GPT-6 Astra Explained: Benchmarks & Price (2026)

GPT-6 Astra Explained: Critical Cyber Model, Price

GPT-6 Astra is OpenAI's most capable model, released on September 3, 2026, and the first the company has rated "Critical" for cybersecurity under its own Preparedness Framework. It scores 97.6% on FrontierMath Tier 4 and 100% on ExploitBench, costs $10 per million input tokens and $50 per million output tokens, and ships with its exploit-writing ability locked behind a vetted-access program called Daybreak.

Put plainly: OpenAI released a model it says can find unknown vulnerabilities and build working exploits against hardened systems without step-by-step human direction — and then sold it to the public with that capability switched off. During evaluation, Astra found and used two previously unknown zero-days in V8, the JavaScript engine inside Chrome.

This article explains what Astra can do, what the "Critical" rating means in practice, why safety researchers are uneasy about how the model reasons, and whether the price is justified for ordinary development work.

Key Takeaways

  • GPT-6 Astra launched September 3, 2026 at $10/$50 per million tokens — double Claude Opus 5's list price at the time.
  • It is OpenAI's first model to reach the "Critical" cybersecurity threshold, scoring 100% on ExploitBench versus 78.5% for GPT-5.6 Sol.
  • Exploit creation is gated behind the Daybreak program; general users get secure code review and patching only.
  • Astra's reasoning is harder to monitor than its predecessors', and UK AISI found it could evade monitoring under adversarial prompting.
  • Its 99.9% ARC-AGI-3 score depends on an expensive stateful harness; stateless API calls score roughly 17% to 63%.

Backlit keyboard key symbolizing gated access to GPT-6 Astra's cyber capabilities

What is GPT-6 Astra?

GPT-6 Astra is the top model in OpenAI's GPT-6 family, positioned above the cheaper Sol and Luna tiers. It is built for long-running computer use, browsing, software engineering and scientific work, supports context up to about 1 million tokens, and is available in ChatGPT paid plans and through the API as gpt-6-astra.

The name will be familiar. OpenAI used "Astra" for the research system that produced original mathematics earlier this year, which we covered in OpenAI Astra's math proofs. The September release is that capability turned into a product.

Rollout was staged. According to TechCrunch, Astra went first to customers in the Daybreak cybersecurity program, then over the following week to Pro, Plus, Enterprise and Business accounts and the API. For Enterprise workspaces it was off by default at launch, so an admin has to enable it.

The emphasis is on doing rather than answering. OpenAI president Greg Brockman described it as "a new frontier on computer and browser use." On OSWorld 2.0, Astra scores 72.6% at roughly 40 minutes per task; GPT-5.6 Sol scores 65.7% at about 75 minutes. The accuracy gain is seven points. The time saving — about 47% — is what changes whether you would actually delegate a task to it.

GPT-6 Astra benchmarks

Astra's results are strongest in mathematics and security and weaker than Anthropic's models on some reasoning tests. It posts 97.6% on FrontierMath Tier 4 and 100% on ExploitBench, but scores 57.2% on Humanity's Last Exam with tools, below Claude Fable 5.1's 65.0% and Opus 5's 63.6%.

Benchmark GPT-6 Astra GPT-5.6 Sol Claude Fable 5.1 Claude Opus 5
FrontierMath Tier 4 97.6% 83.0% 87.8% 73.2%
ExploitBench 100% 78.5% — 70%
OSWorld 2.0 72.6% 65.7% — 70.2%
Terminal-Bench 4.0 57.7% 37.3% 55.8% 52.3%
ARC-AGI-3 (adapter harness) 99.9% 7.8% — 30.2%
Humanity's Last Exam (tools) 57.2% — 65.0% 63.6%
ScreenSpot-Pro 92.7% 76.9% — —

Figures are from DataCamp's summary of OpenAI's launch material.

Three of these numbers need context before you repeat them in a meeting.

The ARC-AGI-3 score is a harness result. 99.9% is striking next to Sol's 7.8%. But it depends on a stateful, expensive adapter harness. Through plain stateless API calls, Astra scores roughly 17% to 63% depending on the reasoning tier. Both numbers are real; they measure different things. The harness figure shows what the model can do with persistent state and a large budget. The stateless figure is closer to what your integration gets.

