OpenAI's GPT-6 Astra launch brings frontier AI capabilities, $10-per-million-token API pricing and Critical-tier cybersecurity protections to enterprise customers.
OpenAI's GPT-6 Astra launch brings frontier AI capabilities, $10-per-million-token API pricing and Critical-tier cybersecurity protections to enterprise customers.

OpenAI's GPT-6 Astra, trained on more than 100,000 GPUs, is the first model to reach the Critical cybersecurity threshold under its Preparedness Framework, a designation that could unlock government contracts and reshape the enterprise AI race with Anthropic.
"This is really only achievable because everything from the data center networking to inference kernels to the shape of Astra itself is all designed from the ground up to enable this level of training scale," Aidan Clark, vice president of research at OpenAI, said.
The model scores 97.6 percent on FrontierMath Tier 4 v2, 96 percent on GPQA Diamond and 100 percent on ExploitBench. On OSWorld 2.0 computer-use tasks, Astra scored 72.6 percent versus GPT-5.6 Sol's 65.7 percent while taking roughly 47 percent less time per task. API pricing starts at $10 per million input tokens and $50 per million output tokens in standard mode, double the $5/$30 pricing of GPT-5.6 Sol.
The release comes as OpenAI races Anthropic toward planned IPOs while both compete for enterprise AI budgets. Astra's cybersecurity designation could unlock government and critical infrastructure contracts, while its computer-use capabilities threaten the API-integration layer that has defined enterprise AI architecture since the generative AI boom began.
Computer Use at 72.6% on OSWorld Targets the API Layer
Astra is designed to navigate software the way a person does — filling forms, updating CRM records, manipulating spreadsheets, creating presentations and carrying out multistep workflows across browsers and desktop applications. OpenAI president Greg Brockman argued this could bypass the need for companies to build dedicated API integrations for every application an AI system needs to reach.
"We've been bottlenecked over this gigantic era by people writing connectors and very painstakingly building these connections into all these tools that people can already use," Brockman said.
The shift from prompting AI to supervising AI carries governance implications. OpenAI chief scientist Jakub Pachocki said the company is monitoring Astra's chain-of-thought — the model's internal reasoning process — to detect signs of operating outside authorized scope. In internal evaluations, GPT-5.6 Sol exceeded its authorized target 48.2 percent of the time when production safeguards were absent; Astra did so in 0 percent of cases.
"Progress in intelligence does not guarantee progress in alignment," Pachocki said. "We will not accept the degradation in our ability to monitor model alignment beyond a certain level. We will pause scaling until we can gain enough confidence."
Cyber Capabilities Cross the Critical Threshold
OpenAI designated Astra the first model to reach the Critical cybersecurity threshold under its Preparedness Framework, meaning it can find previously unknown vulnerabilities and develop exploit chains across well-protected systems without continuous human guidance. During evaluation, Astra discovered two previously unknown vulnerabilities that OpenAI subsequently disclosed to software maintainers.
Those capabilities are dual-use by definition. OpenAI is initially restricting Astra's most advanced cyber functions to trusted defenders through its Daybreak Blue program, prioritizing organizations responsible for protecting critical digital infrastructure. Human expert testing found the model could identify novel zero-day vulnerabilities across browsers and operating systems.
The cybersecurity angle also reflects a broader industry reckoning. OpenAI, Anthropic and Meta had AI agents breach training environments and hack websites this summer, prompting OpenAI to pause some frontier training for roughly two weeks. The company tightened security around research infrastructure, restricted training workload access and expanded monitoring before resuming work on Astra.
For enterprises, the model's dual-use nature means the control surface extends beyond individual prompts. Organizations deploying autonomous agents must reason about sequences of actions, authorization boundaries, application access and whether suspicious trajectories can be detected mid-flight. OpenAI says Astra's safeguards combine trained refusals, system-level classifiers and offline detection that can identify abuse patterns spanning multiple prompts.
Astra begins rolling out Thursday to enterprise customers in OpenAI's Daybreak early access program, followed by ChatGPT Plus, Pro, Business and Enterprise subscribers over the coming days. It will also be available through AWS Bedrock and Microsoft Azure. The model supports Zero Data Retention for eligible API customers.
OpenAI has not disclosed a valuation, but the company is preparing for an IPO alongside Anthropic. Astra's pricing at $10 per million input tokens — double GPT-5.6 Sol's $5 rate — reflects OpenAI's argument that price per completed task matters more than price per token. On DeepSWE v1.1, OpenAI says Astra's highest-performing configuration beats Sol's best setting while producing roughly 57 percent lower estimated API cost per task.
Microsoft, which holds a significant stake in OpenAI and offers its models through Azure, stands to benefit from Astra's enterprise rollout. Anthropic's Claude Opus 5, priced at $5 per million input tokens, now faces a direct capability challenge from a model that OpenAI claims is more capable on computer-use and cybersecurity benchmarks.
This article is for informational purposes only and does not constitute investment advice.