OpenAI spent Tuesday's Dev Day keynote emphasizing speed and savings. Out in the hallways and the merch line, developers wanted to talk about the hours they lose working around model safeguards.

Developers told VentureBeat that OpenAI and Anthropic safeguards are flagging routine aerospace, robotics and security work as risky, costing them time and disrupting otherwise ordinary workflows. Some described abandoning chats or moving specific tasks to other models when refusals became hard to work around.

AI agents are already embedded in day-to-day development. JetBrains’ 2026 Developer Ecosystem Survey of more than 15,000 professional developers found 90% use AI coding agents at work at least weekly, including 68% who use them daily. 

The developers' accounts come as OpenAI is trying to reduce harmless refusals while tightening safeguards around more capable models. On stage, OpenAI launched GPT-6.1 Sol, which the company says approaches the performance of its more powerful GPT-6 Astra model on coding and computer use at one-fifth of Astra's standard token prices. 

OpenAI also said its GPT-6 models are less likely to refuse harmless requests than earlier models, and the model's system card notes that OpenAI treats Sol itself as Critical for cybersecurity and that it uses the same safeguards stack as GPT-6 Astra. The GPT-6 Astra system card says Astra is OpenAI's "first model to reach the Critical level of cybersecurity capability under our Preparedness Framework." OpenAI says that with the right tools and access, the model can discover and exploit unknown vulnerabilities in well-protected systems without step-by-step human direction. OpenAI has also canceled the release of GPT-6.1 Astra over safety concerns, according to The Wall Street Journal.

OpenAI acknowledged to VentureBeat that its safeguards can disrupt legitimate work. The company said GPT-6 Astra and GPT-6.1 Sol are less likely than GPT-5-series models to refuse harmless requests, but that extra safety checks can still “slow, pause, or stop legitimate work,” including defensive cybersecurity. OpenAI said it is continuing to refine the safeguards to reduce unnecessary interruptions.

As model costs fall, developers said refusals can impose a different cost: lost time.

A satellite that isn't there

Alejandro Carrasco, a second-year master's student in MIT's Department of Aeronautics and Astronautics, works in an area that sometimes triggers model safeguards: software and space. He worked with a Stanford lab on putting LLM agents in control of simulated spacecraft, testing whether a language model could outperform reinforcement learning algorithms at flying the mission.

Carrasco said he has not hit an outright refusal. Instead, his requests are sometimes treated as suspicious.

"Because I'm working with the space department, sometimes the model thinks that I am trying to do military stuff," Carrasco said. "I am working with a satellite. It doesn't identify that it's a simulated satellite."

He said the models sometimes flag his requests as involving sensitive data or defense security clearances, though he has no such clearance. Asked about the frontier labs, he singled out Anthropic. "Claude is a lot more aggressive," he said.

Carrasco thinks the conversation history makes the problem worse. Once a model starts treating his work as suspicious, he finds it difficult to steer the conversation back. "Once I see that my chat gets to a point of no return, or that it is getting to a conclusion, for example, refusal, I just switch," he said.

Robot arms and SSH sessions

Martin Kemka, who builds robotics projects, said the blocks he hits show up in routine parts of the work.

"I was getting a lot of blocks when I was working on any robotics projects, even really benign ones," Kemka said. "Stuff like creating a user interface for an arm and being able to SSH into another machine, I would get a lot of refusals."

Carrasco, who has worked with arms including the open-source SO-101 and Universal Robots' UR5, said the trigger appears to be access. Once he asks a model to access real device parameters, he starts running into more restrictions. A few months ago, he said, one model stopped short of refusing and instead required him to state explicitly, by name, that he authorized it to access his own camera and sensors.

Kemka reported no trouble using Astra with the MicroVerse simulator, where he has trained virtual robots to balance, sumo wrestle and sneak past guards. He said the refusals arrive when he asks the model to work with physical hardware or connect to another machine.

Canceling over refusals

Elvis Saravia, co-founder of DAIR.AI and author of Prompt Engineering Guide, said he takes the risks of the technology seriously.

"I'm a builder, but I also think about safety," he said. "I also think about the damages you can do as well."

Even so, he called refusals "a big problem" for technical users like himself. "It's quite frustrating, actually, as an experience," he said. He said he dislikes seeing safeguards prevent people from building what they want to build.

Saravia said refusals he described as "really blatant" eventually led him to cancel his Anthropic subscription. He now uses GPT-6 Astra, which he found to be the least aggressive of the frontier models he has used.

When security work gets flagged

Rohan Balkondekar splits his time between Xsolla and VibeGrow, a growth agent he co-founded. His team codes mostly with OpenAI's Codex and Anthropic's Claude, and he says cybersecurity-related requests are especially likely to trigger refusals.

"They hate the word cyber," Balkondekar said. "Whenever you say cybersecurity, they just flat out, 'Nope.'"

Much of the code his team needs to vet comes from open-source contributors, he said, adding that reviewing third-party code for vulnerabilities is one of the tasks that triggers the guardrails. He said the problem sharpened with the latest generation of frontier releases, pointing to Anthropic's Fable models and OpenAI's GPT-6 line.

OpenAI pointed to Daybreak Access, its trusted-access program for qualified enterprise customers and cybersecurity practitioners. The company says the program supports authorized defensive work including secure code review, vulnerability triage, incident response and malware analysis.

Anthropic has acknowledged problems with false positives in its safeguards. Its Fable models ship with safeguards that can redirect flagged cybersecurity and biology queries to less capable models. After Fable 5 launched in June, developers complained that its safety system was blocking benign prompts, and Anthropic said it had made the wrong tradeoff. With Fable 5.1 this month, Anthropic said its cyber safeguards now permit vulnerability discovery in source code and should produce around 60% fewer interventions per Claude Code session, though penetration testing, exploit generation, and some binary-based vulnerability scanning still route away from Fable.

Anthropic did not respond to a request for comment by publication time.

The open-model workaround

When the closed models refuse, Balkondekar's team reaches for open ones, including Moonshot AI's Kimi. Cost had already pushed them to experiment, Balkondekar said, and refusals gave them another reason to use open models.

Carrasco uses Alibaba's Qwen for research and said that many workflows need a fast, small, locally run model more than a frontier one, especially when someone in the open-source community has already fine-tuned a model for the domain. Kemka pointed to Apfel, an app that exposes the language model Apple ships in the latest macOS as a local API. 

For Balkondekar, open models are a fallback when the closed models won't do the work his team needs. "We do use open models for things like that when the closed models, like Anthropic and OpenAI, refuse," Balkondekar said. "Because someone has to do it. No one can sit down and review all of it."