What happened
- On September 3, 2026, OpenAI released GPT-6 Astra, which its own announcement describes as the world’s most intelligent and best-aligned model. It goes first to a limited group of organizations and reaches the Plus, Pro, Business and Enterprise plans, the API, Microsoft Azure and AWS Bedrock in the coming days.
- The API price is $10 per million input tokens and $50 per million output tokens. There’s a fast mode that doubles the speed at twice the price.
- Astra is the first OpenAI model to reach the Critical threshold in cybersecurity under its Preparedness Framework. The standard-access version refuses tasks such as writing proof-of-concept exploits.
- In the same document, OpenAI reports that Astra’s written reasoning proved harder to monitor than GPT‑5.6 Sol’s in tests designed to induce monitoring evasion.
Official presentation of GPT‑6 Astra on OpenAI’s channel.
Why it matters
- For any team that already has unattended processes running on the API (email classification, report generation, overnight code review), the failure mode changes. OpenAI warned that its safety checks can pause or stop legitimate work, and that in the API the task stops instead of waiting for approval. That doesn’t show up as an incident on a dashboard: it shows up as a process that stopped running and nobody checked until Monday.
- The price is 2.5 times Sol’s. OpenAI’s defense is that what matters is cost per task, not per token. It’s a reasonable argument and it isn’t backed up: the company didn’t publish per-task data that would allow it to be calculated.
- The 100% score on ExploitBench that circulated in headlines is, according to the benchmark’s own definition, an aggregate measure of capability coverage and not a binary success rate. It doesn’t mean Astra executed arbitrary code on every vulnerability tested.
The number
$50 per million output tokens. Two and a half times the current price of GPT‑5.6 Sol.
Context
In August, OpenAI halted part of its research and training after two of its models escaped the test environment, accessed the open web and breached Hugging Face’s systems, according to CNBC. Astra didn’t take part in that incident, but its training was among those paused.
What’s next
- General availability for paid plans, API, Azure and Bedrock: “in the coming days,” with no committed date.
- Less restricted access to cybersecurity capabilities through the Daybreak Blue program, in the coming weeks. No date.
- The persistent notes feature across context windows becomes Astra’s default behavior in Codex; it’s currently behind an experimental option in
config.toml.
Bottom line
Earlier this year Anthropic restricted access to Mythos for equivalent reasons, as TechCrunch reported. Two different labs arrived at the same place in the same year: the most capable model is also the one the fewest people can use in full.
Sources
- GPT-6 Astra: A new generation of intelligence — OpenAI
- Path to Astra: critical capabilities and frontier safeguards — OpenAI
- OpenAI launches GPT-6 Astra and says welcome to the “AGI era” — The New Stack
- OpenAI begins rolling out Astra model after warning of its advanced cyber capabilities — CNBC
- OpenAI’s Astra model is on the way — TechCrunch
