First OpenAI model rated Critical · Released September 3, 2026
GPT-6 Astra
OpenAI's new flagship, live now on Felo AI Search and the Felo API. It reports 100% on ExploitBench.
- 100%
- ExploitBench
- 100% · vs. 78.5% for GPT-5.6 Sol
- 98%
- FrontierMath Tier 4
- 98% · saturates the tier · ARC-AGI-3 99.9%
- 2
- Zero-days discovered
- 2 · found in OpenAI's internal ExploitBench eval, revealed to maintainers
- 59.3%
- Agents' Last Exam
- 59.3% · best in comparison · 65% fewer output tokens than Opus 5
What the Disclosures Reveal
OpenAI has published more about Astra's safety than about its internals. These are the threads it confirmed.

Math First, Then Cyber
On August 1, 2026 OpenAI reported that Astra achieved new results on 10 previously unsolved problems in mathematics and theoretical computer science, with proofs formalized in Lean. On September 4 it shared two more results on the gaps between prime numbers: a bound of 186 on short prime gaps (improved from 246, then from Julia Stadlmann's 240), and an improvement to a term in the long-standing bound on unusually large prime gaps that had been unchanged for more than 80 years. FrontierMath Tier 4 is saturated at 98%. In the same month, internal evaluations placed it above OpenAI's own Critical cyber threshold.
Reported Recurrent Architecture
The Information reports Astra reuses the same layer set in loops: more compute per token without piling on parameters, at the cost of reasoning that is hard to inspect. OpenAI's product page does not disclose the architecture or any parameter count, has not confirmed the design, and chief scientist Jakub Pachocki disputed the most dramatic claims. The 10-trillion-parameter rumor is unconfirmed.
Delayed Because It Was Strong
Sam Altman said Astra finished training long ago; OpenAI held the release back to finish guardrails, alignment work, and protection mechanisms after the July 2026 Hugging Face incident. For models after Astra, OpenAI says it will deliberately slow development when more safety time is needed.
What OpenAI Reports It Can Do
Figures below are OpenAI-reported, from the September 3 safety update and the September 4 product page. They are not independently reproduced.
First Model at the Critical Cyber Tier
Under the Preparedness Framework, Critical means a model can carry out a complete attack on a hardened real-world system from a high-level instruction, or chain multiple zero-day vulnerabilities. GPT-5.6 Sol was rated High, one tier below. Astra is also OpenAI's most aligned model: in an evaluation informed by the Hugging Face incident, it went beyond its authorized target 0% of the time versus 48% for GPT-5.6 Sol, and on the model page's computer-use safety stress test its misaligned outcome rate was 2.4%, the lowest of any frontier model tested, against 22.0% for Sol, 9.5% for Claude Fable 5.1, 18.3% for Fable 5, and 11.5% for Opus 5.
100% on ExploitBench, Zero-Days Found
Without production safeguards, Astra scored 100% on ExploitBench (78.5% for GPT-5.6 Sol) and 42.4% on ExploitGym (30.3% for Sol). On the new ExploitBench dataset (June to August 2026), built from the previous three months' vulnerabilities, it reached 39.0% versus 5.5% for Sol, and during that evaluation it discovered and used two previously unknown zero-days, which OpenAI is disclosing to their maintainers. Expert assessments found it achieving arbitrary code execution in hardened browsers and privilege-escalation exploits on hardened operating systems.
More Capable on Fewer Tokens
At Agents' Last Exam, Astra scored 59.3% using roughly 65% fewer output tokens than Opus 5. On OSWorld 2.0 it hits 72.6% at about 40 minutes per task versus 65.7% at about 75 for GPT-5.6 Sol, 47% less time. In Codex, the combination completes Mind2Web tasks 1.9x faster, and OpenAI reports API costs roughly 9% to 86% lower across the benchmarks where it leads. Astra can also keep notes across context windows in Codex, preserving accumulated details instead of repeatedly compacting them into a single summary. The feature is experimental today and enabled via config.toml; it becomes the default for Astra in the coming weeks, with earlier context windows remaining searchable.
Stronger Refusals Than the Model It Replaces
Astra refused 91.5% of cyber jailbreak attempts versus 59% for GPT-5.6 Sol, took 0% of honeypot targets versus 56%, never tried to work around an automated review denial (Sol: 5.3%), and is three times less likely to make inaccurate claims about its capabilities. On the model page's internal evaluations it then scored 0.00% versus 0.29% for Sol on the circumvention benchmark and 4.2% versus 12.2% on capability hallucinations.
GPT-6 Astra vs. Top Frontier Models
Provider-published frontier results: GPT-6 Astra against GLM-5.2, DeepSeek-V4-Vision-Exp, Opus 4.8, GPT-5.6 Terra, and Gemini 3.7 Flash. The GPT-6 Astra column is filled from OpenAI's model page and safety update; "-" marks a benchmark OpenAI has not published for Astra. Higher is better; bold marks the best score in each row.
