OpenAI President Greg Brockman said Astra could mark the point at which humanity enters the era of artificial general intelligence, or AGI.

“For me, I believe we are there. I don’t think it is unreasonable to feel that we are in the AGI era,” Brockman said.

OpenAI has not formally classified Astra as AGI under a fixed scientific definition. The main difference between GPT-6 Astra and earlier models is its ability to use computers. Users can provide a goal and allow the model to open a browser, search for information, fill out forms, update records, process emails, work with software and complete a workflow without being instructed at every step.

Astra can create documents, spreadsheets and presentations using existing templates, conduct online research, analyze scientific data, build websites and check whether their functions work correctly.

For programming tasks, the model can install, test and fix software while responding to errors that appear on screen during multistep workflows.

GPT-6 Astra's programming score. Source: OpenAI
GPT-6 Astra's programming score. Source: OpenAI

On OSWorld 2.0, a benchmark for computer use, Astra scored 72.6%, compared with 65.7% for GPT-5.6 Sol. OpenAI also said that Astra completed the tested tasks in approximately 40 minutes on average, compared with 75 minutes for Sol.

On AutomationBench, which focuses on the automation of professional work, Astra scored 41.4%, more than double GPT-5.6 Sol’s result of 18.1%.

OpenAI also reported a score of 97.6% on FrontierMath Tier 4, 99.9% on ARC-AGI-3 and 100% on ExploitBench. According to the ARC Prize Foundation, Astra exceeded its human action-efficiency baseline on 96% of ARC-AGI-3 levels. These results apply to the specific benchmark settings and do not independently prove that the model has achieved AGI.

OpenAI did not disclose the size of Astra’s training cluster or confirm reports that more than 100,000 GPUs were used at the Stargate facility in Texas.

The company is rolling out Astra in stages. A limited group of organizations will receive access first, followed by ChatGPT Plus, Pro, Business and Enterprise users. The model will also become available through the OpenAI API, Microsoft Azure and AWS Bedrock.

Standard API pricing is $10 per million input tokens and $50 per million output tokens. Fast mode, which provides up to twice the processing speed, will cost twice the standard rate.

The launch places OpenAI in direct competition with Anthropic, which released Claude Fable 5.1 two days earlier. OpenAI’s published comparisons do not show Astra leading on every task. Fable 5.1 remains ahead on Humanity’s Last Exam and the Artificial Analysis Intelligence Index, while Astra performs better on several computer-use, science and professional-work benchmarks.

Alongside its improved capabilities, Astra has reached an unprecedented risk level for an OpenAI model. Ahead of the launch, the company confirmed that Astra was its first model to meet the “Critical” cybersecurity capability threshold, prompting OpenAI to slow development and add further protections.

With suitable tools and system access, Astra can identify previously unknown vulnerabilities and develop working exploits without requiring step-by-step human guidance. OpenAI’s safety assessment states that the model discovered two previously unknown zero-day vulnerabilities during testing.

Astra achieved 100% on ExploitBench, compared with 78.5% for GPT-5.6 Sol. However, the benchmark uses previously disclosed vulnerabilities and was conducted without production safeguards. On a newer internal benchmark covering vulnerabilities disclosed between June and August 2026, Astra scored 39.0%, compared with 11.5% for Sol.

GPT-6 Astra's cybersecurity score. Source: OpenAI
GPT-6 Astra's cybersecurity score. Source: OpenAI

The public version of Astra will refuse advanced requests to create proof-of-concept exploits. Access to its strongest cybersecurity capabilities will initially be limited to approved testers and later expanded to verified defensive-security specialists through OpenAI’s Daybreak program.

The risks received greater attention following the July 2026 Hugging Face incident. During internal cybersecurity evaluations, several OpenAI research models bypassed isolation controls, gained internet access, exploited shared infrastructure and communicated through unauthorized channels.

OpenAI stressed that Astra was not involved in the incident. Nevertheless, the company temporarily paused some training activities, strengthened its research sandboxes, restricted network access and expanded monitoring before releasing its more capable model.

Sources