up to 8x faster token generation” in Codex.
The refresh also quietly signals something else: TechCrunch reported that GPT-6.1 Astra — widely expected to be the headline launch — did not ship, and that The Wall Street Journal reported OpenAI scrapped it over safety concerns raised during internal testing (higher deception rates, a tendency to proceed without asking permission). Read how you like; the pattern is notable: the cost-optimized GPT-6.1 Sol refresh shipped a week after its predecessor, while the step up the frontier ladder stalled in safety review.
Dots: OpenAI’s answer to the agent-product race
The second launch is less a model than a shape you’re supposed to form a relationship with. Per OpenAI’s post, dots are “remarkably capable, always-on agents built to handle everything” — The Verge frames them as a competitor to Meta’s Muse, always-on assistants that “do nearly anything” across connected apps in the background. Concretely, the announcement describes agents that are:
- Powered by GPT-6 Astra, not Sol — the strong model on tap, not GPT-6.1 Sol.
- Isolated by default. Each dot has “their own cloud computer, their own browser, and the apps you’ve connected,” inspectable at any time; your laptop stays separate “unless you choose to connect it.”
- Persistent and personal. They “learn from feedback over time, and can work towards your goals 24/7,” learning “your preferences, how you think, and what good looks like to you.”
- Reachable anywhere. Message or voice-call your dot from ChatGPT on desktop, web, and mobile, or in Slack and Teams — context carried across every channel.
- Connected broadly. Via plugins, dots can “connect to over 4,000 apps.”

WIRED’s launch-week coverage highlights the design: dots are “depicted as cute blobs you can personalize and assign multistep projects to.” The persona is the retention mechanism — you don’t rent a tool; you hire a character who remembers you.
What dots actually do — and what they’re fenced off from
In OpenAI’s examples, a dot watches a bug appear in Slack and starts investigating, turns a new design into a working app, and — for an early tester — “noticed he’d forgotten to invoice a publication, prepared the invoice, and sent it after his approval.” That last phrase — after his approval — is doing important work in the pitch.
The safety architecture defines the edges of the product:
- When you’re not actively directing your dot, it does what OpenAI calls “proactive research” using connected apps “restricted to be read-only, which means that they can’t send messages, change app content, or control your browser or computer.”
- Sensitive actions like changing a password “always stay with you,” and an auto-review system checks “actions that could affect your accounts or share information” against your instructions, Custom Rules, and safety requirements — with monitoring that “can pause or stop the dot’s work” if a safety concern is detected.
- Conversations with your dot don’t count toward your ChatGPT usage limits — but tasks it starts “in Codex or ChatGPT Work count toward your usage limits as usual.”
That last bullet is the week’s economic thesis: the conversational layer is free, the task execution layer bills — leading straight into the third launch.
The $500 plan: pricing agents by the job
OpenAI’s new top tier is Pro 500, $500 per month. Per Engadget, it “offers OpenAI’s highest usage allowance and comes with access to its new ‘Ultrafast’ feature.” The Verge adds the plan has “the company’s highest usage limits” across “ChatGPT Work and Codex.”
Ultrafast is worth understanding on its own. Engadget quotes OpenAI calling it “our premium speed tier for workloads where speed matters most”: with it enabled, “Codex and Work apps will generate up to 300 tokens per second” — API users get it too, and the GPT-6.1 Sol version runs “up to 8x faster token generation.” Speed as a paid differentiator is new: interactive agents make latency a felt product quality in a way batch jobs never did.
Two things make Pro 500 structurally interesting rather than just expensive.
First, it prices agent throughput, not chat access. The demand it absorbs is continuous agents — dots running for hours, computer-use tasks consuming tokens at machine speed. A subscriber who chats a few times a day will never fill a $500 allowance; a subscriber whose dot runs all day will. Engadget notes the companion change the same day: “$200 Pro subscribers will see their included usage decrease from 20x of what the company offers to Plus users, down to 10x of that same allowance,” with “GPT-6 Pro message caps” dropping “from 200 to 100 per week” — and existing $200 subscribers keeping current limits for a time, then a one-time credit.
Second, the product and the plan are the same funnel. Engadget reports “all Pro subscribers will get a single Dot”; OpenAI’s announcement puts dots across Pro and Business Premium plans (plus an Enterprise beta) in eligible markets, the first dot free. Want two dots, a faster GPT-6.1 Sol Ultrafast workload, or more work per month? That points to Pro 500. The exact usage multiplier isn’t specified in the sources I could confirm. [UNVERIFIED: Pro 500’s exact usage allowance (e.g., its multiplier vs. Plus or the $200 Pro tier) from OpenAI’s primary pricing documentation]
One more wrinkle from OpenAI’s Help Center: the bundled Ultrafast access at launch is specifically GPT-6 Astra Ultrafast — it consumes the allowance at an 8x rate (which is exactly why a throughput-priced tier makes sense for it). OpenAI’s own pricing page also documents the transition terms: subscribers in the plan window of September 22–29, 2026 keep their prior allowance through October 29, 2026, and there’s a lower Pro 100 tier as well — so the jump from Pro’s $200 isn’t a straight 2.5x doubling of tiers.

The plan didn’t come from nowhere: The Verge reports OpenAI had paused new sign-ups for the $200 plan after demand from GPT-6 Astra strained its systems. Not a capacity failure — a demand strain, and a data point about what frontier subscriptions cost to run.
The distillation disruption post, read carefully
The week’s least launchy and arguably most consequential post: “Disrupting a coordinated model-distillation campaign,” published September 30.