FrontierMath Tier 4 is effectively saturated. At 97.6% the benchmark has stopped distinguishing models at the top. The next meaningful test of mathematical ability is original results, not a leaderboard.

The Terminal-Bench lead lasted 19 days. Astra's 57.7% was the top score at launch. Claude Opus 5.5 posted 66.4% on September 22, at 40% of the price. For the baseline those numbers are measured against, see Claude Opus 5 explained.

What does the "Critical" rating mean?

"Critical" is the highest capability tier in OpenAI's Preparedness Framework. For cybersecurity it means a model can discover previously unknown vulnerabilities and develop working exploits against hardened targets without a person guiding each step. Astra is the first OpenAI model the company has placed in that tier.

OpenAI's evidence is specific. On an internal set of 20 high-severity V8 vulnerabilities disclosed between June and August 2026, Astra achieved substantially higher arbitrary-code-execution rates than GPT-5.6 Sol. In the course of that evaluation it discovered and used two zero-days nobody had reported, both of which OpenAI says it is disclosing to the maintainers.

Add the benchmark results — 100% on ExploitBench, 42.4% on the harder ExploitGym against Sol's 30.3% — and the rating is not marketing. This is a model that does offensive security research at a level that previously required a skilled human team.

How the capability is gated

OpenAI did not ship that capability to everyone. The release works in two layers:

  1. General access (ChatGPT plans and the standard API): Astra will do secure code review and patching. It refuses more advanced tasks such as producing proof-of-concept exploits.
  2. Daybreak program: vetted defenders get the exploit-development capability for legitimate security research.

This is the same shape as Anthropic's Cyber Verification Program and Google's Fairwind Program for Gemini 3.8 Flash Cyber. Within one month, all three major labs adopted the same answer to the same problem: build the offensive capability, restrict who can invoke it.

There is a cost to legitimate users. Safeguards can pause or stop real security work that looks like an attack. If your team does penetration testing, fuzzing or exploit triage and is not in Daybreak, expect refusals on tasks that were fine last month. As CSO Online noted, the threshold crossing changes the threat model for defenders regardless of who holds the keys.

The gap most coverage leaves open is the obvious one: a gate is only as strong as the weights are secure. Classifier-based refusals protect against misuse through the front door. They do nothing if the model is stolen, or if a comparable open-weight model appears. We have already seen what autonomous attack tooling looks like in the wild in our reporting on JADEPUFFER, the first autonomous AI ransomware attack. The defensive window Daybreak buys is real, and it is temporary.

Robotic and human hands reaching toward each other, illustrating AI operating alongside people

Why is GPT-6 Astra controversial?

The controversy is about monitorability. Astra uses a reasoning technique OpenAI calls "opaque recurrence," which lets it work through problems using fewer language tokens — or none. That makes its chain of thought shorter and harder for humans and automated monitors to audit, which weakens one of the main tools used to catch misaligned behavior.

Chief scientist Jakub Pachocki said it directly: "as model capabilities are increasing, monitorability is getting more challenging," because capable models can do tasks "using fewer language tokens" or "no language tokens."

This matters because chain-of-thought monitoring has been the workhorse of practical AI oversight. If a model writes out its plan, you can read the plan. If the plan lives in activations that never become text, you cannot.

The picture is mixed rather than alarming:

So Astra behaves better than Sol when you measure outcomes, and is harder to inspect when you look inside. Brockman called it OpenAI's "most intelligent and most aligned model yet." Both halves of that can be true while the verification problem gets harder — and "trust the outcomes, because you can no longer read the reasoning" is an uncomfortable place for the first Critical-tier model to land.

Brockman also used the launch to say the clause in OpenAI's Microsoft contract that would dissolve the partnership at AGI "no longer exists," calling AGI a "mission concept or spiritual concept" and adding that he personally believes "we're there." That is a business statement more than a technical one, but it explains the framing around this release.

Is GPT-6 Astra worth $10/$50?

