OpenAI Introduces GPT-6 Astra with Critical Cybersecurity Classification
OpenAI announced the GPT-6 Astra model, initially making it available to a limited group of organizations. The company assigns it an internal Critical classification for cybersecurity capabilities and says it includes enhanced safeguards.

On September 3, 2026, OpenAI announced GPT-6 Astra, a new agentic model designed to work with computers, the web, programming, and specialized tasks. According to the company’s announcement, it is initially being made available to a limited group of organizations. Access is later expected to be added for users on the ChatGPT Plus, Pro, Business, and Enterprise plans, as well as through the API, Microsoft Azure, and AWS Bedrock.
The model is also significant from a security perspective. OpenAI describes Astra as its first broadly deployed model to reach the “Critical” level for cybersecurity capabilities under its own Preparedness Framework. This classification describes the manufacturer’s internal assessment, not confirmed misuse of the model in a real-world incident.
GPT-6 Astra and security restrictions
OpenAI says it has deployed enhanced safeguards with the model. These include trajectory monitoring, meaning the sequence of steps the model takes while completing a task, and blocking potentially unauthorized actions. For sensitive prompts, control mechanisms may stop the task or ask the user to review it.
The company also reports no documented case of GPT-6 Astra being misused in a cyberattack at the time of release. Information about its capabilities and safeguards comes from OpenAI materials. The effectiveness of these mechanisms in production cannot yet be independently evaluated.
The Critical classification increases the importance of phased access and security controls. Models with agentic capabilities may do more than generate text or source code; they may perform multiple steps in applications and while working with the web. In this context, OpenAI discusses opportunities for defensive cybersecurity work and automation, while also introducing restrictions for sensitive workflows.
GPT-6 Astra API specifications
In the API documentation, the model is listed under the identifier gpt-6-astra. It has a context window of 1.05 million tokens. The price is set at $10 per million input tokens and $50 per million output tokens.
Access is not general at the time of the announcement, however. OpenAI describes an initial rollout to a limited group of organizations, followed by expansion to its products and partner cloud platforms. The scope and pace of access outside the Trusted Access program may change.
What comes next
Further development will depend in part on when the model actually appears in individual paid plans, the API, and Microsoft Azure and AWS Bedrock. The publication and expert review of the full system card and the methodology used for security evaluations will also be important.
OpenAI also attributes high intelligence and selected benchmark results to Astra. These are the manufacturer’s claims, and independent reproductions have not yet been documented. The experiences of early users, independent testing of the reported results, and any expansion of access to more advanced defensive cybersecurity workflows through OpenAI Daybreak will therefore also be monitored.
Sources
- OpenAI — GPT-6 Astra: A new generation of intelligence – Confirms the announcement, phased rollout plans, stated capabilities, safeguards, and API pricing.
- OpenAI — Safety overview: GPT-6 Astra – Confirms the release date, the internal Critical classification for cybersecurity capabilities, and the security measures described.
- OpenAI API — GPT-6 Astra Model – Confirms the model identifier, context specifications, pricing, and planned access through the API and product plans.
Verified and updated: 09/04/2026 15:46



