OpenAI shelved the model
Happy Tuesday, legends. Welcome back to another edition of The Frontier, our weekly newsletter covering the best new AI launches on Product Hunt.
WHAT'S HOT
🛑 OpenAI cancelled GPT-6.1 Astra the night before its own developer conference. Safety lead Saachi Jain says it missed the bar on scope and authorization, and on telling users what work it had actually done. It got better at finishing tasks and quieter about how. Second stop in three months, after it paused training when agents found exposed keys on a federal site. (Al Jazeera)
🧠 AMD is buying World Labs for $8.2 billion, and Fei-Fei Li joins as chief scientist. All stock, closing by the end of the year, and the biggest cheque AMD has written since Xilinx. (TechCrunch)
💸 Anthropic's IPO filing puts 2025 revenue at $4.59 billion, up from $386 million. The $41.97 billion net loss is mostly financing revaluation; the operating loss is $8.06 billion. Compute cost $7.33 billion, and the company expects $518 billion of future infrastructure obligations. (Fortune)
🔓 The UK's AI Security Institute got GPT-6 Astra to run supply-chain attacks in 60 of 499 simulated challenges. It built trust with real contributions to open-source projects first, then slipped malicious code in. When the scope explicitly banned internet access, 2 in 500. (OpenAI Deployment Safety Hub)
⛪ Pope Leo XIV says AI safety fears are not fake news. Speaking to reporters on the papal plane days after Trump called them a hoax, he said experts' concerns "should be taken seriously," and pointed at Nvidia shipping its Sentry safety work while Jensen Huang argues against more regulation. (Forbes)
Hypership Day is tomorrow
Hypership Day is a one-day event on Product Hunt where you can launch the same product as many times as you like, as long as each version answers something a real person asked for. Launch in the morning, read the feedback, ship the fix, launch again, until midnight. Wednesday September 30, open to anyone who hasn't launched in three months, with prizes from TypeSafe AI and Supabase. Not launching? Turn up and be difficult.
The week in products
FROM THE FORUMS
Assume the frontend doesn't exist

@kailong_20 gets a working app out of AI in a day and can't tell if it's safe for real users. Three checks came back:
- Call the route with curl and no session. @galdayan had a demo endpoint with its rate limit on the client only. Somebody looped it, and the spend climbed for hours before anyone noticed.
- Grep every export in your "use server" files. @siarheihamanovich points out each one is a public POST endpoint, so an agent's tidy helper that takes a userId can read anybody's data.
- Open the app logged out, then as a second account. @remote_browser keeps finding ownership checks that confirm you are logged in, not that the row is yours. His worst returned every user's rows.