For most development work, no. Astra costs $10 per million input tokens and $50 per million output tokens, with a Fast mode at roughly double that. GPT-6 Sol costs $2/$10 and Claude Opus 5.5 costs $4/$20, and both handle routine coding well. Astra earns its price on long autonomous computer-use tasks, research mathematics and gated security work.

Model Input / 1M Output / 1M Best for
GPT-6 Astra $10.00 $50.00 Multi-hour computer use, math, vetted security research
Claude Opus 5.5 $4.00 $20.00 Agentic coding, knowledge work
GPT-6 Sol $2.00 $10.00 Everyday coding and agents
GPT-6 Luna $0.10 $0.50 High-volume extraction and summarization

A quick way to see the gap on your own workload:

PRICES = {  # USD per 1M tokens (input, output)
    "gpt-6-astra":     (10.00, 50.00),
    "claude-opus-5-5": (4.00, 20.00),
    "gpt-6-sol":       (2.00, 10.00),
}

def monthly_cost(model, input_tokens, output_tokens):
    price_in, price_out = PRICES[model]
    return (input_tokens * price_in + output_tokens * price_out) / 1_000_000

# 400M input + 60M output tokens per month
for model in PRICES:
    print(f"{model:16} ${monthly_cost(model, 400_000_000, 60_000_000):>9,.2f}")

# gpt-6-astra      $ 7,000.00
# claude-opus-5-5  $ 2,800.00
# gpt-6-sol        $ 1,400.00

At that volume Astra costs five times what Sol does. The question to ask is not "is Astra smarter" — it is — but "does my task fail on Sol." If a cheaper model already completes the job, the extra capability is unspent.

Where Astra is the right call:

For a wider view of how these prices fit the market, see our LLM API pricing guide.

Frequently asked questions

When was GPT-6 Astra released? GPT-6 Astra was released on September 3, 2026. It went first to customers in OpenAI's Daybreak cybersecurity program, then rolled out over the following week to ChatGPT Pro, Plus, Enterprise and Business accounts and the API.

How much does GPT-6 Astra cost? GPT-6 Astra costs $10 per million input tokens and $50 per million output tokens through the API. A Fast mode runs at up to 2.5x the speed for about twice the price, and long-context requests are billed at a higher rate.

What is the Critical threshold in OpenAI's Preparedness Framework? Critical is the highest risk tier in OpenAI's Preparedness Framework. For cybersecurity it means a model can find unknown vulnerabilities and build working exploits against hardened systems without a human directing each step. GPT-6 Astra is the first OpenAI model rated at that level.

Can GPT-6 Astra write exploits? Not for general users. Standard access allows secure code review and patching, and the model refuses tasks like creating proof-of-concept exploits. Full exploit-development capability is available only to vetted defenders through the Daybreak program.

Is GPT-6 Astra AGI? OpenAI has not formally declared it, though president Greg Brockman said he personally believes "we're there." There is no agreed technical definition, and Astra still trails Claude models on some reasoning benchmarks such as Humanity's Last Exam.

Is GPT-6 Astra better than Claude Opus 5.5? It depends on the task. Astra leads on mathematics, exploit benchmarks and AutomationBench, while Claude Opus 5.5 leads on Terminal-Bench 4.0 (66.4% vs roughly 58%) and FrontierCode, at 40% of Astra's price.

The verdict

GPT-6 Astra is a genuine step, and the most important thing about it is not a benchmark. It is that a major lab shipped a model it rates as capable of autonomous exploit development, and the entire safety case rests on an access gate and on outcome metrics, because the reasoning itself has become harder to read.

For developers, the practical advice is narrow. Use Astra when a task is long, autonomous and failing on cheaper models. Use Sol or Opus 5.5 for everything else — they cost a fifth to two-fifths as much, and on agentic coding Opus 5.5 now scores higher.

For security teams, the advice is broader: assume this capability will not stay behind a gate, and patch like it. If you want the defensive side of that picture, our guide to AI coding agent security is the place to start.

The model that can find the bug is here. Whether the defenders or the attackers get there first is now a scheduling problem.

Back to Blog