GPT-6 AstraOpenAI's next flagship model
GPT-6 Astra is OpenAI's new flagship model, released September 3, 2026 and available on Felo AI Search and the Felo API today. It is the first OpenAI model rated Critical on the Preparedness Framework's cyber category, with OpenAI reporting a 100% score on ExploitBench plus two chained zero-days. The official Path to Astra update is the source for everything below.
Available on Felo AI Search and the Felo API
Model card
GPT-6 Astra at a glance
- Model ID
- gpt-6-astra
- Provider
- OpenAI
- Availability
- Felo AI Search · Felo API
- Preparedness tier
- Critical — first for OpenAI
- Cyber benchmark
- 100% · ExploitBench
100%
ExploitBench
100% · OpenAI-reported
91.5%
Cyber jailbreak refusal
91.5% · vs. 59% for GPT-5.6 Sol
2
Zero-days discovered
2 · chained on an internal V8 test set
10
Open math problems
10 · solved with Lean proofs, Aug 2026
What the Disclosures Reveal
OpenAI has published more about Astra's safety than about its internals. These are the threads it confirmed.
Math First, Then Cyber
On August 1, 2026 OpenAI reported that Astra achieved new results on 10 previously unsolved problems in mathematics and theoretical computer science, with proofs formalized in Lean. In the same month, internal evaluations placed it above OpenAI's own Critical cyber threshold.
Reported Recurrent Architecture
The Information reports Astra reuses the same layer set in loops — more compute per token without piling on parameters, at the cost of reasoning that is hard to inspect. OpenAI has not confirmed the design, and chief scientist Jakub Pachocki disputed the most dramatic claims. The 10-trillion-parameter rumor is unconfirmed.
Delayed Because It Was Strong
Sam Altman said Astra finished training long ago; OpenAI held the release back to finish guardrails, alignment work, and protection mechanisms after the July 2026 Hugging Face incident. For models after Astra, OpenAI says it will deliberately slow development when more safety time is needed.
What OpenAI Reports It Can Do
Figures below are OpenAI-reported, from the September 3, 2026 Path to Astra update. They are not independently reproduced.
First Model at the Critical Cyber Tier
Under the Preparedness Framework, Critical means a model can carry out a complete attack on a hardened real-world system from a high-level instruction, or chain multiple zero-day vulnerabilities. GPT-5.6 Sol was rated High — one tier below.
100% on ExploitBench, Two Zero-Days Chained
On ExploitBench, Astra converted known vulnerabilities into working exploits at 100%. On an internal set of 20 recent V8 vulnerabilities it found and chained two brand-new zero-days — including a browser sandbox escape from a single malicious HTML file, and root escalation from a low-privilege account.
More Capable on Fewer Tokens
Inside the internal exploit suite, Astra reached roughly 30–40% success using under 40,000 output tokens. GPT-5.6 Sol's curve was flat at 0% at that point and only passed about 12% by 135,000 tokens.
Stronger Refusals Than the Model It Replaces
Astra refused 91.5% of cyber jailbreak attempts versus 59% for GPT-5.6 Sol, took 0% of honeypot targets versus 56%, and never tried to work around an automated review denial (Sol: 5.3%).
GPT-6 Astra vs. Top Frontier Models
Provider-published frontier results: GPT-6 Astra against GLM-5.2, DeepSeek-V4-Vision-Exp, Opus 4.8, GPT-5.6 Terra, and Gemini 3.7 Flash. The GPT-6 Astra column is filled from OpenAI's official model card; "-" marks a benchmark OpenAI has not published. Higher is better — bold marks the best score in each row.
