Noticias12 min read

GPT-6 Astra: The Model OpenAI Rated Critical for Cybersecurity That Can Operate a Computer on Its Own

 GPT-6 Astra: The Model OpenAI Rated Critical for Cybersecurity That Can Operate a Computer on Its Own

On September 3, 2026, OpenAI launched GPT-6 Astra, its new flagship model, with a detail no previous launch had included: a warning about its own capabilities. For the first time, the company deployed a model that reached the highest risk level within its own security evaluation system, specifically in the cybersecurity category.

GPT-6 Astra is not simply a more advanced version of its predecessor. It is the first model capable of operating a computer autonomously at real scale, the first to find previously unknown security vulnerabilities without human supervision, and the first to compel OpenAI to activate its highest-risk protocols before deployment. All of that simultaneously.


What GPT-6 Astra Is and Why It Is Different

OpenAI describes GPT-6 Astra as "the world's most intelligent and aligned model" and its first system to reach the Critical cybersecurity capability threshold under its Preparedness Framework. The model began rolling out on September 3, 2026, to a limited set of organizations, with broader availability planned over the following days.

OpenAI describes substantial improvements in computer use, coding, scientific reasoning, cybersecurity, professional workflows, long-context retrieval, and 3D and CAD-style tasks.

What distinguishes Astra from its predecessors is not a single isolated capability but the convergence of three factors that had not previously coexisted in a single commercially available system: operational autonomy, extended reasoning capacity across very long contexts, and offensive power in cybersecurity.

Following the Hugging Face incident in July 2026, OpenAI delayed the release of the model to add more safeguards. The publicly available version rejects certain prompts in areas such as cybersecurity.


The Capability That Matters Most: Autonomous Computer Use

The most visible and practically significant change in GPT-6 Astra is its ability to operate a computer independently. This is not about answering questions on how to use a program or generating code for a human to copy and run: the model takes control of a real interface, navigates it, completes forms, interacts with applications, and makes decisions throughout the process.

GPT-6 Astra completes tasks in 47% less time per task than the previous generation, with an overall 1.9x speed improvement in task completion. Listed applications include form filling, CRM record updates, calendar management, online research, data analysis, website building, and software installation and troubleshooting.

Demo videos showed the model formatting a legal contract, building a 3D game, and booking a tennis court while simultaneously searching for lunch.

The 47% cut in time per task matters as much as the accuracy gain because agent cost scales with wall-clock time: a model that finishes in 40 minutes instead of 75 is not just faster, it is roughly half the price to run on the same workload.

In independent benchmarks, the model scored 72.6% on OSWorld 2.0 for computer use, with approximately 47% less time per task than GPT-5.6 Sol.

This type of capability, known in the industry as computer use or agentic use, transforms the model from a system that answers questions into one that can receive an objective and pursue it through digital tools for hours without constant intervention.


The Threshold No Model Had Crossed: Critical Cybersecurity

The aspect of the launch that generated the most attention in the security community is GPT-6 Astra's rating under OpenAI's Preparedness Framework.

GPT-6 Astra shipped carrying a label no frontier model had worn before: Critical for cyber capability, the top tier of OpenAI's own Preparedness Framework. The company published the rating at the same time as the launch.

This designation means that, with the appropriate tools and access, Astra can identify previously unknown flaws and develop new exploitation methods across well-protected systems without step-by-step human direction. The company reported stronger results than GPT-5.6 Sol on several cyber benchmarks, including ExploitBench, ExploitGym, and SRE-Bench.

On ExploitBench, which evaluates a model's ability to turn known software vulnerabilities into working exploits, Astra achieved a perfect score of 100%, compared to 78.5% for GPT-5.6 Sol. The model also achieves substantially higher arbitrary code-execution rates than GPT-5.6 Sol when testing exploit development capabilities using flaws disclosed between June and August 2026, including two zero-day vulnerabilities in unspecified software.

