cyberivy
GPT-6 AstraOpenAIComputer UseAI AgentsCybersecurityCodexModel SafetyDeveloper Tools

GPT-6 Astra combines computer use with critical cyber capabilities

September 11, 2026

Zwei dunkle Browseransichten zeigen nebeneinander von KI erzeugte Entwürfe einer persönlichen Karriere-Website.

OpenAI is rolling GPT-6 Astra into ChatGPT and the API. Strong computer use now meets cyber capabilities that, according to the company, reach its critical risk threshold for the first time.

What this is about

OpenAI introduced GPT-6 Astra on September 11, 2026. The model is initially available to selected organizations and is due to roll out over the following days to ChatGPT Plus, Pro, Business and Enterprise, as well as the OpenAI API, Microsoft Azure and AWS Bedrock. The important change is not one benchmark but the combination of reasoning, computer use and tool operation.

The launch has an unusual security dimension: OpenAI rates Astra's cyber capabilities as “Critical” under its own Preparedness Framework for the first time. This is a vendor assessment, not an independent certification. It still means organizations should not treat the migration like an ordinary model upgrade.

What GPT-6 Astra actually does

Astra can operate websites, desktop applications and developer tools. OpenAI lists forms, CRM records, research, spreadsheets, presentations, software testing and scientific applications. The company reports 72.6 percent on OSWorld 2.0 at about 40 minutes per task; GPT-5.6 Sol scored 65.7 percent at roughly 75 minutes. On Terminal-Bench 4.0, OpenAI reports 57.9 percent versus 37.3 percent for Sol.

The cybersecurity results are more sensitive. Without production safeguards, Astra scored 100 percent on ExploitBench and 42.4 percent on ExploitGym, according to OpenAI. In an internal evaluation using vulnerabilities from June through August 2026, it reportedly found and exploited two previously unknown flaws. OpenAI says it is disclosing both to their maintainers. The released model is designed to refuse advanced exploit-development requests.

Why it matters

Computer use moves AI from producing text to taking action. A model that operates browsers, terminals and specialist software can save time, but it can also turn a mistaken assumption directly into a change in an account, system or production workflow. Permissions, audit trails and approval gates therefore matter more than a high benchmark score.

Developers may also care about the announced long-term memory in Codex: earlier context windows are meant to remain searchable instead of surviving only as compressed summaries. That could stabilize long development tasks, while making stored session traces more valuable and more sensitive.

In plain language

The change is like moving from an excellent travel adviser to someone who packs the suitcase, books tickets and makes changes at the airport. The second person saves more work but can also cause more damage after a bad assumption. They need clear boundaries, a budget and questions before consequential steps.

A practical example

A software team asks Astra to inspect 200 dependencies and prepare safe updates. The model identifies 18 candidates, builds 12 test branches and proposes six releases. A sensible process allows reading, analysis and isolated tests automatically but requires human approval for every change to the main branch. Production secrets remain out of reach. This captures the speed without pairing stronger capabilities with blanket access.

Scope and limits

  • Most performance figures come from OpenAI. Independent reproductions of the new evaluations are limited at launch.
  • A strong test score does not prove that a multi-step workflow will succeed in a particular company's software. Interfaces, permissions and unexpected dialogs remain failure points.
  • Safety refusals are not an absolute barrier. Organizations still need least privilege, isolated environments, spending limits and complete logs.

SEO & GEO keywords

GPT-6 Astra, OpenAI, computer use, Codex, cybersecurity, ExploitBench, OSWorld 2.0, AI agents, Preparedness Framework, model risk

💡 In plain English

GPT-6 Astra can operate software and websites instead of only answering questions. That is why organizations should grant minimal permissions and keep approvals for consequential actions.

Key Takeaways

  • Astra is rolling out to ChatGPT and the API from September 11, 2026.
  • OpenAI reports substantial gains in computer use and software work.
  • Its cyber capabilities reach the Critical threshold of OpenAI's Preparedness Framework for the first time.
  • The published benchmark results need independent confirmation.
  • Least privilege, isolated testing and human approvals remain necessary.

FAQ

When is GPT-6 Astra available?

OpenAI began with selected organizations on September 11, 2026. ChatGPT plans and API access are expected to follow gradually over the next few days.

Why is Astra a distinctive cyber risk?

OpenAI rates its cyber capability as Critical for the first time and reports that an unsafeguarded test version could exploit previously unknown vulnerabilities.

Has Astra been independently verified?

At launch, the most important figures come from OpenAI. Independent reproductions of the new results remain limited.

Sources & Context