OpenAI ships a model it rates critical for cybersecurity capability

AI-generated illustrationAI-generated illustration
OpenAI released GPT-6 Astra on 3 September 2026. The headline feature is computer use: the model drives a machine the way a person does, moving through spreadsheets, forms and web pages, which president Greg Brockman described as running at superhuman speed.
The more consequential detail is the safety classification. Astra is the first OpenAI model the company places at the critical cybersecurity capability threshold of its own Preparedness Framework, meaning it can find and exploit previously unknown security flaws without human oversight under some conditions. OpenAI is releasing it accordingly: first to enterprise customers inside a cybersecurity programme called Daybreak, then to Plus, Pro and Enterprise users and through the API. Aidan Clark, a vice-president of research, said training used more than 100,000 GPUs.
A company grading its own model against its own framework is not an independent finding, and “critical” here is OpenAI’s word inside OpenAI’s scheme. But the classification is a commitment as much as a claim: having named the threshold in advance, the company has staged the rollout around it rather than shipping to everyone at once.
Brockman went further and called this the start of the AGI era. That part is a position, not a result.