CourionAI
EN
Newsletter
← All news
openai 3 min read

OpenAI Ships GPT-6 Astra, and Calls It Its First Critical Cyber Model

OpenAI released GPT-6 Astra on 3 September with a 1.1 million token context window at $10 per million input tokens and $50 per million output. It is the first model the company says meets its Critical cybersecurity threshold.

A large eight pointed star built from concentric printed rings with a small closed padlock at its centre

OpenAI released GPT-6 Astra last Thursday, four weeks after saying it had deliberately slowed the model down over cyber risk. It is the company’s new flagship, and the launch came in the middle of the busiest stretch of frontier model releases this year: four big models in about 72 hours, from four different labs.

The numbers first. Astra takes a context window of roughly 1.1 million tokens, which is the amount of text a model can hold in mind at once, and produces up to 128,000 tokens in a single reply. API pricing is $10 per million input tokens and $50 per million output tokens, with cached input at $1. There is a Fast mode that runs up to 2.5 times quicker for twice the price. On OSWorld 2.0, a benchmark that measures how well a model can drive an actual computer desktop, OpenAI reports 72.6% against 65.7% for GPT-5.6 Sol and 70.2% for Claude Opus 5. The company also says Astra often reaches those scores while spending fewer output tokens than its predecessors, which matters because output tokens are the expensive half of the bill.

The more consequential line in the announcement is not a benchmark. OpenAI says Astra is the first model to meet the “Critical” tier of its own cybersecurity risk scale, meaning it can find previously unknown software flaws and write working exploit code without a human walking it through the steps. The model ships with alignment training plus what OpenAI calls system safeguards: automated review of the code it produces and misalignment monitoring while it runs in production. Stripped of those operational protections, OpenAI reports Astra refuses 91.5% of known jailbreak attempts, against 59% for Sol.

What is actually going on here. Every major lab now publishes a risk framework with tiers, and 2026 is the year models started landing in the top tier rather than comfortably below it. Google did the same thing the day before with a cyber-focused Gemini variant it only hands to vetted defenders. The pattern is that the raw capability arrives first, the gating arrives with it, and the public gets the safe version while a smaller set of trusted organisations gets the unrestricted one. That is a reasonable arrangement and also an enormous amount of trust placed in a handful of private companies deciding who counts as trusted. Worth keeping both thoughts at once.

What this means for you. If you use ChatGPT, Astra is rolling out across plans including Plus, so you may already have it without noticing much. For everyday writing, summarising and research, the honest answer is that you will struggle to feel the difference against the previous model. Where it should show is long, multi-step work: a model that can hold a million tokens and drive a desktop is aimed at people who hand it a whole codebase or a whole afternoon of clicking, not a paragraph. If you are paying per token through the API, do the arithmetic before switching. At $50 per million output tokens, Astra is a frontier-priced model, and a cheaper one may finish your job just as well.

Sources

Source: https://llm-stats.com/models/gpt-6-astra

Next story

K2 Horizon Ships Six Open Models, and the Training Data With Them

Abu Dhabi's Institute of Foundation Models released six models from 0.9B to 375B parameters on 3 September under Apache 2.0, publishing weights, code, training data and methodology. The smallest is meant to run on a watch.

Six mountain peaks rising in ascending size, each drawn as a transparent wireframe so the internal structure shows through