OpenAI released GPT-6 Astra on September 3, positioning it as a frontier model for computer use, cybersecurity, software engineering, science and professional work. The more consequential element of the launch, however, is a safety classification: OpenAI says Astra is the first of its models to reach the Critical level for cybersecurity capability under its Preparedness Framework.
That designation does not establish that Astra has carried out attacks against real systems or that it can autonomously compromise any particular target. It is OpenAI’s assessment of the model’s potential when paired with suitable tools and access. OpenAI says the designation concerns Astra’s potential to find previously unknown vulnerabilities and develop exploit chains across protected systems without continuous human guidance.
Safeguards and access controls
OpenAI says the model’s new safeguards sufficiently minimize severe-harm risk for release. That is the company’s assessment, not independent verification.
Availability reflects that caution, at least initially. OpenAI said broader availability was planned for paid ChatGPT users, the OpenAI API and AWS, although timing and availability remained in flux immediately after launch. The company reported API pricing of $10 per million input tokens and $50 per million output tokens.
OpenAI is phasing access to Astra’s most advanced cybersecurity capabilities through its Daybreak program. Reporting says selected organizations receive initial access, while broader-access versions are intended to refuse advanced cybersecurity tasks. That distinction is important: availability of Astra does not mean broad availability of a less-restricted model for advanced cyber tasks.
Computer-use claims and safety scrutiny
OpenAI has presented Astra as a major advance in computer use, including navigating interfaces and carrying out multistep work. It reports that Astra scored 72.6% on an offline subset of OSWorld 2.0 in roughly 40 minutes per task, compared with roughly 75 minutes for GPT-5.6 Sol. Those are company-reported evaluation results, not an independent assessment of real-world reliability. Still, the combination of longer-horizon computer use and advanced cyber capability is why the access model deserves as much attention as the benchmark claims.
OpenAI’s September 1 safety update designated Astra as its first model to meet the Critical cybersecurity capability threshold. The launch therefore puts those commitments under immediate operational scrutiny: Astra is no longer only a model being assessed for critical cyber capability, but a product being deployed across consumer, enterprise and developer channels.
OpenAI President Greg Brockman has characterized Astra as a possible beginning of an “AGI era.” That remains an executive interpretation, not a settled technical conclusion; artificial general intelligence has no universally accepted definition. The clearer, testable news is OpenAI’s own risk designation and the controls it says follow from it. Whether those safeguards prove durable will depend on external testing, the effectiveness of monitoring in real deployments, and how carefully access expands beyond the initial rollout.
Uneven early rollout
Reports on September 4 said the rollout was uneven for some paying users, after OpenAI chief executive Sam Altman described the initial availability as a “messy rollout.” That issue is separate from the cyber-capability designation, but it underscores the immediate challenge for OpenAI: managing a broad product launch while maintaining meaningful distinctions among ordinary access, enterprise deployment and tightly governed cybersecurity work.




