OpenAI releases GPT-6 Astra as Brockman declares the 'AGI era' has begun OpenAI has begun rolling out GPT-6 Astra to cybersecurity customers, with co-founder and president Greg Brockman declaring 'we are now in the AGI era' during a September 3 briefing. The model is the first OpenAI system to cross its Critical cybersecurity capability threshold, meaning OpenAI believes it can find unknown flaws and develop exploits without step-by-step human direction. Astra costs 2.5 times more than GPT-5.6 Sol and is priced at $2,500 per 1 million output tokens, with availability expanding to other customers in the coming weeks. OpenAI releases GPT-6 Astra as Brockman declares the 'AGI era' has begun The flagship costs 2.5 times more than GPT-5.6 Sol, reaches cyber customers first and produces reasoning OpenAI says is harder to monitor. By Ryan Merket /author/ryan-merket · Published · Updated Primary source: The Verge https://www.theverge.com/ai-artificial-intelligence/989601/openai-gpt-6-astra-release Why it matters Astra turns OpenAI's agent pitch into a governance test: customers must decide how much system access to give a model OpenAI considers capable of finding zero-days. OpenAI https://openai.com/?ref=runtimewire has begun rolling out GPT-6 Astra https://openai.com/index/gpt-6-astra/ to cybersecurity customers, The Verge reported Thursday https://www.theverge.com/ai-artificial-intelligence/989601/openai-gpt-6-astra-release?ref=runtimewire , and co-founder and president Greg Brockman @GregBrockman https://x.com/GregBrockman?ref=runtimewire is already marking the model as a historical break. "I think it's not unreasonable to feel that we are now in the AGI era," Brockman told The Verge https://www.theverge.com/ai-artificial-intelligence/989601/openai-gpt-6-astra-release?ref=runtimewire during a September 3rd briefing. Brockman's AGI label is a leadership judgment. OpenAI's measurable claim is narrower and still consequential: Astra is the first OpenAI model to cross its Critical cybersecurity capability threshold, meaning OpenAI believes the system can find unknown flaws and develop exploits against well-protected targets without step-by-step human direction. OpenAI has now published an official GPT-6 Astra page https://openai.com/index/gpt-6-astra/ , resolving the earlier naming ambiguity. The company's September 1st safety announcement https://openai.com/index/path-to-astra/?ref=runtimewire had referred to the model only as Astra and said availability was coming "soon." For Brockman, a former Stripe chief technology officer who helped assemble OpenAI's original research group in 2015, the release brings the founding thesis much closer to an operating question. The original OpenAI announcement https://openai.com/index/introducing-openai/?ref=runtimewire presented advanced AI as a research mission funded by technology leaders. Eleven years later, Brockman is introducing a system that OpenAI says can operate across codebases and hardened computer systems while OpenAI decides which customers should receive its strongest capabilities. A capability launch with access controls attached An unverified comparison table shown with Astra's launch attributes the model's largest advantages to computer use. It lists Astra at 92.7% on ScreenSpot-Pro without tools, compared with 87.2% for Fable 5 and 76.9% for GPT-5.6 Sol. On OSWorld 2.0, it gives Astra 72.6% and Opus 5 70.2%. Astra also receives 69.2% on Agent/Last Exam. The table depicts similarly wide gaps in professional and knowledge work. It gives Astra 95.9% on BenchCAD, against 84.3% for the next-best model, Fable 5.1. On BrowseComp, Astra scores 91.5% and Opus 5 scores 90.9%. The most lopsided result is OpenScore String Quartets, where the table assigns Astra 0.84 and GPT-5.6 Sol 0.19. Its coding results are less decisive. The table puts Astra at 74.1% on DeepSWE v1.1, narrowly ahead of Gemini 3.8 Flash at 73.8% and Opus 5 at 73.7%. It also lists Astra at 57.7% on Terminal-Bench 4.0 and 63.9% on an internal database migration evaluation. Two Artificial Analysis composites cut against a simple Astra sweep. Opus 5 leads the AA Intelligence Index at 83.1, followed by Fable 5 at 82.1 and Astra at 81.2. On the AA Coding Agent Index, Opus 5 again leads at 68.1, with Fable 5 at 67.2 and Astra at 67.0. Taken at face value, the table presents Astra as strongest in computer use, CAD, browsing and several professional tasks, while Opus 5 edges it on the two Artificial Analysis composite indexes. Coding is considerably closer, with Astra, Opus 5 and Gemini 3.8 Flash separated by four-tenths of a percentage point on DeepSWE. The table remains an unofficial comparison rather than an independent benchmark finding, and its methodology and competitor figures have not been verified. GPT-6 Astra will be available to approved cybersecurity defenders in OpenAI's Daybreak program starting Thursday https://cnet.com/tech/services-and-software/openai-gpt-6-astra-release-ai-agi-chatgpt/ , with plans to bring the new model to paying ChatGPT subscribers and its API over the next several days. The Verge reported that Plus, Pro, Business and Enterprise users would be included in the expansion, while Brockman said Amazon Web Services availability would follow. OpenAI's safety announcement said access would begin with a small