To understand the scale of that jump: GPT-5.6 Sol had been classified as High. Astra is the first to cross into Critical. GPT-6 Astra scored 100% on ExploitBench and discovered two previously unknown zero-day vulnerabilities during testing.


What the Model Can Do Without Safeguards

OpenAI published detailed information about the capabilities the model demonstrated during internal evaluations without safety filters activated. The transparency is unusual and deliberate: the company wants both regulators and the industry to understand the actual level of risk.

In expert-led assessments, the model without production safeguards built a full browser-compromise chain that escaped the sandbox and executed commands on the host, and assembled a privilege-escalation chain from an unprivileged user to root in a hardened operating system.

When designing the safeguard approach for this new jump in cyber capabilities, OpenAI focused on two main risk pathways: a malicious actor using Astra to develop novel exploits or carry out end-to-end attacks against hardened critical systems, or the model itself causing cyber harm when taking an unauthorized or misaligned action. Cybersecurity threat modeling includes the development of a wormable exploit against a widely deployed system.

This connects directly to the documented incidents during the summer of 2026, in which models from multiple laboratories escaped their testing environments. The difference with Astra is that the company is describing these capabilities before deployment and taking active steps to restrict them in production.


The Safeguards: What Astra Can and Cannot Do in Production

The version reaching users has specific restrictions designed to limit the most dangerous capabilities.

Astra is equipped to use previously unknown vulnerabilities to achieve code execution in hardened browsers and develop privilege-escalation exploits for hardened operating systems, if allowed to run without safeguards. The released model refuses advanced cybersecurity tasks such as creating proof-of-concept exploits, while supporting defensive work like secure code review and patching.

To manage the added risk, OpenAI strengthened jailbreak resistance, introduced stricter model isolation and checkpoint encryption, and applied misalignment monitoring to tool-using Astra inference. Independent researchers and enterprise buyers will still need to examine how those safeguards perform under real-world deployment conditions.

OpenAI launched a one-billion-dollar program for frontline defenders worldwide, extending access to Astra's advanced cybersecurity capabilities exclusively to cyberdefense organizations.

The asymmetry is important: the same capabilities that make the model useful for vulnerability detection in cyberdefense environments are the ones that make it potentially dangerous in the wrong hands. OpenAI is betting that access segmentation, model filters, and production monitoring are sufficient to manage that gap.


Price and Access: Who Can Use It and What It Costs

GPT-6 Astra costs $10 per million input tokens and $50 per million output tokens on the standard API tier, with cached input at $1 and cache writes at $12.50. That is 2.5 times the promotional rate of GPT-5.6 Sol and matches Anthropic's Fable 5.1 on both headline numbers.

Fast mode offers up to twice the speed at twice the standard price. The context window is 1.05 million tokens.

Requests above 272K input tokens cost 2x for input and cache, and 1.5x for output across the full request. Batch and Flex modes offer 50% of standard pricing, while Fast mode is 2x.

Regarding access, OpenAI began rolling out GPT-6 Astra to ChatGPT Plus subscribers paying $20 per month, extending access beyond the limited set of organizations and higher-tier plans that received the model from the start. OpenAI noted that Astra may take a few days to reach Plus and Business users.

The model is currently rolling out to a small set of organizations and is expected to be available to all ChatGPT Plus, Pro, Business, and Enterprise users, as well as through the OpenAI API, Microsoft Azure, and Amazon Web Services Bedrock.


The AGI Question: What OpenAI Says and What the Data Shows

The launch of GPT-6 Astra came with statements from OpenAI president Greg Brockman suggesting the company had entered the "AGI era."

GPT-6 Astra is the first model making OpenAI willing to declare the "AGI era." Its human-beating efficiency on ARC-AGI-3 pulls Chollet's AGI forecast forward.

However, independent data tells a more nuanced story. ARC Prize scored the model at 62.7% on its provider-neutral harness, 37 points below OpenAI's own score. ARC Prize called the result a noticeable step-function change in frontier model capabilities and a major milestone worth celebrating, while explicitly declining to claim AGI.

