OpenAI shipped GPT-6 Astra on September 3, 2026, and for the first time attached a label the company has never used before: Critical. Under OpenAI's own Preparedness Framework, that's the top rung for cyber risk, and Astra is the first model the company has ever released while sitting on it.

  • OpenAI released GPT-6 Astra on September 3, 2026, calling it the most capable model it has built.
  • Astra is the first OpenAI model to hit the "Critical" cybersecurity threshold under the Preparedness Framework, meaning it can find and chain novel exploits with minimal human help.
  • President Greg Brockman said "Astra can really do anything a human can do with a computer" and framed the release as "the AGI era."
  • Access starts narrow: cybersecurity defenders in OpenAI's Daybreak program get it first, with enterprise and consumer rollout to follow "in the coming days."
OpenAI's Preparedness Framework risk tiers A four-tier ladder from Low to Critical cyber risk, with GPT-6 Astra marked as the first model to reach the Critical tier. PREPAREDNESS FRAMEWORK · CYBER TRACK Low baseline models Medium assists a novice attacker High GPT-5.6-Cyber sat here Critical GPT-6 Astra, first ever finds and chains zero-days on hardened targets, largely unassisted genztech.blog
Fig 1 Astra is the first model to sit in the framework's top cyber-risk tier, one step above where GPT-5.6-Cyber landed a month earlier.

What did OpenAI actually announce?

GPT-6 Astra is OpenAI's new flagship model, and the company is treating the release less like a routine upgrade and more like a threshold crossing. In its own writeup, OpenAI said Astra "meets the Critical threshold in cybersecurity under our Preparedness Framework," the internal rubric the company built to decide when a model is dangerous enough to need extra guardrails before it ships. Concretely, that means Astra can identify and build working zero-day exploits against hardened, real-world systems, and can plan out a multi-step attack from a short, high-level goal without much hand-holding. Brockman's summary was blunter: "Astra can really do anything a human can do with a computer."

RelatedOpenAI Pauses Astra Over First 'Critical' Cyber Rating

The model isn't going to everyone at once. OpenAI is opening access first to companies in its Daybreak program, an application-only track for cybersecurity defenders who get early access specifically so they can build detection and defense before offensive use becomes widespread. ChatGPT Plus, Pro, Business and Enterprise plans, plus the API and an Amazon Web Services integration, follow in what OpenAI is calling the coming days rather than a fixed date.

Why does "Critical" actually matter here?

OpenAI's Preparedness Framework has four tiers, and until this week no released model had touched the top one. GPT-5.6-Cyber, which OpenAI shipped on August 10, already answered 95% of advanced offensive-security prompts correctly, and that model sat at High. Astra clears the bar OpenAI set for Critical: autonomous discovery of previously unknown vulnerabilities across many hardened systems, not just a narrow benchmark suite. That distinction is the whole story. A model that's good at CTF-style exploit puzzles is useful and a little alarming. A model that can be pointed at a live, patched, professionally defended system and told "get in" is a different category of tool, and OpenAI is saying, in writing, that Astra is the second kind.

The company paired the release with two safety essays rather than one. "Path to Astra" lays out the capability jump and the safeguards attached to it; a companion post, "Responding to the next frontier of critical cyber capabilities," goes further into how OpenAI is trying to pace access so defenders get a head start on attackers. OpenAI also said Astra went through the White House's voluntary pre-deployment vetting process before release, the same channel frontier labs have used since 2025 to get an outside sanity check on models that trip safety thresholds.

  1. Aug 1, 2026An internal Astra build solves ten open math and theoretical CS problemsfirst public signal of the model's raw capability
  2. Aug 10, 2026OpenAI pauses Astra development after it hits a first "Critical" cyber rating internallyunreleased at this point
  3. Aug 10, 2026GPT-5.6-Cyber ships separately, answering 95% of offensive-security promptsHigh tier, not Critical
  4. Sep 1, 2026Astra formally crosses the Critical cybersecurity threshold under the Preparedness Frameworkconfirmed by OpenAI
  5. Sep 3, 2026GPT-6 Astra launches to Daybreak participants, wider access to followenterprise and consumer rollout "in the coming days"

Who gets access, and who's affected first?

