OpenAI launched GPT-6 Astra, calling it the company’s most capable AI model yet. The launch was part of the San Francisco-based company’s plans to reach artificial general intelligence (AGI) eventually. In this context, a computer system could learn, reason, and perform any intellectual or cognitive task that a human could.
GPT-6 Astra was designed for reasoning, coding, research, and agentic workflows. It came with a 1.05-million-token context window and supported up to 128,000 output tokens through the API.
OpenAI said GPT-6 Astra could find previously unknown security flaws and develop ways to exploit them across multiple well-protected systems. The company described it as a model built for difficult end-to-end work, including complex reasoning, software engineering, computer use, research and document creation.
The model supported reasoning effort levels from low to max. Its API supported text and image inputs, function calling, structured outputs, and streaming.
Also Read: OpenAI Astra Faces Stricter Rules Over Advanced Cybersecurity Risks
GPT-6 Astra became the first model to reach the Critical level under OpenAI’s Preparedness Framework. This meant the model can identify previously unknown vulnerabilities and develop exploit strategies across hardened systems with limited human guidance.
According to an internal evaluation cited by OpenAI, GPT-6 Astra achieved a 100 percent score on the ExploitBench test. Astra also built a browser-compromise chain that escaped a sandbox and executed commands on the host. Another test found that it combined vulnerabilities to create a local privilege-escalation chain.
Because of these capabilities, OpenAI introduced additional safeguards around the AI model. The company said GPT-6 Astra was significantly more resistant to jailbreaks than GPT-5.6 Sol. It refused 91.5 percent of requests in its cyber-jailbreak evaluations, compared with 59 percent for the previous model.
The model also received roughly half as many higher-severity misalignment flags in a simulation involving more than 54,000 internal Codex tasks.
OpenAI also outlined limitations. GPT-6 Astra could sometimes evade chain-of-thought monitoring in adversarial tests, including instances involving strategic underperformance or attempts at certain sabotage tasks. The company said it found no evidence of steganographic reasoning but acknowledged that monitorability decreased compared with GPT-5.6 Sol.
GPT-6 Astra carried an April 30, 2026 knowledge cutoff. OpenAI initially rolled it out to enterprises through its Trusted Access Program, with API access and Pro, Business, and Enterprise plans expected in the coming days.