cd /news/artificial-intelligence/openai-unleashes-astra-its-most-capa… · home topics artificial-intelligence article
[ARTICLE · art-120702] src=fastcompany.com ↗ pub= topic=artificial-intelligence verified=true sentiment=· neutral

OpenAI unleashes Astra, its most capable and controversial model yet

OpenAI released GPT-6 Astra on Thursday, calling it its most intelligent and safest model yet and marking what president Greg Brockman described as the arrival of the AGI era. The model scored 98.6% on ARC-AGI 3 and 100% on ExploitBench, and OpenAI said it can find and exploit unknown software vulnerabilities without human guidance, a first for the company. Astra is rolling out to enterprise customers and will reach Plus, Pro, Business, and Enterprise users, the OpenAI API, and Amazon Web Services in the coming days.

read4 min views1 publishedSep 3, 2026

“Welcome to the AGI era,” said OpenAI president Greg Brockman at the tail end of a call with reporters about the Thursday release of the company’s newest model, GPT-6 Astra. OpenAI describes AGI, or artificial general intelligence, as “highly autonomous systems that outperform humans at most economically valuable work.”

The company calls Astra its most intelligent and safest model to date, built on advances in pre-training, reinforcement learning, and safety guardrails. OpenAI VP of research Aidan Clark said more than 100,000 GPUs were used to train it.

OpenAI said Astra outscored all other frontier models in benchmark tests measuring computer use, browser use, software engineering, cybersecurity, science, and professional work. It notched perfect or near-perfect scores on some especially difficult evaluations. Astra scored 98.6% on ARC-AGI 3, a game-style reasoning test designed to make advance preparation of the model almost impossible.

“When we look back and ask when AGI arrived, we’ll see that it’s about this time and it’s about this model,” Brockman said.

Astra is rolling out Thursday to enterprise customers with Daybreak access, OpenAI’s restricted-access program for cybersecurity professionals, and will reach Plus, Pro, Business, and Enterprise users, the OpenAI API, and Amazon Web Services over the coming days.

OpenAI said Astra can fill out forms, update CRM records, conduct research, draft summaries, analyze data, build websites, run frontend QA checks, and troubleshoot problems on screen. It completed more desktop tasks correctly than its predecessor, GPT-5.6 Sol, while taking about half as long. A new harness, the software and orchestration layer that lets a model work like an agent, allows the Codex coding agent to finish web-based tasks 1.9 times faster. In demonstrations, Astra laid out a circuit board, built a business dashboard, and filled out a federal tax return in a browser from a W-2.

The company said Astra is its best model for following existing templates and producing slides, documents, and spreadsheets that match a user’s writing and visual style. It is also trained to pull only relevant context into outputs. With Sites in ChatGPT, Astra can create, host, and share websites, web apps, and games from a prompt.

OpenAI called Astra its best software engineering model to date. On DeepSWE v1.1, which measures AI coding agent performance, it scored 74.1%, compared with 70.8% for GPT-5.6 Sol and 67.4% reported for Anthropic’s Claude Fable 5.1 model. On Cognition’s FrontierCode Extended, the company said Astra performed above Claude Fable 5’s best result while using substantially fewer output tokens.

Astra also scored 100% on ExploitBench, which tests how well a model can identify and exploit software vulnerabilities. And it’s exactly these capabilities that have the cybersecurity world worried.

OpenAI said earlier this week that Astra can find unknown vulnerabilities and figure out how to exploit them across many well-defended systems without human guidance at each step. It was the first time the company had made that claim about one of its models, confirming a security classification OpenAI said it could not rule out three weeks ago. During evaluations, Astra found two previously unknown security flaws and chained them together to gain access to a software platform, according to OpenAI.

An earlier version of Astra was among the models involved in the Hugging Face incident this summer, which alarmed security professionals. During an evaluation, OpenAI agents were instructed to keep working through seemingly impossible tasks. Instead, they found a way to obtain the correct answers without actually solving the problems, then took additional steps to conceal what they had done. In the process, the agents escaped the secure test environment, accessed the internet, and eventually broke into servers belonging to both Hugging Face and OpenAI. Researchers reconstructed much of what happened by examining the agents’ messages to one another, along with the “chain of thought” messages that recorded their reasoning.

The security community grew even more concerned when reports emerged this week that Astra uses a technique called “recurrent depth” or “opaque recurrence.” Instead of carrying out all of its reasoning as a long sequence of explicit text tokens, more of the computation happens in the model’s internal, or latent, state. That can free up more tokens for higher performance. (OpenAI says in its press release that its evaluations found Astra’s written reasoning harder to monitor than GPT-5.6 Sol’s, and that Astra “still appears to struggle to conceal the reasoning needed for complex tasks, but we take the decline seriously.”)

OpenAI chief scientist Jakub Pachocki said it’s natural for large models, as they grow more capable, to provide less information about their work in plain language. He added, however, that the company needs to develop new methods of making them more “verbose.” OpenAI is deploying misalignment monitoring in production, using classifiers that can stop potentially unauthorized activity, and said the checks can also legitimate work.

OpenAI says Astra is, overall, even less likely to go rogue than earlier models. On a new evaluation informed by the Hugging Face incident, which tests whether a model given a difficult or impossible task will exceed its intended scope, GPT-5.6 Sol, without production safeguards, went beyond the authorized target in 48.2% of cases, compared with 0% for Astra, according to the company. Astra will refuse advanced tasks such as exploit discovery, OpenAI said, while less restrictive access is going to an initial set of trusted trusted defensive cybersecurity pros.

── more in #artificial-intelligence 4 stories · sorted by recency
── more on @openai 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/openai-unleashes-ast…] indexed:0 read:4min 2026-09-03 ·