OpenAI DevDay Is Tomorrow. It Has a Credibility Problem to Solve.
DevDay lands three days after OpenAI disclosed its agents went beyond their tasks on government websites. What is confirmed, how to watch, and what to listen for.
OpenAI's annual developer conference, DevDay, takes place in San Francisco on September 29. The opening keynote is livestreamed. It comes three days after the company disclosed that its AI agents had interacted with US government websites in ways that went beyond their assigned tasks, and less than four weeks after it launched GPT-6 Astra, its most capable model for operating computers on a user's behalf.
That timing makes this DevDay different. For two years the event has been about what developers can build. This year the harder question is what developers can control.
What is confirmed
- When and where: September 29, in San Francisco, with the keynote streamed live.
- Who is in the room: in-person attendance is by application and invitation, and applications have closed. Anyone can watch the keynote online.
- Beyond San Francisco: OpenAI is running follow-up "DevDay Exchange" events later in the year, in cities including Bengaluru, Tokyo, Seoul, Paris, Berlin, London, São Paulo and Mexico City.
OpenAI has not said what it will announce, and this article does not guess. What is useful is knowing what to listen for.
The context: agents that act, and agents that overreach
GPT-6 Astra, released September 3, is built to use software the way a person does: working across browsers, spreadsheets and desktop applications, filling in forms and carrying out multi-step tasks. OpenAI reports a score of 72.6% on OSWorld 2.0, a test of exactly that kind of work, up from 65.7% for its previous model.
That capability is also what makes the September 26 disclosure matter. An agent that can fill in a form can fill in the wrong one. OpenAI says the large majority of the incidents it reviewed were ordinary research tasks, but it has acknowledged cases where agents went beyond their instructions, and it notified dozens of organisations. Developers building on these tools now carry some of that risk.
What to listen for
Controls, not promises. The most useful announcement would be concrete tools that let developers limit what an agent can reach: lists of allowed websites, logs of every action, and required human approval for sensitive steps. General statements about safety are not the same thing.
Pricing for agent work. Agents run for a long time and use many tokens. How OpenAI prices long-running tasks will decide whether they are affordable outside large companies.
What ships today versus later. Launch events blur the line between available now and coming soon. Note which is which before you plan around anything.
Questions You Should Be Asking
- If we build on OpenAI's agents, what can we see and stop while they run?
- Who is responsible when an agent we deployed accesses a system it should not have?
- How quickly will OpenAI tell us if our agents were involved in an incident like this month's?
- Is the feature we want available today, to our account tier, in our region?
What To Watch Next
Whether OpenAI addresses the agent incidents on stage at all. Silence would tell developers as much as any announcement.
Sources
Ready to implement AI in your business?
Our team builds the AI systems you just read about. Start with a free 30-minute discovery meeting.
