AI & automation

OpenAI GPT-6 Astra: the first model to cross the 'Critical' cybersecurity threshold

TerraCodeSeptember 3, 2026 2 min read
OpenAI GPT-6 Astra: the first model to cross the 'Critical' cybersecurity threshold

On September 3, 2026, OpenAI released GPT-6 Astra, presented as the product of years of research and big bets. The headline feature is "computer use": the model navigating a computer the way a human would, but what actually shook the public was that this is OpenAI's first model to cross its own "Critical" cybersecurity risk threshold: it can find previously unknown security flaws and exploit them without step-by-step human guidance.

What happened

According to the announcement, Astra navigates spreadsheets, fills out forms, and moves across web pages at superhuman speed; this "computer use" capability is the model's flagship feature. Alongside it, though, OpenAI issued an explicit warning: Astra's cybersecurity risk classification crossed the "Critical" level, the highest on the company's own scale. The rollout is phased: a limited group of companies in OpenAI's application-based cybersecurity program, Daybreak, gets access first, with the API, Amazon Web Services, and ChatGPT Plus/Pro/ Business/Enterprise plans following in the days after the Thursday launch.

The gist in a minute

  • Release: 2026-09-03
  • Pricing: $10/M input tokens, $50/M output tokens (roughly 2.5x GPT-5.6 Sol's $4/$20 rate)
  • Cached input: $1/M tokens; batch/flex at half price; fast mode at double price, ~2.5x speed
  • Above 272K input tokens: $20 in / $75 out
  • First OpenAI model to cross the "Critical" cybersecurity threshold
  • Access: Daybreak program participants first, then API/AWS/ChatGPT plans

An unusual kind of warning

A "Critical" risk classification means the model can independently perform security research work (vulnerability discovery, exploit development) that previously required an expert human team. That's why OpenAI didn't announce Astra with a simple feature list, instead launching it through a dedicated, restricted-access program (Daybreak), a signal that the company itself is treating its own model's capabilities with caution.

"A model so good at finding security holes that they hand it to a narrow group first instead of the public: like saying the knife is sharp, but only chefs get one for now. Reassuring and unsettling in equal measure." (Nasus)

Who benefits

Because of "computer use," Astra is primarily interesting to teams building real browser/desktop automation on AI (form-filling, data-entry workflows, QA testing) where speed and accuracy could be a concrete, measurable improvement over prior models. The cybersecurity capability cuts both ways: huge potential for pentest and security research teams, but the narrow initial access (the Daybreak program) means you can't just build on it without registration yet; worth following the official program's terms before planning any security workflow around Astra.

Source: Fortune: OpenAI launches GPT-6 Astra, its most powerful model yet, CNBC: OpenAI begins rolling out Astra model after warning of its advanced cyber capabilities, Yotta Labs: GPT-6 Astra Pricing

Stay up to date!

Subscribe to my newsletter and get my latest articles.