OpenAI's GPT-6 Astra is the first AI model rated 'Critical' for cyber risk — what that means if you're choosing an AI coding tool
OpenAI shipped GPT-6 Astra on 3 September 2026 at 2.5x GPT-5.6 Sol's price after delaying it four weeks over cyber risk, and it's now the first model to hit OpenAI's 'Critical' cybersecurity threshold — scoring 100% on exploit-development benchmarks and finding two previously unknown zero-days during testing — a milestone anyone evaluating AI coding agents needs to understand.
11 September 2026
OpenAI shipped GPT-6 Astra on 3 September 2026, four weeks later than planned, after saying it had slowed the release to assess cyber risk. The numbers explain why: Astra is the first model to reach OpenAI’s “Critical” threshold for cybersecurity under its Preparedness Framework, scoring 100% on internal exploit-development benchmarks and independently discovering two previously unknown zero-day vulnerabilities during testing. It’s priced 2.5x GPT-5.6 Sol — $10 per million input tokens, $50 per million output — carries a 1M-token context window, and posts OpenAI’s highest-ever scores on abstract reasoning and maths alongside a clear edge in agentic coding and computer-use workflows, the exact niche it was built to compete in against Claude Opus 5, Cursor and Windsurf’s agents.
Because of that cyber rating, OpenAI is gating Astra’s most sensitive agentic and computer-use capabilities behind a trusted-access program rather than shipping them to everyone at once. That’s a meaningful design choice: the same capability that lets an AI coding agent autonomously find and fix a security hole in your codebase is, at sufficient strength, also capability that can find and exploit one. OpenAI clearly doesn’t think that’s a hypothetical concern at this model’s level.
Why this matters beyond the benchmark chart
Most founders and product leads don’t pick AI coding tools by comparing Preparedness Framework scores — they pick by what ships fastest. But Astra’s release makes something explicit that’s been true for a while: the agentic capability that makes these tools genuinely useful for shipping software — writing code, running commands, browsing, operating on your systems with real permissions — scales together with the capability to do damage if it’s misconfigured, over-permissioned, or simply wrong. A model good enough to find a zero-day in a security audit is also a model whose access to your production systems deserves the same scrutiny you’d give a new hire, not the default trust you might extend to an autocomplete suggestion.
That’s a genuinely different question from “which model writes better code,” and it’s one procurement conversations rarely ask yet: what access does this agent actually have, is it scoped to what the task needs, and is anything it does auditable after the fact.
So what
If AI-assisted development is part of how your software gets built — and increasingly it is, whichever vendor you use — the model’s capability tier is only half the evaluation. The other half is how tightly its access is scoped and how its actions are reviewed, especially as tools like Astra push agentic permissions further into “operates your systems for you” territory. That’s the discipline we build around AI-assisted development rather than treating capability as the only variable that matters — see our AI-assisted development approach, or get in touch if you want a second opinion on how a tool or vendor you’re evaluating actually scopes its access.