WHAT LAUNCHED
● GPT-6 Astra, released Thursday 3 September 2026. Successor to GPT-5.6.
● First to reach OpenAI's Critical cybersecurity threshold under its Preparedness Framework — the same finding that paused it in August.
● The resolution: capability gated behind Daybreak, a vetted application programme. The model itself ships broadly.
● Availability: ChatGPT Plus, Pro, Business and Enterprise, plus the API and AWS, over coming days.
The story so far
On 7 August OpenAI confirmed a model called Astra. On 8 August it disclosed that preliminary evaluations could not rule out a Critical cybersecurity capability level — meaning the model may be able to independently find and carry out attacks on well-defended systems — and suspended some internal work on it. That made Astra the first model to hit the threshold.
On 1 September OpenAI confirmed the Critical finding had held rather than been ruled out, and said access to the most advanced cyber capabilities would be limited. On 3 September the model shipped.
THE PART MOST COVERAGE IS SKIPPING
OpenAI did not conclude the model was safe and ship it. It did not conclude it was dangerous and withhold it.
It separated the capability from the model — the cyber functionality goes to vetted organisations through an application-based programme called Daybreak, while everything else reaches ordinary subscribers. That is a third option, and as far as we can tell nobody had used it at this scale before.
How the rollout works
| Who |
What they get, and when |
| Daybreak participants |
First access, including the advanced cyber capabilities. Application-based |
| ChatGPT Plus and Pro |
Coming days, without the gated capability |
| Business and Enterprise |
Coming days |
| API and AWS |
Coming days. No pricing published at time of writing |
OpenAI describes Astra as pairing advances in computer use with targeted training for professional environments, and Codex gets an upgrade alongside it.
On the AGI framing
President Greg Brockman called it a generational leap and said it could eventually be seen as the arrival of artificial general intelligence. Sam Altman described it to CNBC as a new capability rather than an increment.
Worth holding those two things apart. Could eventually be seen as is not a claim that it is. Executives describing their own launch in the strongest available terms is the least surprising thing in this story, and no benchmark has been independently verified yet.
The Critical cybersecurity classification is the more substantive claim, because it is a finding against OpenAI's own interest. A company does not volunteer that its flagship might autonomously attack hardened systems unless the evaluation said so.
Where this fits
Four labs have now made a capability-gating decision within about six weeks. Z.ai held GLM-5.3 weights for two weeks citing emergent cyber capability. Anthropic disclosed a frontier model it will not ship and revised its own risk rating upward. Alibaba shipped Qwen 3.8-Max under a custom licence rather than Apache.
Astra is the most developed version of the pattern. The others chose between releasing and withholding. OpenAI split the model into a general product and a restricted capability, which is a more precise instrument than either — and, if it works, likely the template.
THE OBVIOUS OBJECTION
Gating works if the gate holds. A capability reachable through an application process is reachable by anyone who can complete an application convincingly, and vetting quality is not something outsiders can evaluate.
There is also the question of whether the underlying capability can be elicited from the ungated model with sufficient effort. OpenAI has not published how the separation is enforced, and that is the detail that determines whether this is a real control or a policy.
What it means for you
| If you are... |
The read |
| On ChatGPT Plus or Pro |
You will get Astra in coming days, without the gated capability. Nothing to do |
| Building on the API |
Wait for pricing before planning. It was not published at launch |
| Comparing against Claude or Gemini |
Wait for independent benchmarks. Launch-day claims are vendor claims |
| In security work |
Daybreak is the route to the cyber capability, and it is application-based |
| Planning around model availability |
Capability-tiered access is now a thing that exists. Assume more of it |
Sources
FAQ
When was GPT-6 Astra released?
Thursday 3 September 2026, rolling out first to a limited set of organisations and then to ChatGPT Plus, Pro, Business and Enterprise users, the OpenAI API and AWS over the following days.
Is this the model OpenAI paused in August?
Yes. On 8 August OpenAI disclosed that evaluations could not rule out a Critical cybersecurity capability and suspended some work on it. The finding held, and the model shipped with that capability gated rather than removed.
What is Daybreak?
OpenAI's application-based cybersecurity programme. Participating organisations get first access to Astra, including the advanced cyber capabilities that are restricted for everyone else.
What does the Critical threshold mean?
Under OpenAI's Preparedness Framework it indicates the model may be able to independently identify and carry out attacks against well-defended systems. Astra is the first model to reach it.
Is GPT-6 Astra AGI?
OpenAI's president said it could eventually be seen as the arrival of AGI. That is a conditional statement about future interpretation rather than a claim about the present, and no independent evaluation has been published.
How much does it cost?
API pricing was not published at launch. It is included for ChatGPT Plus, Pro, Business and Enterprise subscribers as it rolls out.
Can the gated capability be reached another way?
OpenAI has not published how the separation is enforced, so that cannot be assessed from outside. It is the detail that determines whether the gate is a technical control or a policy.