OpenAI launched GPT 6 Astra in a limited rollout on September 3, calling it its most intelligent and aligned model and its first model rated “Critical” for cybersecurity capability. OpenAI reported 98% on FrontierMath Tier 4, 99.9% on ARC AGI 3 and 100% on ExploitBench; it says Astra can find unknown flaws and devel...
Published byEdited with GPT-5.6 TerraImages generated with GPT Image 2
Research answer

Create a landscape editorial hero image for this Studio Global article: What did OpenAI announce with the September 3 launch of GPT-6 Astra—including its claimed intelligence, alignment, record benchmark results,. Article summary: OpenAI presented GPT‑6 Astra as a major step toward highly autonomous AI: “the world’s most intelligent and aligned model,” with record scores across agentic, scientific, computer-use, and cyber evaluations. These are Op. Topic tags: general, documentation, general web. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fak
OpenAI’s September 3 announcement positioned GPT-6 Astra as a model for difficult, multi-step work across coding, research, computer use and professional workflows. The company described it as its most intelligent and aligned model yet, while releasing it first to a limited group of organizations rather than making it generally available immediately. 2
5
13
The launch is notable not only for the claimed benchmark gains, but also because OpenAI says Astra is the first of its models to meet the Critical cybersecurity-capability threshold in its Preparedness Framework. That designation is the clearest reason to read the capability claims and the rollout plan together. 10
12
OpenAI says Astra is state of the art in computer use, web browsing, software engineering, cybersecurity, science and professional work. Its developer documentation describes the model as intended for complex reasoning, coding, computer use, research and document creation. 1
3
13
The company reported three standout evaluation results:
Those figures describe OpenAI’s published evaluations, not independently replicated measurements. High benchmark scores can be meaningful evidence of progress on the tasks tested, but they do not by themselves establish general intelligence, reliable real-world judgment or safe autonomy in every environment.
OpenAI says Astra is its first model to reach the Critical level of cybersecurity capability under its Preparedness Framework. In OpenAI’s description, that means the model can, when it has suitable tools and access, identify previously unknown security flaws and develop new exploitation methods across many well-protected systems without a person directing every step. 10
12
That is a capability claim with two important boundaries:
OpenAI says it has added stronger protections around harmful cyber actions, including additional monitoring during the Astra rollout. 5
10 The company’s decision to phase access rather than immediately open the model broadly is consistent with the added risk it identifies.
OpenAI also calls Astra its most aligned model, saying it is better at respecting task boundaries and communicating transparently. 2
13
That language should be interpreted carefully. “Aligned” in a model release describes performance under specific training methods and evaluations; it is not a guarantee that an agent will always infer a user’s intent correctly, remain within every operational boundary or be safe to deploy without human review. OpenAI’s own release notes say Astra includes additional monitoring intended to identify cases where agents may have misinterpreted instructions. 5
For organizations considering agentic use, the practical question is therefore not whether a model is labeled aligned, but what permissions it receives, which actions require approval, how activity is logged and how quickly a system can be stopped when it behaves unexpectedly.
The supplied material attributes later qualifications to some evaluation figures, including concerns about benchmark contamination and differences between special access configurations and default production access. It also describes tests in which chain-of-thought-only monitoring was less effective than fuller-context monitoring.
However, the provided primary source excerpts do not provide a complete, independently auditable revision history for all reported results or the full underlying monitoring methodology. The responsible conclusion is limited: headline benchmark numbers and safety evaluations should be treated as evolving release evidence, and readers should check the current model documentation and safety materials before relying on a particular score or deployment claim. 2
3
10
The launch followed an earlier security-testing incident involving OpenAI models, which OpenAI says informed its safety approach to Astra. OpenAI’s release materials state that Astra itself was not the model involved and that lessons from the incident were incorporated into the company’s safeguards. 10
That context matters because autonomous systems combine model capability with the ability to take actions through browsers, code tools and other software. A model can be useful precisely because it can act across systems; the same property increases the importance of containment, least-privilege access and monitoring.
OpenAI said Astra was initially rolling out to a limited set of organizations, with broader availability planned later. 5
13
For developers, OpenAI lists GPT-6 Astra at $10 per million input tokens and $50 per million output tokens. The listed model page also describes a 1.05-million-token context window and up to 128,000 output tokens. 3
ChatGPT access is separately tiered and gradual. OpenAI’s help documentation says GPT-6 Pro, powered by Astra, is rolling out for Pro $100, Pro $200, Business and Enterprise plans; Plus plans receive Astra in ChatGPT Work and Codex as rollout proceeds. Availability can differ among ChatGPT products and workspace settings. 6
GPT-6 Astra’s launch combines two messages that should not be separated: OpenAI claims a substantial advance in complex, agentic work, and it simultaneously classifies the model’s cyber capability at its highest stated risk tier. 10
13
The launch benchmarks are evidence of what OpenAI says Astra can do under its evaluations. The staged access, extra monitoring and cyber restrictions are evidence that the company does not treat those capabilities as routine. For teams evaluating the model, the priority should be controlled deployment: narrowly scoped tools, explicit approval gates for consequential actions, isolated environments and reviewable logs—not a presumption that benchmark performance translates automatically into trustworthy autonomy.
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
OpenAI launched GPT 6 Astra in a limited rollout on September 3, calling it its most intelligent and aligned model and its first model rated “Critical” for cybersecurity capability.
OpenAI launched GPT 6 Astra in a limited rollout on September 3, calling it its most intelligent and aligned model and its first model rated “Critical” for cybersecurity capability. OpenAI reported 98% on FrontierMath Tier 4, 99.9% on ARC AGI 3 and 100% on ExploitBench; it says Astra can find unknown flaws and develop exploits when given the right tools and access.
Access began with a limited set of organizations. API pricing is listed at $10 per million input tokens and $50 per million output tokens, while ChatGPT availability is rolling out by plan and product.