OpenAI released GPT-6 Astra on September 3, calling it the most capable and best-aligned model it has built and the first to earn a Critical rating for cybersecurity under its Preparedness Framework. The rating means the model can find unknown security flaws and develop working exploits across well-protected systems without step-by-step human guidance.
Astra carries a 1.05 million token context window and is built for computer use. OpenAI reports it beats its own GPT-5.6 Sol on several coding and agent benchmarks while finishing some computer tasks in roughly half the time, and says it found two previously unknown V8 browser vulnerabilities during testing that it is now disclosing to maintainers. API pricing starts at $10 per million input tokens and $50 per million output.
That capability ships behind strict gates. The released model refuses exploit development, and access began with Trusted Access and Daybreak organizations only, with Plus, Pro, Business, and Enterprise plans promised in the coming days and Enterprise switched off by default. Microsoft is offering the model through its Foundry limited access program, and AWS Bedrock lists it too. OpenAI warns its new misalignment monitors can slow, pause, or block legitimate work.
The rollout carried two controversies. OpenAI confirmed Astra’s reasoning is harder to audit because a technique called opaque recurrence processes queries in loops, leaving fewer legible traces than classic chain of thought; safety researchers including Redwood’s Buck Shlegeris called that direction alarming. And paying subscribers found themselves locked out of the staged launch, prompting chief executive Sam Altman to apologize on September 4 and promise reset credits for each day of delay.
All benchmark figures are OpenAI’s own, and the company says it hopes broader access arrives over the September 5-6 weekend.