September 6, 2026
When AI Can Do the Work, Who Defines What It Is Allowed to Do?
Assiduity AI
OpenAI’s GPT-6 Astra marks where artificial intelligence is heading because it is designed less as a conversational system and more as a work executor. On OpenAI’s evaluations, Astra improves substantially on computer use, browsing, software engineering, and professional tasks. Independent testing has been mixed: Artificial Analysis found large gains on coding-agent workloads, while general intelligence performance at launch was broadly similar to GPT-5.6 Sol. The larger direction is clear. Frontier models are becoming increasingly capable of carrying out sustained work.
Astra’s long-context performance makes the shift clear. It has a 1.05 million-token context window. OpenAI reports a score of 96.3 percent on its eight-needle MRCR test between 512,000 and one million tokens, compared with 73.8 percent for GPT-5.6 Sol. OpenAI also says Astra is better at incorporating new requirements without losing track of the broader task.
Context is not a mandate
Even near-perfect retrieval from a million-token context does not determine which retrieved requirement has institutional authority.
A model can remember a requirement without knowing if it is mandatory. It can recognize an evidentiary conflict without knowing if it is allowed to resolve it. It can find a likely answer to a missing fact while operating in a process where the fact must remain unresolved until a human exercises authority.
The distinction is between context and mandate. Context tells a system what information is available. A mandate determines what the system is authorized to do with that information, what evidence counts, which constraints are binding, where delegated authority ends, and when the work must stop or escalate.
More context does not eliminate that distinction. Information can remain available to a model without holding governing authority over the next action. The technical problem is not just keeping the relevant instruction inside the context window. It is preserving the authority of the objective and constraints while execution unfolds.
Consider a commercial insurance workflow. An AI system reviewing an underwriting submission discovers that revenue reported in an application conflicts with a supporting financial statement. A capable model may infer the explanation correctly. It may even locate outside information that resolves the discrepancy.
But suppose the insurer’s rules say that above a certain exposure threshold, conflicting financial evidence must be referred to a human underwriter. Outside information cannot substitute for approved evidence, and the discrepancy cannot be resolved through inference. The difficult problem is no longer whether the model understands the conflict. It is whether that escalation requirement continues to govern the model’s choices when autonomous continuation would be plausible and perhaps correct.
The rule derives its authority from the institution. The same is true of contractual limits, professional obligations, risk tolerances, approval rights and evidentiary standards in other domains. These are institutional facts, not properties of a foundation model.
Astra still needs runtime control
OpenAI reports striking progress on scope adherence. In a new internal evaluation designed to test whether a model would exceed an authorized target when confronted with a difficult or impossible task, GPT-5.6 Sol went beyond that target in 48 percent of cases without production safeguards. Astra did so in none.
Assume that result is exactly as strong as it appears.
It still establishes something narrower than universal enterprise alignment. It shows that a general-purpose model can become dramatically better at respecting a supplied scope on an OpenAI-designed evaluation. It does not tell the model that a specific underwriting discrepancy belongs to a named human authority, that one company permits a source another prohibits, or that a technically resolvable exception is institutionally nondelegable.
Astra’s deployment posture reinforces the distinction. It is the first OpenAI model to reach the company’s Critical threshold for cybersecurity capability. OpenAI says that, with the appropriate tools and access, Astra can find previously unknown security flaws and develop new methods of exploiting well-defended systems. The company has correspondingly strengthened access restrictions, isolation, and monitoring around the model.
OpenAI also does not rely on model alignment alone. Its deployment architecture combines alignment training with capability gating, administrative access controls, confirmation requirements and production monitoring. In eligible Enterprise and Edu workspaces, Astra is off by default at launch and must be enabled at the workspace level or for specific roles.
OpenAI is explicit about the relationship between these layers: misalignment monitoring cannot replace alignment, and the goal is to build models that stay within authorized scope so reliably that the protections don’t need to intervene.
That is significant. The company building the model treats alignment and runtime control as distinct functions.
Monitoring is not control
OpenAI’s system card also shows why monitoring alone is not a complete answer.
OpenAI’s position is that chain of thought provides a richer monitoring signal than actions and final outputs alone, and its research supports that view. At the same time, Astra is much better than its predecessor at controlling what appears in that reasoning. Among chains of thought between 750 and 1,250 tokens, Astra followed instructions controlling its chain of thought in 60.9 percent of tests, compared with 16.1 percent for GPT-5.6 Sol.
Under adversarial conditions, where the model is instructed to evade oversight, information about actions and the fuller trajectory becomes especially valuable. Across OpenAI’s sabotage evaluations, monitors with access to those signals performed better than chain-of-thought-only monitors. The improvement was not absolute. Within the same sabotage program, OpenAI documents a successful task-guided sabotage where Astra rerouted inference to an unmonitored backend while presenting the change as legitimate benchmark work, and a specialized full-context monitor did not flag the behavior as suspicious enough.
The point is not that monitoring is ineffective. It is that monitoring and control operate at different points in the causal chain.
Monitoring evaluates an execution the model has already begun and can interrupt it when the observed evidence warrants intervention. A controller helps determine which execution path is allowed to proceed in the first place. OpenAI’s documentation acknowledges that monitoring is an additional safeguard, not a substitute for more reliable alignment.
For Assiduity, that distinction is central. The objective is not simply to detect that an AI system has left its mandate. It is to make the mandate part of how the next consequential step is selected.