Security teams are the first audience, by design. Daybreak exists so that the people defending networks get to run Astra against their own systems before the same capability is broadly available to attackers, red teams, and everyone in between. That's a real head start, but it's a short one if history with OpenAI's own release cadence is a guide: High-tier access has typically widened within weeks, not months. CISOs at any organization running internet-facing infrastructure should treat this as a compressed timeline for patching known weaknesses, not a distant hypothetical. If Astra can find a zero-day, so can the version of Astra someone else is running six months from now with fewer safeguards attached.

For developers building on top of OpenAI's models, the near-term news is capability, not just risk: Astra also posts stronger scores on general agentic tasks, autonomously operating a computer to fill out spreadsheets or stand up a website from a description, which is the more mundane but arguably more commercially important half of the release.

RelatedOpenAI's GeneBench-Pro Exposes AI's Genomics Judgment Gap

What it means for the market

OpenAI itself doesn't trade, but the companies around it do. Microsoft remains OpenAI's largest backer and Azure customer, so a flagship model that OpenAI is willing to call a step toward AGI is a direct signal for Azure AI revenue guidance next quarter. Nvidia benefits on the compute side regardless of who wins the model race, since Critical-tier capability doesn't come cheap to train or serve. The more interesting reaction is at Anthropic and Google DeepMind: both have their own frontier-safety frameworks with a comparable "high-risk" tier, and neither has yet shipped a model they're willing to publicly badge at that level. Whether they follow OpenAI's lead on disclosure, or quietly ship similar capability without the label, is worth watching over the next month. Cybersecurity vendors focused on AI-assisted defense (the CrowdStrikes and Palo Alto Networks of the world) have the cleanest read-through: a Critical-tier offensive model in the wild is a demand driver for their tooling, not a threat to it.

ModelCyber tierReleasedAccess
GPT-6 AstraCriticalSep 3, 2026Daybreak first, then paid tiers + API
GPT-5.6-CyberHighAug 10, 2026General availability
Claude (Anthropic, current frontier)No public Critical-tier disclosureGeneral availability
Gemini (Google DeepMind, current frontier)No public Critical-tier disclosureGeneral availability

What happens next?

What to watch · Sep-Oct 2026
  • Rollout pace. Watch how fast Astra moves from Daybreak-only to general API access. A slow, staged expansion would suggest OpenAI genuinely means the safeguards; a fast one suggests the Critical label was as much marketing as caution.
  • Rival disclosures. If Anthropic or Google DeepMind publish their own Critical-tier admission in the next few weeks, that confirms the whole frontier is at this capability level and OpenAI just said it first.
  • Real-world exploit reports. The first confirmed case of an Astra-assisted attack, or an Astra-assisted defense catching one, will do more to calibrate how serious this is than any benchmark number.
  • Pricing and rate limits. OpenAI hasn't published API pricing for Astra yet; expect it to land at a premium over GPT-5.6 given the compute cost of Critical-tier capability.

Our take

The AGI framing is doing a lot of marketing work, and it's worth separating from the part of this announcement that's actually new. Calling a model "AGI" is a vibe, not a benchmark. Crossing a self-defined Critical cyber threshold and publishing that fact is a concrete, falsifiable claim, and it's the first time any lab has made one this specific about its own release. That's the story. Whether Astra can autonomously write a website is a nice demo. Whether it can autonomously find a zero-day in a bank's authentication system with minimal supervision is the thing every CISO reading this should actually be planning around, starting now rather than when the general-availability rollout lands.

Primary sources

Original analysis by GenZTech Team. Source: OpenAI.