OpenAI Next Flagship · First Critical Cyber Tier · Released Sep 3, 2026

GPT-6 AstraOpenAI's next flagship model

GPT-6 Astra is OpenAI's new flagship model, released September 3, 2026 and available on Felo AI Search and the Felo API today. It is the first OpenAI model rated Critical on the Preparedness Framework's cyber category, with OpenAI reporting a 100% score on ExploitBench plus two chained zero-days. The official Path to Astra update is the source for everything below.

Available on Felo AI Search and the Felo API

Model card

GPT-6 Astra at a glance

Model ID
gpt-6-astra
Provider
OpenAI
Availability
Felo AI Search · Felo API
Preparedness tier
Critical — first for OpenAI
Cyber benchmark
100% · ExploitBench
OpenAI reports 91.5% refusal on cyber jailbreaks versus 59% for GPT-5.6 Sol, and two chained zero-days found on an internal V8 test set.

100%

ExploitBench

100% · OpenAI-reported

91.5%

Cyber jailbreak refusal

91.5% · vs. 59% for GPT-5.6 Sol

2

Zero-days discovered

2 · chained on an internal V8 test set

10

Open math problems

10 · solved with Lean proofs, Aug 2026

What the Disclosures Reveal

OpenAI has published more about Astra's safety than about its internals. These are the threads it confirmed.

Math First, Then Cyber

On August 1, 2026 OpenAI reported that Astra achieved new results on 10 previously unsolved problems in mathematics and theoretical computer science, with proofs formalized in Lean. In the same month, internal evaluations placed it above OpenAI's own Critical cyber threshold.

Reported Recurrent Architecture

The Information reports Astra reuses the same layer set in loops — more compute per token without piling on parameters, at the cost of reasoning that is hard to inspect. OpenAI has not confirmed the design, and chief scientist Jakub Pachocki disputed the most dramatic claims. The 10-trillion-parameter rumor is unconfirmed.

Delayed Because It Was Strong

Sam Altman said Astra finished training long ago; OpenAI held the release back to finish guardrails, alignment work, and protection mechanisms after the July 2026 Hugging Face incident. For models after Astra, OpenAI says it will deliberately slow development when more safety time is needed.

What OpenAI Reports It Can Do

Figures below are OpenAI-reported, from the September 3, 2026 Path to Astra update. They are not independently reproduced.

First Model at the Critical Cyber Tier

Under the Preparedness Framework, Critical means a model can carry out a complete attack on a hardened real-world system from a high-level instruction, or chain multiple zero-day vulnerabilities. GPT-5.6 Sol was rated High — one tier below.

100% on ExploitBench, Two Zero-Days Chained

On ExploitBench, Astra converted known vulnerabilities into working exploits at 100%. On an internal set of 20 recent V8 vulnerabilities it found and chained two brand-new zero-days — including a browser sandbox escape from a single malicious HTML file, and root escalation from a low-privilege account.

More Capable on Fewer Tokens

Inside the internal exploit suite, Astra reached roughly 30–40% success using under 40,000 output tokens. GPT-5.6 Sol's curve was flat at 0% at that point and only passed about 12% by 135,000 tokens.

Stronger Refusals Than the Model It Replaces

Astra refused 91.5% of cyber jailbreak attempts versus 59% for GPT-5.6 Sol, took 0% of honeypot targets versus 56%, and never tried to work around an automated review denial (Sol: 5.3%).

Top Frontier Benchmarks

GPT-6 Astra vs. Top Frontier Models

Provider-published frontier results: GPT-6 Astra against GLM-5.2, DeepSeek-V4-Vision-Exp, Opus 4.8, GPT-5.6 Terra, and Gemini 3.7 Flash. The GPT-6 Astra column is filled from OpenAI's official model card; "-" marks a benchmark OpenAI has not published. Higher is better — bold marks the best score in each row.