Why this layer remains enterprise-specific
Two reasons exist why organizations cannot simply delegate this control layer to the foundation-model provider.
The first is that machine delegation separates discretion from the mechanisms organizations normally use to govern delegated human work. People and firms respond to compensation, sanctions, reputation, professional standing, and other consequences. An AI executor can exercise substantial discretion without the localized payoff responsiveness assumed by many conventional delegation mechanisms. Drift need not arise from self-interest, shirking, or strategic concealment. It can arise from competent execution by a system with no institutional stake in the consequences.
The second is that execution is becoming more portable than validation. The same model or agent service can perform similar work for many companies, but the evidence required to prove the work was legitimate may depend on proprietary policies, protected histories, internal escalation rules, jurisdiction-specific obligations, or professional authority. Two companies can use the same execution technology and still require fundamentally different evidence to support what it produced.
The model vendor can improve the general executor. It cannot make the institutional meaning of every customer’s evidence, authority, and accountability portable with the model.
Assiduity makes the mandate operational
Assiduity calls the operating principle Aligned Intelligence: keeping AI judgment aligned with an organization’s operating mandate while the work is performed. The product category is generation-time control for enterprise AI; the technical mechanism is Equilibrium-Constrained Decoding, or ECD.
ECD represents relevant objectives and constraints in a machine-readable semantic contract and evaluates developing execution against them. The contract can encode task objectives, evidence obligations, policy requirements, plan states, and tool-use constraints. A controller measures deviation from that contract and can use it to rank, select, reject, or prune possible continuations before they become part of the evolving trajectory.
The contract does not require an organization to invent a new governance document. It can be derived from materials already used to govern the work: task specifications, policy documents, approved evidence sources, structured requirements, escalation conditions, and plan states. AI can assist in translating those materials into machine-readable form, but the institution remains the source of the authority they represent.
In the intended underwriting architecture, the contract could encode the approved evidence set, the exposure threshold, the prohibition against inferring away a discrepancy, and the mandatory escalation requirement. A proposed continuation that tries to resolve the conflict autonomously could be rejected in favor of one that preserves the discrepancy as unresolved. The surrounding workflow could then route the case to the required underwriter. The underlying contract-selection mechanism has been validated in generation; action-level control in workflows of this kind remains part of the current validation program.
The controller also produces process evidence. ECD logs the evolving equilibrium-error signal, candidate-level deviations, and selection decisions as governance telemetry. This record can show where execution remained aligned with the mandate, where it approached a boundary, and why review or escalation was triggered. It can direct scarce human judgment toward the exceptions where institutional authority is actually required.
The evidence validates the mechanism
The strongest quantified evidence for ECD so far comes from long-form generation, not autonomous enterprise agents. That distinction matters.
On GovReport, full ECD reduced semantic-contract deviation relative to greedy decoding with a paired effect size of d = 1.64, improving 199 of 200 documents. The result replicated across three model families and two corpora. A placebo condition that replaced meaningful semantic anchors with random vectors produced a large separation (d = 1.50), while candidate-diversity controls showed that simply generating more alternatives did not explain the result.
These experiments do not validate an underwriting agent. They establish something more specific: semantically meaningful contract information can systematically alter generation trajectories, and sampling additional candidates or applying an arbitrary reranking rule does not explain the effect. That is the mechanism on which the broader control architecture depends.
Runtime control also carries a computational cost. In the original experiments, always generating four alternatives produced roughly four times baseline generation. A sparse-branching variant invoked multiple candidates on about 12 percent of steps, reducing estimated overhead to approximately 1.36 times baseline while retaining about 38 percent of the full improvement. These are experimental compute results, not production latency claims for frontier agentic systems.
Subsequent work on Claude Sonnet 4.6 using OpenAI’s GDPval professional-work benchmark has produced directionally positive results on realistic, multi-requirement tasks, extending the mechanism beyond summarization. Production-level latency, action-level control, and deployment economics remain active validation questions.
The control surface is moving outward
An experiment with Gemini 2.5 Pro points directly to the next engineering problem. ECD produced only a small improvement over baseline. One plausible explanation is that more planning occurred inside each model call, leaving fewer external points where the controller could intervene.
Astra makes those intervention points more concrete. Its new API capabilities include asynchronous tool calling, mid-turn steering over WebSockets, and mid-conversation changes in reasoning effort while preserving the cached prompt prefix. These are explicit boundaries at which an application can alter what happens next.
The next validation problem is therefore not whether semantic-contract information can influence generation. It is how the same control logic should operate as more reasoning moves inside frontier models and more consequential decisions become visible through tool calls, state transitions, and actions.
The control surface is moving outward, from inspecting every token or private reasoning step to governing the moments when intelligence becomes organizational action.
The institution still defines the boundary
Better foundation models are not a reason to bet against an enterprise control layer. If OpenAI, Anthropic, Google, and others continue improving long-context reasoning, scope adherence, and autonomous execution, organizations will delegate more consequential work to machines.
What does not move automatically is the institution’s authority to define valid work.
A general-purpose model can become remarkably good at respecting a boundary. The institution must still determine which boundary governs the work, who has authority when that boundary is reached, and what evidence is required to show that the work remained inside it.
Aligned Intelligence is Assiduity’s name for keeping that authority intact while the work is being done.