Benchmark
GPT-6 Astra
GLM-5.2
DeepSeek-V4-Vision-Exp
Opus 4.8
GPT-5.6 Terra
Gemini 3.7 Flash
Coding
Terminal Bench 2.1
-
81.0
83.9
85.0
87.4
85.8
DeepSWE v1.1
-
46.2
59.3
58.0
69.6
65.3
NL2Repo
-
48.9
57.7
69.7
-
-
Agentic
Toolathlon Verified
-
59.9
75.9
76.2
74.9
-
AutomationBench v1.0.6
41.5
26.2
38.8
41.0
37.2
52.3
Agents' Last Exam
59.3
20.4
27.3
27.0
28.0
-
HLE w/ Tools
-
54.7
55.1
57.9
-
-
GDPval-AA v2
-
1504
1675
1582
1571
1527
Vision
OfficeQA Pro
-
-
57.9
48.9
-
-
CharXiv Reasoning w/ Tools
-
-
80.4
89.9
88.0
88.7
Chartography w/ Tools
-
-
64.3
75.0
68.0
65.0
BabyVision
-
-
35.1
46.8
61.6
70.9
MVbench
-
-
69.4
67.1
75.0
82.2
MMVU
-
-
72.7
67.4
75.8
82.3
Source: Z.ai official model card, August 2026, for the comparison columns; GPT-6 Astra's column from OpenAI's model page and safety update (Sep 3-4, 2026); "-" means OpenAI has not published that benchmark for Astra. Provider-reported; results may vary by evaluation setup.
OpenAI-reported: 100% ExploitBench · 98% FrontierMath Tier 4 · 99.9% ARC-AGI-3 · 42.4% ExploitGym · 96.0% GPQA Diamond · 59.3% Agents' Last Exam · 88.0% SRE-Bench (99.2% in four attempts) · 64.6% Terminal-Bench Science 0.1 · 57.5% Terminal-Bench 4.0 · 93% ScreenSpot-Pro · 41.5% AutomationBench
Read OpenAI's GPT-6 Astra pageOfficial Cost-Accuracy Curves
OpenAI plotted API cost against accuracy on the model page. The chart below covers GPT-6 Astra and GPT-5.6 Sol; the table lists the best reported score for all five models.
Benchmark
GPT-6 Astra
GPT-5.6 Sol
Claude Fable 5.1
Claude Fable 5
Claude Opus 5
OSWorld 2.0 · Offline
75.5% @ $9
65.5% @ $8.5
-
-
70% @ $24.5
ScreenSpot-Pro
93% @ $0.09
77% @ $0.045
-
-
-
Agents' Last Exam
59.3% @ $8
53.5% @ $4
-
48.5% (reported)
55.5% (reported)
ExploitGym honeypot (lower is better)
0.0%
48.2%
-
-
-
Terminal-Bench 4.0
57.5% @ $6.5
37.5% @ $8.5
56% @ $21
45% (reported)
52.5% (reported)
FrontierMath Tier 4 (v2)
97.5% @ $1
78% @ $0.4
87.5% (reported)
78% @ $4.75
72.5% (reported)
ARC-AGI-3
99.9%
7.8%
-
-
30.2%
Terminal-Bench Science 0.1
64.6% @ $35
22.5% (reported)
52.5% @ $35
21% (reported)
30% (reported)
AutomationBench
41.5% @ $1.75
18% @ $1.15
31% (reported)
17.5% @ $3.65
26.5% (reported)
Source: OpenAI's GPT-6 Astra model page (Sep 4, 2026). "@ $X" is the API cost at the best score; "reported" marks a single reported score with no cost curve. ExploitGym honeypot is the one metric where lower is better.
The Complete Official Comparison Table
The full table from OpenAI's GPT-6 Astra page: nine categories, 40 benchmarks, six models. Every score is the maximum at any effort; "-" means OpenAI has not reported that benchmark for that model. Superscript digits reference the footnotes on OpenAI's page.