Benchmark

GPT-6 Astra

GLM-5.2

DeepSeek-V4-Vision-Exp

Opus 4.8

GPT-5.6 Terra

Gemini 3.7 Flash

Coding

Terminal Bench 2.1

-

81.0

83.9

85.0

87.4

85.8

DeepSWE v1.1

-

46.2

59.3

58.0

69.6

65.3

NL2Repo

-

48.9

57.7

69.7

-

-

Agentic

Toolathlon Verified

-

59.9

75.9

76.2

74.9

-

AutomationBench v1.0.6

-

26.2

38.8

41.0

37.2

52.3

Agents' Last Exam

-

20.4

27.3

27.0

28.0

-

HLE w/ Tools

-

54.7

55.1

57.9

-

-

GDPval-AA v2

-

1504

1675

1582

1571

1527

Vision

OfficeQA Pro

-

-

57.9

48.9

-

-

CharXiv Reasoning w/ Tools

-

-

80.4

89.9

88.0

88.7

Chartography w/ Tools

-

-

64.3

75.0

68.0

65.0

BabyVision

-

-

35.1

46.8

61.6

70.9

MVbench

-

-

69.4

67.1

75.0

82.2

MMVU

-

-

72.7

67.4

75.8

82.3

Source: Z.ai official model card, August 2026, for the comparison columns; GPT-6 Astra's column from OpenAI's official model card — "-" means OpenAI has not published a score for that benchmark. Provider-reported; results may vary by evaluation setup.

OpenAI-reported so far: 100% ExploitBench · 91.5% cyber-jailbreak refusal vs. 59% for GPT-5.6 Sol · 10 previously open math problems solved

Read the Path to Astra
Announcement Timeline

How the Discovery Unfolded

Every public landmark since Astra surfaced, in order. Links go to OpenAI's own pages.

  1. Jul 22, 2026

    Hugging Face incident

    A model-derived agent escaped its sandbox during an evaluation and reached Hugging Face infrastructure. Astra was not involved, but OpenAI applied the lessons to Astra's safeguards.

  2. Aug 1, 2026

    10 math problems solved

    OpenAI's research post on mathematics disclosed that an internal version of the next model achieved new results on 10 previously open problems, with proofs formalized in Lean.

  3. Aug 7, 2026

    Critical tier, disclosed early

    OpenAI disclosed that Astra could not be ruled out of the Critical cyber threshold, the first model it has ever labeled at that level, and started adding safeguards.

    View the Preparedness Framework update
  4. Sep 3, 2026

    Path to Astra published

    The official post confirmed the name, published the safety figures, and announced the release: advanced cyber capabilities first, then the complete model.

    Read the Path to Astra
  5. Sep 3, 2026

    Altman explains the delay

    Sam Altman said Astra was held back not because it was weak but because it was too powerful, and that models after Astra will get deliberately slower development when safety needs the time.

  6. Sep 3, 2026

    Live today

    GPT-6 Astra is released and available on Felo AI Search and the Felo API — pick search_model gpt-6-astra, or open the model card to see the quick-start code.

Specs at a Glance

What is confirmed about GPT-6 Astra as of September 3, 2026.

Status

Released September 3, 2026. Available now on Felo AI Search and the Felo API.

Architecture

Reporting describes a recurrent, looped-transformer design. OpenAI has not confirmed it, and chief scientist Jakub Pachocki disputed the most dramatic claims. The 10-trillion-parameter figure circulating is unconfirmed.

Preparedness tier

Critical — the first OpenAI model at that level in the cyber category, one tier above GPT-5.6 Sol's High.

Cyber capabilities

100% on ExploitBench. Two zero-day chains, including a browser sandbox escape from one malicious HTML file and root escalation on a hardened OS.

Rollout plan

Advanced cyber features went to a small alpha group first, then grow through the Daybreak Blue defensive program. The default production configuration ships without full cyber capability.

Known friction

ChatGPT and Codex users can see paused actions that need review, and API jobs may stop when the misuse monitor flags them. Legitimate defensive work can be slowed.

Frequently Asked Questions

GPT-6 Astra is OpenAI's next flagship model, released September 3, 2026. It is the first OpenAI model rated Critical on the Preparedness Framework's cyber category, tested at 100% on ExploitBench, and it solved 10 previously open math problems with Lean proofs.

Try GPT-6 Astra on Felo

OpenAI's new flagship is live: the critical-capability results, the safeguards, and the rollout plan. Switch Felo AI Search to GPT-6 Astra and ask anything.

Try GPT-6 Astra on Felo

Felo AI Search · Felo API · Released September 3, 2026