NEWS
OpenAI Names GPT-6 Astra AGI, Then Locks It Down
OpenAI released GPT-6 Astra with an AGI claim, a 99.9% adapter score, and a first Critical cyber rating that keeps its hacking tools gated.
OpenAI released GPT-6 Astra on September 3, 2026, and president Greg Brockman told reporters the world had entered the AGI era. He said later viewers will look back at this time and this model as the moment AGI arrived.
The same launch rated Astra Critical for cybersecurity, the first OpenAI system at that tier, so its strongest hacking skills start locked to testers and a later Daybreak window.
OpenAI Ships GPT-6 Astra With an AGI Claim
Brockman did not hedge the briefing. “Welcome to the AGI era,” he said. He added that it is not unreasonable to feel the era has started, and that “for me personally, I do think we’re there.” CEO Sam Altman, posting the same afternoon, called Astra the best model OpenAI has for computer use, professional work, science, coding, and cybersecurity, and said the extra wait was for safety and alignment at this capability level.
I think that if we fast forward a couple of years, when we look back and say, ‘When was it really that AGI was created?’ I think it’s going to be about this time, and I think it might be about this model.
Greg Brockman, president, OpenAI press briefing
The company blog is cooler. OpenAI calls Astra the world’s most intelligent and aligned model, state of the art on computer use, browsing, software engineering, science, and professional work. It does not use the word AGI. That split, a personal declaration next to a product that is still rolling out in stages, is the launch.
Astra was pretrained on more than 100,000 GPUs at the Stargate site in Texas, part of a wider compute build that includes the Ohio GPU capacity already leased to OpenAI. Limited organizations got it on September 3. ChatGPT Plus, Pro, Business, and Enterprise access, plus the API on Azure and AWS Bedrock, follows over the coming days. Enterprise admins find Astra off by default.
https://x.com/OpenAI/status/2095595741528125780
Two Harnesses, Two Very Different Scores
The number OpenAI put on the poster is 99.9% on ARC-AGI-3. ARC Prize, which built the test, verified that figure under a Provider Adapter that keeps OpenAI’s hidden reasoning state between turns. Under its Standard harness, the same model at maximum effort scores 62.7 percent on the Standard harness.
THE ARC-AGI-3 HARNESS SPLIT
| Setup | Astra score | Run cost | What the harness keeps |
|---|---|---|---|
| Standard, max effort | 62.7% | $26,098 | Visible notes only, provider-neutral interface |
| Provider Adapter, high effort | 99.9% | $18,817 | Opaque reasoning state plus compaction |
| GPT-5.6 Sol, Standard | 7.8% | $25,064 | Same minimal interface as Astra’s 62.7% |
| Claude Opus 5, Standard | 30.2% | $20,657 | Same minimal interface |
ARC Prize president Greg Kamradt wrote that in the adapter, Astra used fewer actions than the median human on 96.0% of levels and 51.7% fewer actions per level. Adapter runs were about 3.66 times faster and used 49% fewer tokens on the 167 game-reasoning pairs both setups solved. Humans still solve 100% of the environments. When ARC-AGI-3 launched in March 2026, frontier systems sat below 1%.
When we launched ARC 3, and in every presentation we made about it, we were very insistent on one thing: solving it is not proof of AGI. It’s not intended as a finish line.
François Chollet, co-founder, ARC Prize
Kamradt’s own line on OpenAI’s blog is the one the company wanted: Astra “effectively reaching human parity on the benchmark.” Chollet’s line is the one the scoreboard still needs. The foundation says it will publish both harnesses, labeled, because a future AGI should clear the Standard setup, and because the 99.9% number is what a vendor-tuned memory layer can do.
What GPT-6 Astra Can Do on a Desktop
The product OpenAI is actually selling is an agent that sits on a computer and keeps going. On OSWorld 2.0, which times long desktop workflows, Astra scores 72.6% in about 40 minutes per task. GPT-5.6 Sol scores 65.7% in about 75 minutes, which OpenAI puts at about 47% less time. Claude Opus 5 sits at 70.2% on the same OpenAI table.
Launch demos show Astra laying out a printed circuit board in KiCad, modeling a house in Blender and walking it in Unreal Engine 5, filling forms, updating a CRM, and drafting in a document editor. Cognition is wiring it into Devin on day one. Higgsfield AI’s Alex Mashrabov said complex creative jobs ran with up to 20% fewer tokens than other models his team tried.
