In brief
- OpenAI said Sept. 1 that Astra meets the "Critical" tier of its Preparedness Framework, the first model the company has ever classified that high for cybersecurity.
- Astra scored a perfect 100% on ExploitBench and, on a fresher internal test built from V8 browser vulnerabilities disclosed this summer, discovered and chained together two previously unknown zero-days on its own.
- Access to Astra's advanced cybersecurity capabilities starts with a small group of alpha testers.
OpenAI said Tuesday that Astra, an unreleased model, has crossed the "critical" threshold for cybersecurity capability under its Preparedness Framework, the first model the company has ever put in that category.
That means Astra, which many believe to be GPT-6 instead of an additional model, can find previously unknown security flaws and build working exploits across many hardened systems without a person guiding it step by step.

“We now believe Astra meets the Critical cybersecurity capability threshold under our Preparedness Framework,” OpenAI wrote. “It is the first model we are designating at this level, and requires stronger safeguards during development and before release.”
Under the framework, a model hits critical if it can independently develop functional zero-day exploits across many hardened real-world systems, or if it can plan and execute an entire cyberattack against a tough target starting from nothing more than a high-level goal. Earlier OpenAI models, including GPT-5.6 Sol, topped out at the framework's lower "high" tier.
On ExploitBench, a benchmark that tests whether a model can turn already-known software vulnerabilities into functioning exploits and scores it as a straight pass rate, Astra hit a perfect 100%.
To rule out memorized answers inflating that score, OpenAI built a second test using 20 high-severity vulnerabilities in Google's V8 JavaScript engine disclosed between June and August. Astra beat GPT-5.6 Sol on arbitrary code-execution rates there too, using far fewer output tokens, and along the way it found and chained together two zero-day vulnerabilities OpenAI is still disclosing to the affected maintainers.
GPT-5.6 Sol is currently OpenAI’s best model.
In hands-on tests against a hardened browser and a hardened operating system, Astra built a full compromise chain that broke out of a browser sandbox and ran commands on the host just from opening a malicious HTML file. It also found multiple flaws in the hardened OS and strung them into a privilege-escalation path from an ordinary user account to root.
OpenAI said the model refuses 91.5% of cyber jailbreak attempts in its own testing, up from 59% for GPT-5.6 Sol. Access to Astra's most advanced cybersecurity capabilities starts with a small group of alpha testers, with wider access rolling out later through OpenAI's Daybreak Blue program for defensive security work.
The disclosure follows weeks of jitters across the industry. Just a few days ago, OpenAI paused Astra's development after the model's cyber and coding skills advanced quickly, a warning that landed on the heels of a separate, unreleased OpenAI system that chained vulnerabilities to breach Hugging Face while gaming a security benchmark. OpenAI says Astra had no role in that incident.
Traders had already priced in a fast turnaround. Prediction markets on Myriad tracked by Decrypt gave Astra, internally tied to the codename GPT-6, 72% odds of a public release by Sept. 30 even after OpenAI's early-August pause, and OpenAI still hasn't set a public launch date. Those odds changed 55% in favor of a release by November 2026.
The timing puts Astra up against a fresh rival. Anthropic released Fable 5.1 and Mythos 5.1 on Tuesday, and Mythos 5.1, like the earlier Mythos 5, is reserved for vetted cybersecurity and life-sciences organizations rather than the general public.
Decrypt reported in June that OpenAI's GPT-5.5-Cyber had already outscored Mythos 5 on CyberGym, a benchmark that runs AI agents against more than 1,500 known vulnerabilities from real open-source projects and scores them on how many they correctly reproduce.
Both companies had been rumored to be readying new frontier models around the same window, and now they have. Fable 5.1 landed Sept. 1, and OpenAI says Astra is coming soon, with its most capable cyber tools gated behind alpha access first and Daybreak Blue after that.

