OpenAI's GPT-6 Astra hallucinates less but remains vulnerable to hidden prompt injections

What happened
OpenAI's GPT-6 Astra hallucinates less than its predecessor and blocks 99.99 percent of direct prompt injections. But when attacks are hidden inside documents the AI reads, the model still gets cracked in 8.5 percent of scenarios. Claude Opus 5 does better at 4.8 percent. For autonomous AI agents handling real data, those numbers still seem high.
Summary assembled by rule from the sources below