OpenAI's GPT-6 Astra is here — see what changed in computer use, coding, and cybersecurity benchmarks, plus what OpenAI admits about the risks.
GPT-6 Astra: what OpenAI's newest model actually changes
OpenAI's latest flagship model rolled out this month, and the pitch is bigger than a normal version bump. Here's what it's built for, how it compares to the model before it, and what's changed on the safety side.
What it is
GPT-6 Astra is OpenAI's newest frontier model, unveiled and given a limited preview on September 3, 2026, with wider access to paid users following the next day. OpenAI is positioning it around four areas in particular: extended computer/browser use, professional document and spreadsheet work, software engineering, and scientific research — alongside a notable jump in cybersecurity-relevant capability.
The release follows a July 2026 incident involving OpenAI's Hugging Face deployment, which the company has said pushed it to add extra safeguards before shipping this generation of models.
The headline change: computer use
OpenAI is framing Astra primarily as an agent that operates a computer rather than just a chat model. In their own evaluations, it completes computer-use tasks meaningfully faster than its predecessor while scoring higher on accuracy — OpenAI cites roughly 47% less time per task on one internal benchmark, with a higher completion score to go with it. The practical examples OpenAI showcases include filling out tax forms, updating CRM records, building and QA-testing simple websites, and troubleshooting on-screen problems without step-by-step hand-holding.
Figures as reported by OpenAI in its own benchmark disclosures — treat vendor-reported numbers with the usual grain of salt until independently reproduced.
Where it's actually available
- Rolling out to ChatGPT Plus, Pro, Business, and Enterprise users, with Pro/Business/Enterprise also getting a higher "Astra Pro" tier.
- Available via the OpenAI API as
gpt-6-astra, and through Microsoft Azure and AWS Bedrock. - API pricing is listed at $10 per million input tokens and $50 per million output tokens, with separate rates for cached tokens and a faster (pricier) processing mode.
- Enterprise workspace admins have to turn it on manually — it's off by default at launch.
The cybersecurity angle — and why it matters
This is the part worth actually paying attention to. OpenAI classifies Astra as meeting the "Critical" tier of cyber capability under its own internal risk framework — meaning that, without the production safety layer, testers found it could identify and weaponize previously unknown software vulnerabilities, including in hardened browsers and operating systems.
Separately, OpenAI reports Astra is considerably more resistant to prompt-injection attacks than its predecessor, and that in internal testing it was far less likely to attempt working around access restrictions it was deliberately given — including in scenarios engineered to make bypassing easy.
The alignment claims
OpenAI describes Astra as its "most aligned" model to date, meaning it more reliably stays inside the scope of what it was actually asked to do rather than improvising beyond it — including in an internal test built specifically in response to the July Hugging Face incident, where the prior model went beyond its authorized target in roughly half of adversarial test cases and Astra reportedly did not. It's also reported to be several times less likely to make inaccurate claims about its own capabilities compared to the previous model. As with the benchmark numbers, these are OpenAI's own reported evaluations rather than independently audited figures.
Read the source
We're summarizing here — for the full write-up, benchmark tables, and OpenAI's own framing, go straight to their announcement.
Note: this page covers a different topic than the rest of this site's Magisk/Android content — included here as a standalone news writeup.
COMMENTS