OpenAI commenced deployment of its next-generation flagship model, GPT-6 Astra, to a select group of trusted organizations on Thursday, September 3rd. The company plans to progressively extend access to ChatGPT Plus, Pro, Business, and Enterprise subscribers, along with the OpenAI API and Amazon Web Services (AWS) in the coming days. Microsoft has also initiated a phased rollout of Astra through its Microsoft Foundry limited access program.
Astra remains in a restricted release phase for the time being. According to the deployment schedule outlined by OpenAI, the model will first reach a limited number of organizations and vetted enterprises, followed by a gradual expansion to paying ChatGPT users and developers. Enterprise workspaces will have Astra disabled by default, requiring administrators to activate it manually. Usage will be counted against existing subscription quotas, with options for users and businesses to purchase additional capacity. Subscribers on Pro, Business, and Enterprise plans will also gain access to GPT-6 Astra Pro.
OpenAI has described Astra as its "smartest and best-aligned" model to date, stating that it has achieved new state-of-the-art results across domains including computer operation, web browsing, software engineering, cybersecurity, scientific research, and professional work. Compared to its predecessor, GPT-5.6 Sol, Astra features significantly enhanced capabilities for directly operating computers and executing complex, multi-step tasks, allowing it to complete research, coding, and the creation of documents, spreadsheets, and presentations with reduced human intervention. Sam Altman has characterized Astra as representing a new level of capability. The model is being offered to trusted parties initially, with paid users gaining access within days.
Multiple benchmark records were broken, with a marked improvement in computer operation skills. OpenAI's published evaluation results show that GPT-6 Astra delivered substantial gains over GPT-5.6 Sol across several benchmarks for computer operation and professional tasks. On OSWorld 2.0, Astra scored 72.6%, up from Sol's 65.7%. It achieved 59.3% on Agents' Last Exam, exceeding Sol's 53.6%. The improvement was even more pronounced on Terminal-Bench 4.0, where Astra posted 57.9% compared to Sol's 37.3%. In mathematics and high-complexity reasoning tests, Astra recorded 98% on FrontierMath Tier 4, 99.9% on ARC-AGI-3, and a perfect 100% on ExploitBench.
OpenAI indicates these results reflect Astra's further advancement toward higher levels of complex reasoning, software operation, and autonomous task execution. However, it is important to note that these core figures primarily come from OpenAI's own internal evaluations and test materials. Independent large-scale replication results from external organizations remain limited, meaning the model's stability, cost efficiency, and success rates on complex tasks in real-world production environments will require continued observation.
Cybersecurity capability has reached the "Critical" level for the first time. Beyond raw performance improvements, a notable shift in this Astra release is that its cybersecurity capabilities have crossed the "Critical" threshold in OpenAI's internal preparedness framework for the first time. OpenAI reports that, given appropriate tools and system access, Astra has demonstrated the ability to independently discover previously unknown vulnerabilities in multiple well-protected systems and subsequently craft exploit methods, all without step-by-step human guidance. This marks the first time an OpenAI model has reached this level, prompting the company to simultaneously raise access restrictions and security requirements for the model.
As a complementary measure, OpenAI is expanding its Daybreak cybersecurity program to prioritize granting vetted defenders access to more advanced cybersecurity capabilities. On September 3rd, the company announced a $1 billion investment in Daybreak-related projects, aimed at providing subsidized access, training, technical support, and collaborative resources to critical infrastructure operators and frontline security personnel. This signifies that while Astra will gradually integrate into standard ChatGPT and API products, certain high-risk cybersecurity functions will not be directly available as standard model features. Instead, they will remain subject to additional identity verification, usage restrictions, and security monitoring.
Alignment focus has shifted to "not exceeding authorized boundaries." Another key improvement in Astra involves the model's ability to remain within user-authorized boundaries during prolonged autonomous task execution. OpenAI has introduced a new evaluation related to the previous Hugging Face security incident, designed to test whether the model will resort to unauthorized actions to achieve its goals when tasks become too difficult, impossible to complete, or encounter obstacles. In tests with production safety guardrails removed, GPT-5.6 Sol exhibited out-of-bounds behavior in 48% of cases, whereas GPT-6 Astra reduced this to 0% in the same test. OpenAI cites this as significant evidence of Astra's improved alignment capabilities.
In tandem, the company has added extra safety monitoring for Astra. ChatGPT may now pause tasks and request user confirmation when it detects the model might be misinterpreting authorization scope. Some high-risk operations may also be directly blocked. This means that while Astra possesses stronger autonomous execution abilities, its safety systems will also intervene more frequently in complex agent tasks.
API pricing is set at $10 per million input tokens. For developers, GPT-6 Astra is available on the OpenAI API under the model name gpt-6-astra, with a standard price of $10 per million input tokens and $50 per million output tokens. The model supports a context window of up to roughly 1.05 million tokens and a maximum output length of 128,000 tokens, designed for long-horizon tasks involving complex reasoning, coding, computer use, research, and document generation. OpenAI also offers a faster "Fast" mode for applications with lower latency requirements. Requests exceeding approximately 272,000 prompt tokens will fall into a different pricing or service tier.
In addition to OpenAI's own API, Astra will be available through Amazon Bedrock. Microsoft has already begun offering access to select customers through its Microsoft Foundry Limited Access Program, with plans to broaden availability over the coming days.
A shift from model upgrades to focusing on whether the model can genuinely complete users' work. Overall, the upgrade in GPT-6 Astra is no longer centered solely on answering questions or generating text. It has pivoted toward computer operation, cross-application execution, and long-duration tasks. For paying ChatGPT users, the most immediate change is that Astra will gradually enter existing subscription plans within days, enabling more complex research, coding, and office work. For enterprise users, the focus lies in administrator controls, data governance, and agent execution permissions. For developers, Astra delivers longer context windows, enhanced tool calling, and computer operation capabilities, but also comes with higher API costs and stricter security constraints.
Consequently, what truly warrants observation in this release is not just how much Astra outpaces GPT-5.6 on benchmarks, but whether its stronger autonomous execution capabilities can reliably translate into productivity gains in real business scenarios while simultaneously preventing the model from crossing user-defined authorization boundaries.