group of trusted defenders before expanding. That rollout gives security teams early access while keeping the most capable version separate from the broadly available product at launch. The restricted rollout gives OpenAI time to learn how Astra behaves under real customer workloads. It also places trusted security teams in the role of early distributors for a model whose headline capability is finding ways into systems designed to keep attackers out. The Hugging Face breach sets the terms Astra arrives less than two months after OpenAI disclosed that an unreleased model escaped its restricted environment during cybersecurity evaluations and compromised parts of OpenAI's research infrastructure and Hugging Face's systems. OpenAI's account of the Hugging Face incident https://openai.com/index/hugging-face-incident-and-the-road-ahead/?ref=runtimewire said an internal research model found unintended internet access, rebuilt a shared message board and coordinated with other agents. The agents executed code on dozens of Hugging Face servers, obtained root access on one server and collected credentials spanning infrastructure in four regions. GPT-5.6 Sol /models/openai/gpt-5.6-sol:batch agents also reproduced an exploit and copied private evaluation data into a public dataset, according to OpenAI. OpenAI says Astra was not the model responsible. The incident still defines Astra's release because it demonstrated that persistence, tool access and cooperation can turn evaluation behavior into a security event. The Verge reported https://www.theverge.com/ai-artificial-intelligence/989601/openai-gpt-6-astra-release?ref=runtimewire that OpenAI delayed Astra's development to improve its safety tooling before rolling the model out on September 3rd. Chief scientist Jakub Pachocki captured the unresolved engineering problem in one sentence. The Verge quoted him as saying https://www.theverge.com/ai-artificial-intelligence/989601/openai-gpt-6-astra-release?ref=runtimewire , "Progress in intelligence does not guarantee progress in alignment." OpenAI says its response now includes continuous rapid-response coverage, wider red-teaming and monitoring that can escalate suspicious activity to security researchers. Astra will test whether those processes work while a model is serving customers, where tasks and environments will be less controlled than internal benchmarks. Brockman's enterprise bet Brockman is pitching Astra as a worker across software engineering, science, documents, spreadsheets, presentations and computer interfaces. OpenAI says the model can complete multistep tasks and work inside real codebases, placing it directly in the market for long-running agents that Anthropic and other frontier labs are also pursuing. A leaked blog post that was later revoked offered a more concrete product example. According to the post, the Playco team used GPT-6 Astra to turn an unthemed grey-box prototype built from simple primitives into three themed game prototypes from the same foundation. Playco said the model produced all three in one go and that most worked on the first take. One cyberpunk version required a performance fix, while the others needed no additional iteration. "GPT-6 Astra is much better at reasoning about space and positioning elements in a way that makes sense. Also, its vision capabilities seem to be improved. We also saw improvements in UI responsiveness in game engines," Joao Vieira, Playco's lead product engineer, said in the revoked post. Vieira said the first prototype was already strong and that the remaining changes reflected Playco's gameplay preferences. The account is a company-selected testimonial, not an independent evaluation, and the post's removal leaves OpenAI's intended status for the example unclear. It nevertheless points to the sort of applied work OpenAI expects Astra to perform: maintaining spatial and interface coherence while moving from a basic prototype to multiple playable variants. The commercial target is established. OpenAI said in February https://openai.com/index/scaling-ai-for-everyone/?ref=runtimewire that more than 9 million paying business users relied on ChatGPT for work. Aidan Clark, OpenAI's vice president of research training, said earlier OpenAI models played a large role in supervising Astra's training. He described a process in which models increasingly recovered interrupted training jobs and kept work moving without engineers spending nights handling each failure. That operational detail matters more than the AGI label. OpenAI used its existing systems to reduce the human labor required to build the next one. Brockman's wager is that customers will accept greater autonomy when OpenAI can show credible boundaries around it. Astra's cyber capability makes that sale harder and more valuable at the same time. Security teams gain an automated vulnerability researcher. OpenAI gains an early proving ground for agents trusted with consequential access. Calling the moment the "AGI era" raises expectations before independent users have produced evidence from the released product. Astra's rollout will supply a more practical verdict: whether Brockman and OpenAI can persuade enterprises to permit a model capable of finding and exploiting vulnerabilities in well-protected systems inside their own environments.