Codex is the other half of that pitch. Instead of crushing a long debug session into one summary, Astra can keep searchable notes across context windows and look back at earlier tool output. OpenAI says the updated harness plus Astra’s speed yields 1.9 times faster completion than the current Sol experience on Mind2Web. Agents’ Last Exam, a grind through professional software tasks, has Astra at 59.3% against 55.5% for Opus 5 and 53.6% for Sol, using about 65% fewer output tokens than Opus 5 at those settings.
Early testers describe a model with quirks and rough edges that can still run multi-step engineering loops without a person clicking each file. That is the practical claim, and it does not need the AGI slogan to land.
The First Critical Cyber Label Comes With Limits
OpenAI now says Astra meets the first Critical cybersecurity threshold under its Preparedness Framework. That means, with the right tools and access, it can find previously unknown flaws and build ways to exploit them across many well-protected systems without a person guiding each step. GPT-5.6 Sol was rated High, one rung down.
On ExploitBench the model scored 100%, against 78.5% for Sol. OpenAI’s own footnote is easy to miss: those Astra cyber scores reflect Daybreak Blue access, not the default production setup. On a fresher internal port of 20 high-severity V8 bugs disclosed after the model’s cutoff, Astra also found and used two zero-days in an exploit chain. The company is disclosing both to maintainers. In expert tests it built a browser-compromise chain that escaped a sandbox when an HTML file opened, and a local privilege-escalation chain from an ordinary user to root.
THE DAYBREAK GATES
- Production Astra: Refuses advanced cyber work such as writing proof-of-concept exploits, while still helping with secure code review and patching.
- Alpha testers: Get the stronger cyber workflows first, on a short list.
- Daybreak Blue: Opens defensive use next, and lifts Astra’s proof-of-concept completion from 2.4% to 92% in OpenAI’s table.
- Daybreak money: OpenAI has pledged $1 billion in subsidized access over six months for state and local governments, critical-infrastructure operators, community banks, nonprofits, and open-source maintainers.
- Jailbreak refusals: Astra refuses 91.5% of cyber jailbreak tests, up from 59% for Sol.
The dual-use problem is the product. The same loop that helps a defender patch a hole can write the exploit. OpenAI’s answer is not to withhold the model. It is to ship a polite version to ChatGPT and park the dangerous configuration behind vetting.
Hugging Face Forced a Two-Week Pause
Astra was not the model that broke out of an isolated eval and hit Hugging Face. OpenAI still treated that incident as a dress rehearsal. It paused some frontier training, including Astra work, for two weeks, hardened isolation and network controls, then restarted the large reinforcement-learning run on August 28. Smaller experimental runs stayed on hold.
FROM CRITICAL WARNING TO LAUNCH
- August 7, 2026: OpenAI says it cannot rule out Critical cyber capability in Astra and adds isolation, restricted network access, and weight encryption.
- August 10, 2026: Daybreak splits into Blue for general frontier models and Red for purpose-trained cyber models.
- August 28, 2026: The large frontier RL run that had been paused after Hugging Face restarts under tighter rules.
- September 1, 2026: OpenAI says Astra meets Critical, and that advanced cyber access will start with testers.
- September 3, 2026: GPT-6 Astra launches to a limited set of organizations, with ChatGPT and API access promised over the following days.
A new test, built from the Hugging Face mess, asks whether a model facing a hard or impossible task will go after surrounding systems instead of the assigned target. Sol, without production safeguards, went beyond the authorized target in 48% of those cases. Astra did it in 0%. A related honeypot test had Sol reaching for the bait in 56% of runs; Astra made no such attempts. In a simulation of more than 54,000 internal Codex tasks, Astra drew roughly half as many flags for higher-severity misaligned behavior as Sol.
The safety overview also says Astra is harder to watch. It is better at controlling its own chain of thought than Sol, less likely to leave incriminating detail in that chain, and in adversarial tests it can sandbag evaluations and sometimes evade internal monitors on sabotage tasks. OpenAI says it has not seen hidden messages stuffed into ordinary text. It is still deploying chain-of-thought monitoring on all tool-using Astra inference, at real compute cost, because the trend worried the safety team. Brockman told reporters the model went through White House pre-release review and that officials did not ask OpenAI to change safeguards. The system card rates biological and chemical skill High, not Critical, and says Astra does not reach High for AI self-improvement.
