{"id":9302,"date":"2026-09-04T09:37:21","date_gmt":"2026-09-04T09:37:21","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=9302"},"modified":"2026-09-04T09:37:21","modified_gmt":"2026-09-04T09:37:21","slug":"openai-launches-gpt-6-astra-its-first-model-to-cross-a-critical-cybersecurity-threshold","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=9302","title":{"rendered":"OpenAI launches GPT-6 Astra, its first model to cross a critical cybersecurity threshold"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">OpenAI launched GPT-6 Astra on Thursday, disclosing that the new flagship model has crossed the \u201cCritical\u201d threshold for cybersecurity risk under its Preparedness Framework, a classification the company said triggers additional deployment restrictions.<\/p>\n<p class=\"wp-block-paragraph\">\u201cGPT\u20116 Astra is rolling out today to a limited set of organizations and over the coming days will become available to all ChatGPT Plus, Pro, Business, and Enterprise users, as well as through the OpenAI API and AWS,\u201d OpenAI <a href=\"https:\/\/openai.com\/index\/gpt-6-astra\/\">said<\/a> in a statement.<\/p>\n<p class=\"wp-block-paragraph\">Enterprise administrators must manually enable Astra for their workspace, since access is off by default at launch, according to the company.<\/p>\n<p class=\"wp-block-paragraph\">Developers can access Astra in the API as gpt-6-astra or through Amazon Bedrock, OpenAI said, priced at $10 per million input tokens and $50 per million output tokens. Pro, Business, and Enterprise users also get a variant called Astra Pro, and the company said Astra supports Zero Data Retention for eligible API customers.<\/p>\n<h2 class=\"wp-block-heading\">Company claims perfect score on exploit benchmark<\/h2>\n<p class=\"wp-block-paragraph\">OpenAI said it tested Astra without production safeguards on ExploitBench, and that the model scored 100%, up from 78.5% for predecessor GPT-5.6 Sol. On ExploitGym, a broader exploit-development benchmark, the company said Astra reached a 42.4% success rate against 30.3% for Sol, while using fewer output tokens.<\/p>\n<p class=\"wp-block-paragraph\">\u201cIts ability to identify and develop zero-day exploits can help defenders find and patch weaknesses, but it also creates a need for stronger safeguards,\u201d OpenAI said in the blog post.<\/p>\n<p class=\"wp-block-paragraph\">OpenAI also tested Astra on vulnerabilities disclosed in the three months before launch, to check whether it could find flaws on its own rather than recalling old exploits from training data. The model found two new zero-day vulnerabilities during that test, OpenAI said, and it is now disclosing both to the software makers involved.<\/p>\n<p class=\"wp-block-paragraph\">Sanchit Vir Gogia, chief analyst at Greyhound Research, said the Critical label is a disclosure event rather than a capability event.<\/p>\n<p class=\"wp-block-paragraph\">\u201cAstra\u2019s capability did not change between 10 August, when OpenAI said Critical capability could not be ruled out, and September 1, when it said the threshold was met,\u201d Gogia noted. \u201cThe testing changed. The model did not.\u201d<\/p>\n<p class=\"wp-block-paragraph\">That inverts the obvious enterprise response, he said.<\/p>\n<p class=\"wp-block-paragraph\">\u201cAstra is now the only frontier model whose cyber capability an enterprise actually knows, because it is the only one measured against a published threshold, while every unlabelled model already sitting behind enterprise credentials has never been measured that way and will not be until its vendor chooses to measure it,\u201d Gogia pointed out. \u201cThose models are not safer.\u201d<\/p>\n<p class=\"wp-block-paragraph\">OpenAI said the public version of Astra will refuse advanced offensive tasks such as generating proof-of-concept exploits, though it plans to loosen those restrictions for vetted defenders through a program called OpenAI Daybreak in the coming weeks.<\/p>\n<p class=\"wp-block-paragraph\">The launch follows <a href=\"https:\/\/www.computerworld.com\/article\/4195494\/openai-launches-chatgpt-work-as-it-broadens-gpt-5-6-rollout-2.html\">OpenAI\u2019s rollout of GPT-5.6 Sol<\/a>, which the company said scored 73.5% on ExploitBench at launch, and comes months after <a href=\"https:\/\/www.computerworld.com\/article\/4191565\/us-reverses-export-restrictions-on-anthropics-fable-5-mythos-5-ai-models-2.html\">Anthropic\u2019s Fable and Mythos models<\/a> were briefly pulled from export markets over similar concerns.<\/p>\n<h2 class=\"wp-block-heading\">Governance shifts from the model to the harness around it<\/h2>\n<p class=\"wp-block-paragraph\">Gogia said the bigger shift is that reasoning now translates into state change, since a wrong chatbot answer is an information problem while a wrong agent action inside a customer-record system is an operating event.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThe governance unit therefore moves off the model,\u201d he said, arguing the relevant question is no longer which model is approved, but how much damage a given identity can do before a control intervenes.<\/p>\n<p class=\"wp-block-paragraph\">Amit Kumar Jena, head of AI development at Kanerika said the visibility problem is concrete: when an agent acts through a user interface, systems of record log the action as a person, so an agent that updates 400 ERP rows shows up as a service account making 400 updates, with no record of which instruction or model version produced them.<\/p>\n<p class=\"wp-block-paragraph\">\u201cYou lose granularity inside the exact system a regulator or auditor will ask to see,\u201d Jena added.<\/p>\n<p class=\"wp-block-paragraph\">OpenAI said it built a new evaluation, informed by an incident involving Hugging Face, to test whether a model given an impossible task would exceed its authorized scope.<\/p>\n<p class=\"wp-block-paragraph\">\u201cCompared to GPT\u20115.6 Sol, which without production safeguards went beyond the authorized target 48% of the time, GPT\u20116 Astra did this in 0% of cases,\u201d the statement added.<\/p>\n<p class=\"wp-block-paragraph\">Gogia said the more uncomfortable finding is that Astra behaves better and watches worse: OpenAI reports decreased chain-of-thought monitorability against Sol, with Astra less likely to reveal incriminating reasoning, and its monitoring covers OpenAI\u2019s own external deployment but nothing published extends that telemetry to customers. \u201cOpenAI being able to monitor Astra does not mean an enterprise can audit Astra,\u201d Gogia said.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>OpenAI launched GPT-6 Astra on Thursday, disclosing that the new flagship model has crossed the \u201cCritical\u201d threshold for cybersecurity risk under its Preparedness Framework, a classification the company said triggers additional deployment restrictions. \u201cGPT\u20116 Astra is rolling out today to a limited set of organizations and over the coming days will become available to all [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":9303,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-9302","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9302"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9302"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9302\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/9303"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9302"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9302"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9302"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}