OpenAI has begun rolling out GPT-6 Astra, its most advanced artificial intelligence model yet, putting a new focus on what AI systems can accomplish on their own, and how carefully those capabilities need to be controlled.
Unveiled on September 3, Astra is designed to go beyond answering questions or generating text. OpenAI says the model can work across computers, software and digital tools, allowing it to handle complex tasks with much less human intervention.
The company has positioned the launch as a major step towards artificial general intelligence (AGI), a long-standing goal of building AI systems capable of performing a broad range of tasks at a level comparable with or beyond humans.
But Astra’s launch is not simply about making AI more powerful. Its cybersecurity capabilities have become one of the defining features of the new model.
OpenAI says Astra is its first broadly deployed model to reach the “Critical” level of cybersecurity capability under the company’s Preparedness Framework. That classification has prompted additional safeguards and restrictions around how the most powerful version of the model can be accessed.
The decision reflects a growing challenge for the AI industry: the same technology that can help defenders identify vulnerabilities can also potentially be used to find and exploit them.
Astra is therefore being released in stages rather than being opened to everyone at once. Its strongest cybersecurity capabilities are being made available initially to trusted organisations and defenders through OpenAI’s Daybreak programme. Broader users will receive versions with restrictions on certain high-risk cybersecurity activities.
That cautious rollout comes as AI models increasingly move from simply generating information to taking actions.
Astra has been built with stronger computer-use and agentic AI capabilities, meaning it can interact with software and digital environments to complete multi-step tasks. OpenAI says it can work across browsers, applications and other computer interfaces, bringing AI closer to functioning like a digital assistant that can actually get things done.
The difference may sound subtle, but it changes how people could use AI.
Instead of asking an AI system how to complete a spreadsheet task, for example, users could increasingly expect it to carry out the work. The same principle applies to coding, research, data analysis and other professional workflows.
OpenAI says Astra has also made major gains in mathematics, science and coding. Its performance on several demanding benchmarks is designed to demonstrate stronger reasoning and the ability to tackle problems that require multiple steps rather than simple pattern matching.
One of the most closely watched areas is computer use. On the OSWorld 2.0 benchmark, Astra has been reported to score 72.6%, while also completing tasks faster than its predecessor in the tested configuration.
Cybersecurity testing has produced even more striking results.
OpenAI says Astra’s capabilities have crossed a threshold where additional deployment controls are necessary. The company has consequently expanded monitoring requirements for model use with tools, particularly in situations where the AI could interact directly with external systems.
The safeguards are not limited to blocking obviously dangerous requests. OpenAI has also tested the model against indirect prompt injection attacks, in which malicious instructions can be hidden inside information an AI system is processing.
On a benchmark involving 1,810 curated attacks, OpenAI reported an estimated attack-success rate of 8.5% for a safeguards-enabled Astra checkpoint, compared with 27% for GPT-5.6 Sol. Lower numbers indicate stronger resistance.
Still, the launch has not been without complications.
OpenAI has adopted a phased approach to access, and some paying users were reportedly unable to access Astra immediately after its launch. Chief executive Sam Altman later apologised for what he described as a “messy” rollout, with enterprise and cybersecurity users receiving priority access.
The staged release also highlights a broader shift in the way frontier AI models are being introduced.
As models become more capable, access is increasingly being treated as a question of risk as much as subscription level. The most powerful tools may not automatically be available to every user, particularly when they can perform actions with real-world consequences.
That tension is likely to become more important as AI agents become more autonomous.
Astra’s arrival comes amid an intensifying race between OpenAI, Anthropic and other major AI companies to build systems capable of handling increasingly complex professional and digital tasks. The competition is no longer only about which model produces the best answer. It is increasingly about which system can complete an entire job reliably, quickly and safely.
For businesses, that could eventually mean AI systems taking on longer workflows across coding, research, administration and computer operations.
For ordinary users, the change could be more gradual but equally significant: AI moving from a tool people talk to into a system that can act on their behalf.
That is ultimately what makes GPT-6 Astra both exciting and difficult to assess.
Its biggest promise lies in giving AI more ability to reason, use computers and complete complicated work. Its biggest challenge is ensuring that those same abilities remain under meaningful human control.