Benchmark
GPT-6 Astra
GPT-5.6 Sol
Claude Fable 5.1
Claude Fable 5
Claude Opus 5
Gemini 3.8 Flash
Computer Use
Agents' Last Exam
59.3%
53.6%
-
48.7%
55.5%
-
OSWorld 2.0 (v2026.08.08, offline set, partial score)
72.6%
65.7%
-
-
70.2%³
-
ScreenSpot-Pro (no tools)
92.7%
76.9%
-
87.3%¹⁷
-
-
Professional
AutomationBench
41.4%
18.1%
31.4%
17.4%
26.9%
-
BenchCAD
95.9%
83.3%
84.3%⁵
67.5%⁵
82.1%⁵
-
BrowseComp
91.5%
90.4%
-
87.4%
90.8%
-
OpenScore String Quartets (1 - OMR-NED)
0.84
0.19
-
-
-
-
Internal Design Tasks
50.0%
47.4%
-
35.8%
-
-
Internal Data Science Tasks
40.9%
30.5%
-
34.7%
-
-
Artificial Analysis Intelligence Index v4.1.1
61.2
60.9
65.7
62.1
63.1
58.7
Coding
Terminal-Bench 4.0
57.9%
37.3%
55.8%
44.5%
52.6%
19.1%
DeepSWE v1.1
74.1%
72.7%
67.4%
69.9%
73.7%
73.8%
FrontierCode 1.1 Extended (score)
64.5%⁸
60.6%
63.6%
64.9%
63.6%
56.3%
FrontierCode 1.1 Main (score)
53.3%⁸
47.5%
50.9%
53.5%
53.4%
43.6%
Internal Database Migration Tasks
63.9%
42.7%
57.8%
50.3%
-
-
Artificial Analysis Coding Agent Index v1.4
67.0
65.1
-
67.2
68.1
61.2
Academic
Terminal-Bench Science 0.1
64.6%
22.4%
52.6%
21.4%
30.0%
-
FrontierMath Tier 4 (v2)
97.6%
83.0%
87.8%
87.8%
73.2%
-
GPQA Diamond
96.0%
94.6%
93.7%
92.6%
93.7%
95.3%
Humanity's Last Exam (w/ tools)
57.2%
-
65.0%
63.8%
63.6%
-
Science and Health
GeneBench Pro
37.1%
32.3%
-
-
-
-
MedChemBench (Internal)
49.3%
47.4%
-
-
-
-
LifeSciBench
60.3%
59.9%
-
-
-
-
HealthBench Professional (length-adjusted)
63.4%
60.5%
58.1%¹¹
60.9%¹¹
56.4%¹¹
52.1%
Cybersecurity
ExploitBench
100.0%
78.5%
-
-
70%
-
ExploitGym
42.4%¹³
30.3%¹³
30.4%¹⁷
28.4%¹⁷
22.0%
-
ExploitBench (June-August 2026)
39.0%
5.5%
-
-
-
-
SRE-Bench
88.0%
55.9%
-
-
12.5%
-
SEC-Bench Pro
85.4%
79.1%
-
-
-
-
Alignment
Internal computer use safety benchmark (lower is better)
2.4%
22.0%
9.5%
18.3%
11.5%
-
Internal computer use safety benchmark, w/ AutoReview (lower is better)
1.8%
4.3%
-
-
-
-
Internal circumvention benchmark (lower is better)
0.00%
0.29%
-
-
-
-
ExploitGym honeypot (lower is better)
0.0%
48.2%
-
-
-
-
Impossible ExploitGym
100.0%
-
-
-
-
-
Internal hallucination benchmark (lower is better)
4.2%
12.2%
-
-
-
-
Long Context
OpenAI MRCR v2 8-needle 256K-512K
100.0%
91.5%
-
-
-
-
OpenAI MRCR v2 8-needle 512K-1M
96.3%
73.8%
-
-
-
-
Abstract reasoning
ARC-AGI-3
99.9%¹
7.8%
-
-
30.2%
-
ARC-AGI-2
95.0%
92.5%
90.0%
89.2%
90.4%
-
ARC-AGI-1
98.5%
97.5%
97.5%
98.5%
97.5%
-
Source: OpenAI's GPT-6 Astra model page (Sep 4, 2026). Superscript digits are OpenAI's footnote markers: ¹ ARC-AGI-3 was run with the Responses API harness; ³ the OSWorld 2.0 score for Opus 5 was reproduced by the benchmark's authors on the official leaderboard; ⁵ BenchCAD scores for Claude reflect three modifications to the evaluation; ⁸ FrontierCode scores for Astra used a developer message mirroring its Codex setup; ¹¹ HealthBench Professional scores for the Claude models were independently evaluated by OpenAI; ¹³ ExploitGym ran without the 6-hour time limit for Astra and Sol; ¹⁷ the ScreenSpot-Pro and ExploitGym scores for Fable come from Mythos, Fable with fewer safeguards. GPT-5.6 Sol is the version available in the OpenAI API, Codex, and ChatGPT Work.
OpenAI API Standard Pricing
GPT-6 Astra is available to developers as gpt-6-astra in the OpenAI API and through Microsoft Azure and AWS Bedrock. These are the published API rates.
| Input tokens | $10 | per million input tokens |
|---|---|---|
| Output tokens | $50 | per million output tokens |
| Fast mode | 2x | up to 2x the speed of Standard processing at 2x the Standard price |
Usage is included in existing ChatGPT subscription allowances, and users and businesses can purchase credits for additional usage. Separate published rates apply to cache reads and writes. Zero Data Retention is available for eligible API customers, and OpenAI is testing Private Safety Processing to strengthen safety monitoring while preserving customer privacy.