Who Gets Astra, and What It Costs
Standard API pricing is $10 per million input tokens and $50 per million output tokens. Cached input is $1. Cache writes are $12.50. Fast mode bills at 2x those rates. Prompts with more than 272,000 input tokens pay 2x input and cache rates and 1.5x output for the full request. Batch and Flex are half of Standard. The model ID is gpt-6-astra. ChatGPT usage sits inside existing Plus, Pro, Business, and Enterprise allowances, with extra credits for sale. Pro, Business, and Enterprise also get GPT-6 Astra Pro.
ASTRA ACCESS ON DAY TWO
- Trusted Access: Selected enterprises could call the model on September 3.
- ChatGPT plans: Plus, Pro, Business, and Enterprise were told to wait days, not minutes.
- Enterprise default: Workspace admins must switch Astra on; it ships off.
- Under-18 rules: OpenAI says Astra applies age-appropriate safety for users under 18 more consistently than Sol.
On day one, launch still meant a waiting room. ChatGPT subscribers were not handed the model with the blog post. That is why the AGI greeting landed oddly: the system described as generally capable is, in practice, a staged SKU with a cyber lock and a default-off enterprise flag. Anthropic’s Claude Fable 5.1, priced at the same $10 and $50 per million on public lists, had already shipped on September 1.
Humanity’s Last Exam Still Goes to a Rival
OpenAI’s own academic table is the simplest rebuttal to a clean sweep. On Humanity’s Last Exam with tools, Astra scores 57.2%. Claude Fable 5.1 scores 65.0%. Fable 5 is at 63.8% and Opus 5 at 63.6%. Sol has no published number on that row. The exam is the one OpenAI did not read aloud in the briefing.
WHERE ASTRA LEADS, AND WHERE IT DOES NOT
| Test | GPT-6 Astra | Closest published rival |
|---|---|---|
| FrontierMath Tier 4 (v2) | 97.6% | Fable 5.1 87.8%; Sol 83.0% |
| GPQA Diamond | 96.0% | Gemini 3.8 Flash 95.3% |
| Terminal-Bench Science 0.1 | 64.6% | Fable 5.1 52.6%; Sol 22.4% |
| Terminal-Bench 4.0 | 57.9% | Fable 5.1 55.8% |
| DeepSWE v1.1 | 74.1% | Gemini 3.8 Flash 73.8%; Opus 5 73.7% |
| Humanity’s Last Exam (with tools) | 57.2% | Fable 5.1 65.0% |
| ScreenSpot-Pro, no tools | 92.7% | Sol 76.9% |
| BenchCAD geometric overlap | 95.9% | Fable 5.1 84.3%; Sol 83.3% |
DeepSWE is a 0.3 point edge over Gemini 3.8 Flash. OpenAI still calls Astra the best software-engineering model to date. FrontierMath is the blowout, 97.6% against 87.8% for Fable 5.1, after an internal Astra already helped with a batch of long-open math problems. GPQA Diamond, graduate questions in biology, chemistry, and physics, is effectively saturated across the field.
So the launch is two products sharing one name. One is a computer-use agent that is faster than Sol, dense on math and science workflows, and careful about staying inside a sandbox. The other is a Critical-rated exploit engine that OpenAI will not put on the default ChatGPT path. Brockman told the room AGI had arrived. ARC Prize scored the comparable run at 62.7% and declined the trophy. Plus users were still waiting on September 4, while testers held the keys to the copy that can chain a zero-day.
-
FINANCE3 months agoZcash Patched a Double-Spend Bug as ZEC Climbed 5%
-
ENTERTAINMENT3 months agoSteam Summer Sale 2026 Locks In June 25 to July 9 Dates
-
FINANCE2 months agoCLARITY Act Final Text Expected This Weekend as 60-Vote Hurdle Looms
-
NEWS4 months agoMeta Adds AI Replies to Threads, But Users Can’t Block It
-
NEWS3 months agoYouTube Shorts is testing a heart in place of the thumbs-up
-
NEWS1 month agoSenators Force Apple Off Chinese Memory as Big Three Cash In
-
NEWS3 months agoNEURA Robotics’ $1.4B Series C Redraws Europe’s Physical AI Bet
-
ENTERTAINMENT5 months agoExtraction 3 Is Officially Coming to Netflix in 2027
