OpenAI Releases GPT-6 Astra, the First Model It Rates a 'Critical' Cyber Risk

OpenAI's new frontier model can find unknown software flaws and write working exploits with little human help — and the company says so itself, in the safety card it published alongside the launch.
OpenAI on Friday introduced GPT-6 Astra, the most capable system it has ever shipped, and paired the announcement with an unusually blunt admission: by the company's own internal scale, the model is a critical cybersecurity risk.
What the 'Critical' label actually means
OpenAI grades its frontier systems on a tiered capability framework, with "Critical" sitting at the top. Astra is the first model the company has released broadly at that level. According to the documentation published with the launch, the system can identify software vulnerabilities that were not previously known and then construct methods to exploit them, working largely on its own once pointed at a target.
That is a meaningful shift in what these tools are. Earlier models could read code, explain it, and suggest patches. A system that discovers a novel flaw and builds a working exploit around it is doing the job, not assisting with it.
OpenAI says the classification triggered additional safeguards before release, including a staged rollout and tighter access controls on the highest-risk capabilities. The company has not published the full detail of those mitigations.
Who gets it, and when
Access is deliberately narrow at first. A limited set of organisations receives the model ahead of everyone else, with OpenAI citing the need to watch how the system behaves under real workloads before opening the gates.
After that initial window, Astra is scheduled to reach ChatGPT Plus, Pro, Business and Enterprise subscribers. Developers will be able to call it through the OpenAI API, Microsoft Azure and Amazon Bedrock — the same three-channel distribution OpenAI has used for its recent releases.
The price tag
API pricing starts at $10 per million input tokens and $50 per million output tokens. That is frontier-tier pricing, and it tells you who the model is aimed at: teams running long, complex, high-value tasks where the output justifies the bill, not consumer chat traffic.
The wide gap between input and output rates also hints at how OpenAI expects Astra to be used — fed large amounts of context, then asked to produce comparatively concise, high-stakes results.
The uncomfortable part
There is an obvious tension in a company shipping a product while simultaneously publishing a document explaining that the product is dangerous. OpenAI's argument, consistent with its position over the past two years, is that disclosure plus controlled deployment beats the alternative of releasing quietly or letting a less careful competitor set the norm.
Security researchers have made the counter-argument for just as long: capabilities like automated vulnerability discovery do not stay contained to authorised users, and defenders historically adopt new tooling more slowly than attackers do. A model that can find zero-days at scale helps whoever is willing to point it at a network first.
Neither side of that argument is new. What is new is that the capability is now a shipping product with a published price list.
What to watch next
Three things will say more than the launch post does. First, whether enterprise security teams are given the same access as everyone else, or whether the exploit-relevant capabilities stay gated. Second, how quickly rival labs match the capability and whether they adopt similar disclosure. Third, whether regulators — who have spent 2026 largely focused on data centres, energy and copyright — treat a self-declared critical cyber capability as the trigger for a harder look.
OpenAI has framed Astra as a step toward systems that carry out serious technical work end to end. On the evidence of its own safety documentation, that includes the technical work nobody wants automated.
Related Articles
TechnologyIceland-based Treble raises $18 million for its voice simulation platform
Voice AI has emerged as one of the hottest sectors in AI, with investors pouring in billions of dollars to serve use cases ranging from automating customer support and sales calls to creating meeting notetakers and developing AI smart glasses that use voice as the primary interaction surface. Me...
Technology

