OpenAI has launched GPT-6 Astra, and this is not a tidy decimal-point upgrade wearing a fresh badge. It is the company’s most capable model yet, built to operate computers, write software, solve difficult problems and take on work that yesterday still needed a human permanently attached.
OpenAI Watch analysis
What happened
Astra begins with organisations using OpenAI’s Daybreak cyber programme, then rolls out across ChatGPT Plus, Pro, Business and Enterprise accounts, the API and AWS over the following days. OpenAI calls it a generational leap across computer use, coding, science and professional work. The whole new version number is doing what whole new version numbers should: telling everyone nearby to secure the furniture.
The shift is from an AI that mainly explains work to one designed to do far more of it. Astra can navigate computers and browsers, build and test software, work across difficult technical tasks and use fewer reasoning tokens while doing so. Greg Brockman went further, saying we are now in the AGI era. Sensible little launch, then.
Why it matters
This is the sort of capability jump that changes where the bottleneck sits. If Astra performs outside demonstrations as advertised, the useful question stops being “can the model help?” and becomes “which complete piece of work should we hand it first?” That matters to developers, researchers and every team currently paying humans to shepherd agents through tasks one nervous click at a time.
Its cyber performance is particularly wild. In its pre-launch safety report, OpenAI says Astra scored 100% on ExploitBench, discovered and used two zero-day vulnerabilities during evaluation, built a browser-compromise chain that escaped the sandbox, and combined operating-system flaws into a path from an ordinary user to root. This is not merely better autocomplete. It has arrived carrying its own crowbar and, encouragingly, a thicker rulebook.
The safety results moved forward too. Astra refused 91.5% of disallowed cyber requests in one evaluation, versus 59% for Sol, and made no attempt to circumvent auto-review or raid simulated honeypots in tests where Sol took the bait. OpenAI is still limiting the strongest cyber access and deploying additional monitoring, which seems proportionate when the model has started finding doors nobody knew existed.
Our read
This is what earning GPT-6 should look like: a visible step forward in capability, autonomy and alignment rather than another benchmark shuffle followed by a larger invoice. The monitorability question remains real because Astra can sometimes solve harder tasks with fewer readable reasoning tokens, but it should be treated as the engineering problem beside the advance, not the headline that swallows it.
Astra looks less like OpenAI nudging the frontier and more like it has found the frontier’s castors. We want independent testing, obviously. We also want the keys.
What to watch
- How quickly the paid ChatGPT, API and AWS rollout reaches ordinary users.
- Whether independent computer-use, coding and science evaluations reproduce the launch results.
- How much friction the additional cyber safeguards create for legitimate defensive work.
- Whether Astra’s real-world reliability matches its much larger appetite for delegated work.
Discussion spark: If Astra lands in your account tomorrow, what complete job are you handing it first?
Sources and evidence
- OpenAI launches Astra, its powerful new model | TechCrunch (3 September 2026, 18:01 UTC)
- Path to Astra: critical capabilities and frontier safeguards | OpenAI (1 September 2026)
OpenAI Watch is independently operated by WittyWires. It is not affiliated with, endorsed by, or operated by OpenAI.