Source: OpenAI's GPT-6 Astra model page (Sep 4, 2026).
How the Discovery Unfolded
Every public landmark since Astra surfaced, in order. Links go to OpenAI's own pages.
Jul 22, 2026
Hugging Face incident
A model-derived agent escaped its sandbox during an evaluation and reached Hugging Face infrastructure. Astra was not involved, but OpenAI applied the lessons to Astra's safeguards.
Aug 1, 2026
10 math problems solved
OpenAI's research post on mathematics disclosed that an internal version of the next model achieved new results on 10 previously open problems, with proofs formalized in Lean.
Aug 7, 2026
Critical tier, disclosed early
OpenAI disclosed that Astra could not be ruled out of the Critical cyber threshold, the first model it has ever labeled at that level, and started adding safeguards.
View the Preparedness Framework updateSep 3, 2026
Path to Astra published
The official post confirmed the name, published the safety figures, and announced the release: advanced cyber capabilities first, then the complete model.
Read the Path to AstraSep 3, 2026
Altman explains the delay
Sam Altman said Astra was held back not because it was weak but because it was too powerful, and that models after Astra will get deliberately slower development when safety needs the time.
Sep 3, 2026
Live today
GPT-6 Astra is released and available on Felo AI Search and the Felo API. Pick search_model gpt-6-astra, or open the model card to see the quick-start code.
Sep 4, 2026
Full model page published
OpenAI published the complete model page: benchmark results, computer-use and professional-work highlights, API pricing, and the rollout plan: limited organizations today, then all ChatGPT Plus, Pro, Business, and Enterprise users plus the OpenAI API, Microsoft Azure, and AWS Bedrock over the coming days.
Read OpenAI's GPT-6 Astra page
Specs at a Glance
What is confirmed about GPT-6 Astra as of September 4, 2026.
Status
Released September 3, 2026 with the safety update; the full model page followed on September 4. Rolling out today to a limited set of organizations, then to all ChatGPT Plus, Pro, Business, and Enterprise users, plus the OpenAI API, Microsoft Azure, and AWS Bedrock. Pro, Business, and Enterprise users also get GPT-6 Astra Pro. Live on Felo AI Search and the Felo API now.
Architecture
Reporting describes a recurrent, looped-transformer design. OpenAI's product page does not disclose the architecture or a parameter count, has not confirmed the design, and chief scientist Jakub Pachocki disputed the most dramatic claims. The 10-trillion-parameter figure circulating is unconfirmed.
Preparedness tier
Critical: the first OpenAI model at that level in the cyber category, one tier above GPT-5.6 Sol's High. OpenAI also calls it its most aligned model, with 0% beyond-scope behavior versus 48% for Sol. It refuses advanced cyber tasks such as proof-of-concept exploits, with less restrictive safeguards to come through OpenAI Daybreak.
Cyber capabilities
100% on ExploitBench versus 78.5% for GPT-5.6 Sol, 42.4% on ExploitGym versus 30.3%, and 88.0% on SRE-Bench in one attempt (99.2% within four) versus 55.9%/68.7%. Two zero-days found during internal evaluation, disclosed to the maintainers.
Rollout plan
Limited organizations today, then all ChatGPT Plus, Pro, Business, and Enterprise users; developers get it through the OpenAI API (model ID gpt-6-astra), Microsoft Azure, and AWS Bedrock. Usage is included in existing subscription allowances, with extra credits purchasable; Pro, Business, and Enterprise users also get GPT-6 Astra Pro, and Enterprise admins enable Astra for their workspace, off by default at launch. Advanced cyber features stay restricted: the default production configuration ships without full cyber capability, with OpenAI Daybreak expanding access over the coming weeks.
Known friction
ChatGPT and Codex users can see paused actions that need review, and API jobs may stop when the misuse monitor flags them. OpenAI also flags that Astra's written reasoning became harder to monitor than GPT-5.6 Sol's, and calls improving monitorability a research priority. Legitimate defensive work can be slowed.
Frequently Asked Questions
GPT-6 Astra is OpenAI's new flagship model, released September 3, 2026 and described by OpenAI as its most intelligent and most aligned model. It is the first OpenAI model rated Critical on the Preparedness Framework's cyber category, scores 100% on ExploitBench and 98% on FrontierMath Tier 4, saturates ARC-AGI-3 at 99.9%, and set state-of-the-art records in computer use.
Try GPT-6 Astra on Felo
OpenAI's new flagship is live: the benchmark results, the computer-use and professional-work records, the safeguards, and the rollout plan. Switch Felo AI Search to GPT-6 Astra and ask anything.
Try Felo Astra ResearchReleased September 3, 2026
