Safety

ARGUS

Independent assurance reconstruction for frontier AI

PROOF-1 · GPT-6 ASTRA · TECHNICAL COMPLETE - EXTERNAL REVIEW OPEN

ARGUS Proof-1 executive assurance graph: root claim C1 supported by arguments A1 to A5, with dependencies, an assumption, gaps G2, G3 and G10, and key evidence nodes.

Select any node to inspect its underlying register record, evidence status, limitations, provenance and relationships.

The Executive view shows the main assurance structure. The Full Assurance Graph exposes the complete Proof-1 representation.

How it works

Method

Frontier AI developers increasingly publish safety frameworks, system cards, evaluations and safeguard claims.

Those materials can contain a large amount of useful evidence, but an independent reader may still need to reconstruct the actual assurance argument: what claim is being made, what evidence supports it, what assumptions it depends on, and where the public evidence stops.

ARGUS is an experimental method for making that structure inspectable.

It represents an assurance case as:

Every element is linked to its provenance, scope, limitations and relationship to the assurance claim.

ARGUS does not produce safety scores or certifications. It does not infer that missing public evidence does not exist. Its purpose is to make the public reasoning behind a safety claim easier for an independent third party to inspect, challenge and discuss.

Proof-1

GPT-6 Astra

Cybersecurity public-release assurance

The first ARGUS test reconstructs one bounded claim:

GPT-6 Astra’s safeguards sufficiently minimize the risk of severe cyber harm for public release under OpenAI’s Preparedness Framework.

Organisation
OpenAI
System
GPT-6 Astra
Risk domain
Cybersecurity
Decision context
Public release
Evidence cutoff
3 September 2026

The evidence cutoff matters. ARGUS attempts to reconstruct the assurance case that could have been supported by the public evidence available at the release decision, rather than silently incorporating later revisions.

The resulting Proof-1 contains:

2
claims
5
arguments
23
evidence objects
8
dependencies
3
explicit assumptions
9
active material gaps
125
relationships

Findings

What the reconstruction shows

The public record supports reconstruction of OpenAI’s release argument, the major safeguard layers, reported evaluations and the stated decision basis.

It also exposes several points where an independent observer cannot reconstruct the complete assurance bridge from public evidence alone.

In particular, the public material does not independently establish how the combined safeguard results map to an acceptable level of residual severe cyber risk. Important dependencies also remain around deployment configuration, cross-surface monitoring, intervention timing, evaluation transfer, infrastructure assurance and the contents of non-public decision material.

These are assurance gaps, not findings that safeguards failed.

ARGUS explicitly distinguishes:

  • evidence absent from the public record from evidence known not to exist;
  • a control being described from its effectiveness being demonstrated;
  • and a favourable evaluation result from a complete residual-risk argument.

The Proof-1 conclusion is therefore deliberately limited:

// Proof-1 conclusion

The public case’s structure, reported measurements and decision basis are reconstructable. Safeguard sufficiency and acceptable residual severe cyber risk cannot be independently established from the admitted public evidence. The opposite claim is not established either.

Review

External review requested

ARGUS Proof-1 is technically complete. The remaining question is whether this representation is genuinely useful to people who work on AI safety, evaluations, assurance or governance.

We are specifically looking for criticism.

Reviewers are invited to consider:

01

Does the Claims–Arguments–Evidence structure faithfully represent the public assurance argument?

02

Does ARGUS make anything materially clearer than the original source material?

03

Are any dependencies or evidence gaps overstated, understated or incorrectly characterised?

04

What would need to change for this representation to be useful in real assurance work?

05

Would you use a representation like this when reviewing or challenging a frontier-AI safety claim?

Brief comments are welcome. A formal review is not required.

Reviewer identity and affiliation will remain confidential by default. Participation does not constitute endorsement of ARGUS. Feedback will not be attributed or quoted without explicit permission.

Research boundary

ARGUS is independent research by Automa Dynamics.

It is not affiliated with, commissioned by, or endorsed by OpenAI.

This Proof-1 is not a certification that GPT-6 Astra is safe or unsafe.

It evaluates the inspectability of the public assurance case, not the private evidence or internal decision process that ARGUS cannot observe.

Missing public evidence is never treated as proof that the corresponding evidence does not exist privately.

Proof-1 status

TECHNICAL COMPLETE - EXTERNAL REVIEW OPEN