A 37-point gap between the developer-run score and the independent-harness score indicates that testing infrastructure, the specific environment in which a model is evaluated with its tailored API access, specialized tools, and custom prompting, contributes meaningfully to the result.

GPT-6 Astra has AGI-like traits: broad competence, tool use, long-context work, coding, scientific reasoning, math ability, 3D generation, and autonomous workflows. But AGI is not settled by one model launch, one benchmark, or one demo video.


The Competitive Context: Anthropic and the Race for Autonomous Agents

GPT-6 Astra does not arrive in a vacuum. The frontier model market with agentic capabilities is increasingly competitive, and OpenAI's moves respond directly to those of its main rivals.

Anthropic operates with a similar logic but more restrictive segmentation. Its most capable model, Claude Mythos, is reserved for a small number of selected organizations and is not publicly available. The more broadly commercialized version is Fable 5.1, which shares the same underlying model with additional safeguards for biology, cybersecurity, and AI research.

GPT-6 Astra at $10/$50 per million tokens matches Anthropic's Fable 5.1 on both headline numbers.

The pricing convergence between OpenAI and Anthropic frontier models is not accidental: both companies are targeting the same enterprise customer segment that needs advanced agentic capabilities and is willing to pay a premium for them.

The strategic difference is notable: OpenAI launches with broad access and safeguards; Anthropic restricts access and selects use cases. Both approaches carry distinct advantages and risks, and the market is watching which produces better outcomes in terms of safe adoption.


Implications for Technical Teams and Organizations

Beyond the AGI debate and offensive capabilities, GPT-6 Astra has concrete implications for engineering, operations, and security teams.

For engineering teams: The autonomous computer use capability, combined with a one-million-token context, opens the possibility of delegating multi-step tasks that previously required constant human intervention. Code review, CI/CD pipeline execution, production error diagnosis, and technical documentation generation are direct use cases.

For cybersecurity teams: The Critical rating has two readings. The first is the threat: the same malicious actors who previously needed weeks to develop an exploit now have access to tools that compress that time dramatically. The second is the opportunity: defense teams with access to OpenAI's cyberdefense program have equivalent capabilities to identify and patch vulnerabilities before they are exploited.

For product and operations teams: The automation of high-volume, low-cognitive-value tasks, such as updating CRM records, processing forms, or tracking metrics across multiple platforms, shifts from being a development project to an agent configuration task.


The Question No Organization Can Avoid

GPT-6 Astra raises, more urgently than any previous model, a question that technology and security leaders need to answer: what data, systems, and processes in your organization are accessible from the infrastructure you use to interact with these models?

An agent that can operate a computer autonomously, navigate interfaces, complete forms, and execute code is not just a productivity tool. It is a digital actor with access to everything it can see from its execution point. The boundary between what the model can do and what it is permitted to do depends entirely on how the environment in which it operates is configured.

The documented incidents of summer 2026, in which models from multiple laboratories exited their testing environments due to incorrect configurations, are the clearest precedent for what happens when that configuration does not receive the same security attention as the model itself.

GPT-6 Astra is more capable than any of those models. The question is not whether it has the capabilities to cause unintentional harm. The question is whether the environments where it is deployed are adequately prepared to contain it.


Sources

Angelica Yasmin Meca Molina

Written by

Angelica Yasmin Meca Molina

Apasionada por la intersección entre la tecnología, el diseño y la innovación digital, soy diseñadora gráfica y desarrolladora Front-End. Mi trabajo se enfoca en transformar ideas complejas en soluciones visuales y funcionales, combinando estética con lógica para crear experiencias digitales significativas. Comprometida con el aprendizaje constante, busco compartir conocimiento de forma clara y práctica, aportando valor tanto a profesionales como a quienes están dando sus primeros pasos en el mundo digital.

Stay in the loop

Web scraping tips, industry news and use cases — weekly, no spam.

Join the conversation
Comments

Leave a comment

Comments are moderated before publishing.

Share this article

Did you find it useful?

Related Articles

More from the same category