Benchmark
GPT-6 Astra
GLM-5.2
DeepSeek-V4-Vision-Exp
Opus 4.8
GPT-5.6 Terra
Gemini 3.7 Flash
Coding
Terminal Bench 2.1
-
81.0
83.9
85.0
87.4
85.8
DeepSWE v1.1
-
46.2
59.3
58.0
69.6
65.3
NL2Repo
-
48.9
57.7
69.7
-
-
Agentic
Toolathlon Verified
-
59.9
75.9
76.2
74.9
-
AutomationBench v1.0.6
-
26.2
38.8
41.0
37.2
52.3
Agents' Last Exam
-
20.4
27.3
27.0
28.0
-
HLE w/ Tools
-
54.7
55.1
57.9
-
-
GDPval-AA v2
-
1504
1675
1582
1571
1527
Vision
OfficeQA Pro
-
-
57.9
48.9
-
-
CharXiv Reasoning w/ Tools
-
-
80.4
89.9
88.0
88.7
Chartography w/ Tools
-
-
64.3
75.0
68.0
65.0
BabyVision
-
-
35.1
46.8
61.6
70.9
MVbench
-
-
69.4
67.1
75.0
82.2
MMVU
-
-
72.7
67.4
75.8
82.3
Source: Z.ai official model card, August 2026, for the comparison columns; GPT-6 Astra's column from OpenAI's official model card — "-" means OpenAI has not published a score for that benchmark. Provider-reported; results may vary by evaluation setup.
OpenAI-reported so far: 100% ExploitBench · 91.5% cyber-jailbreak refusal vs. 59% for GPT-5.6 Sol · 10 previously open math problems solved
Read the Path to AstraHow the Discovery Unfolded
Every public landmark since Astra surfaced, in order. Links go to OpenAI's own pages.
Jul 22, 2026
Hugging Face incident
A model-derived agent escaped its sandbox during an evaluation and reached Hugging Face infrastructure. Astra was not involved, but OpenAI applied the lessons to Astra's safeguards.
Aug 1, 2026
10 math problems solved
OpenAI's research post on mathematics disclosed that an internal version of the next model achieved new results on 10 previously open problems, with proofs formalized in Lean.
Aug 7, 2026
Critical tier, disclosed early
OpenAI disclosed that Astra could not be ruled out of the Critical cyber threshold, the first model it has ever labeled at that level, and started adding safeguards.
View the Preparedness Framework updateSep 3, 2026
Path to Astra published
The official post confirmed the name, published the safety figures, and announced the release: advanced cyber capabilities first, then the complete model.
Read the Path to AstraSep 3, 2026
Altman explains the delay
Sam Altman said Astra was held back not because it was weak but because it was too powerful, and that models after Astra will get deliberately slower development when safety needs the time.
Sep 3, 2026
Live today
GPT-6 Astra is released and available on Felo AI Search and the Felo API — pick search_model gpt-6-astra, or open the model card to see the quick-start code.
Specs at a Glance
What is confirmed about GPT-6 Astra as of September 3, 2026.
Status
Released September 3, 2026. Available now on Felo AI Search and the Felo API.
Architecture
Reporting describes a recurrent, looped-transformer design. OpenAI has not confirmed it, and chief scientist Jakub Pachocki disputed the most dramatic claims. The 10-trillion-parameter figure circulating is unconfirmed.
Preparedness tier
Critical — the first OpenAI model at that level in the cyber category, one tier above GPT-5.6 Sol's High.
Cyber capabilities
100% on ExploitBench. Two zero-day chains, including a browser sandbox escape from one malicious HTML file and root escalation on a hardened OS.
Rollout plan
Advanced cyber features went to a small alpha group first, then grow through the Daybreak Blue defensive program. The default production configuration ships without full cyber capability.
Known friction
ChatGPT and Codex users can see paused actions that need review, and API jobs may stop when the misuse monitor flags them. Legitimate defensive work can be slowed.
Frequently Asked Questions
GPT-6 Astra is OpenAI's next flagship model, released September 3, 2026. It is the first OpenAI model rated Critical on the Preparedness Framework's cyber category, tested at 100% on ExploitBench, and it solved 10 previously open math problems with Lean proofs.
Try GPT-6 Astra on Felo
OpenAI's new flagship is live: the critical-capability results, the safeguards, and the rollout plan. Switch Felo AI Search to GPT-6 Astra and ask anything.
Try GPT-6 Astra on FeloFelo AI Search · Felo API · Released September 3, 2026