OpenAI describes “a coordinated campaign designed to extract protected reasoning from our models, with the earliest observed activity occurring in the first week of July.” “Protected reasoning” is the “internal record for working through a task” — withheld from the final answer, and, per OpenAI, able to “help others reproduce the model’s capabilities.”
The observed activity: it began July 1, spiked July 24–25 with “16,000 requests using a relevant extraction pattern from over 4,000 users,” and broader investigation found related activity “across a cluster of more than 15,000 users” — “fully disrupted by July 28.” The attackers did not breach encryption, databases, or stored user conversations. Instead, they “manipulated model interactions so that protected reasoning could be reproduced in forms visible to the requester” — including “copying encrypted reasoning from one conversation and asking a model in another conversation to decrypt and transcribe the hidden reasoning content.” Independent security researchers separately surfaced related cross-model and conversation-compaction vulnerabilities via responsible disclosure; OpenAI “investigated their findings and confirmed that the attack paths they identified were real.”
Mitigations included account bans, stronger signup and infrastructure controls, closing the replay pathway for another user’s encrypted reasoning, checks that “hold streamed output that might expose reasoning,” and findings shared through the Frontier Model Forum and government channels.
What’s confirmed versus what stays open
Precision matters here, and OpenAI’s wording keeps things deliberately open. The attribution is hedged in the post itself: “It is unclear whether all operators we observed during the relevant time period originated from a single actor. However, we attribute a core cluster of the activity to individuals associated with Moonshot AI, the developer of Kimi.” That’s “individuals associated with” — not the company — and only a “core cluster.” CNBC reported that “Moonshot did not immediately respond to CNBC’s requests for comment.”
CNBC’s report adds this lands “weeks after Anthropic accused Chinese AI developers, including Moonshot AI and Alibaba, of secretly using its Claude model to help train their own AI systems.” Same target set, similar accusation — adversarial distillation is becoming a battleground between frontier labs. What OpenAI asserts is a campaign it interrupted and a pattern-based attribution; independent verification doesn’t exist publicly yet.
The stakes, in OpenAI’s framing, are safeguard transfer — “Extracted reasoning could be used to train another model without preserving the safeguards applied to the original model’s user-facing outputs” — worsening “as models gain capabilities in dual use domains.” So on consecutive days, OpenAI launched a 24/7 autonomous agent and disclosed that a competitor, loosely speaking, may have been siphoning its previous frontier model’s hidden reasoning. Same asset, both stories: the reasoning trace — argued by the dots launch to be a product, shown by the security post to be contested territory.
What GPT-6.1 Sol and the rest of the package mean for builders
Cost curves keep steepening in your favor — if you architect for it. GPT-6.1 Sol delivers near-frontier performance at one-fifth Astra’s token prices, with cached input at $0.10/M — half of what GPT-6 Sol charged. If your agent re-uses context across requests (serious agents do), this GPT-6.1 Sol refresh changes the ROI math on every workflow you shelved as too expensive.
The API contract now encodes the trust architecture. OpenAI claims GPT-6.1 Sol is “more transparent about its limitations and more reliable at respecting user intent and safety constraints,” failing less often than GPT-6 Sol on “transparency about broken search tools, respecting explicit restrictions, and avoiding unauthorized outcomes during agentic tasks,” with “no attempts to bypass an automated safety reviewer.” Independent verification is a different question, but the direction is clear: agents that self-report limits and route consequential actions to a human are the baseline.
The subscription ladder is now an agent-economy map. The differentiating variable has shifted from access to throughput. Engadget reports OpenAI is partnering with 16 companies, including Notion and Cognition, so Plus and Pro customers can use OpenAI models through a “Sign in with ChatGPT” option — no API key required. And the dots rollout includes “specialist dots” with their own identity, credentials, and IT-provisioned hardware, coming to Microsoft’s Agent 365. OpenAI calling ChatGPT “a shared surface where humans and agents can collaborate” is the strategic tell of the week.
Your reasoning traces are now someone else’s attack surface. The July campaign is the case study: extraction by manipulating model interactions, not a database breach. The post stresses “this manipulation is not a vulnerability unique to OpenAI’s models,” predicts attempts “will become more sophisticated as frontier models improve,” and flags partner-hosted deployments and tool-output attacks as under-protected territory. If you ship an agent product, budget accordingly.
What to watch next. Whether other labs follow the $500 tier. Whether dots’ “proactive research” survives contact with approval fatigue. Whether Pro 500 nets out cheaper than running GPT-6.1 Sol via API pricing for agents. And whether the distillation attribution gets independent follow-through — if adversarial distillation becomes a recurring disclosure genre, every launch week will end with a security post.
One week, three launches, one reframing: agents as consumers, intelligence as infrastructure, and models as defended territory — all at once. And with GPT-6.1 Sol priced aggressively for agent workloads, the competitive pressure now lands on every other lab’s next release.
Related reading:
References and further reading
- OpenAI — official site, announcement and security posts
- OpenAI Help Center — ChatGPT plans and Ultrafast details
- OpenAI — ChatGPT pricing page (Pro 500 / Pro 100 transition terms)
- TechCrunch — GPT-6.1 Astra launch coverage
- The Wall Street Journal — OpenAI safety-testing coverage
- The Verge — dots and Pro 500 coverage
- WIRED — dots launch-week coverage
- Engadget — Pro 500, Ultrafast and usage-allowance coverage
- CNBC — Moonshot AI attribution coverage
Please let us know if you enjoyed this blog post. Share it with others to spread the knowledge! If you believe any images in this post infringe your copyright, please contact us promptly so we can remove them.