3 hrs ago
OpenAI Releases GPT-6 Astra After Critical Cybersecurity Finding
OpenAI says GPT-6 Astra can independently identify and develop zero-day exploits against hardened systems.
The model is the first OpenAI system rated “Critical” for cybersecurity under its Preparedness Framework.
In a test using recently disclosed vulnerabilities, Astra reportedly found two previously unknown vulnerabilities.
Without production safeguards, Astra scored 100% on ExploitBench and 42.4% on ExploitGym.
OpenAI will limit access initially, while considering broader access for vetted defenders through its Daybreak program.
- Who
- OpenAI and its GPT-6 Astra model; the company also references cybersecurity defenders and software makers.
- What
- OpenAI released Astra and classified it as Critical for cybersecurity after reporting that it could independently discover and develop exploits.
- Where
- Astra was trained using more than 100,000 GPUs at Stargate and will be offered through OpenAI products and selected organizations.
- When
- The release followed testing against vulnerabilities disclosed during the three months before launch; the article does not give an exact release date.
- Why
- OpenAI says the restrictions are needed because Astra can perform advanced offensive cybersecurity tasks, while its Daybreak program is intended to help vetted defenders.
Restrict Access
Expand Defender Access
Who should receive Astra’s advanced capabilities?
Restrict Access
Because OpenAI classifies Astra as Critical and the model can perform advanced offensive tasks, access should remain tightly restricted and require administrator approval.
Expand Defender Access
Cybersecurity defenders are outnumbered by attackers, so vetted defenders could use Astra to find and fix flaws before criminals exploit them.
Public safeguards
Restrict Access
The public model should refuse advanced offensive requests, including requests to generate proof-of-concept exploits, to reduce misuse.
Expand Defender Access
OpenAI intends to relax some restrictions for approved defenders through Daybreak, arguing that defensive work may require access to stronger capabilities.
Risk from scalable capability
Restrict Access
The capability was achieved through large-scale computing rather than a unique safety breakthrough, suggesting others with comparable resources could reproduce it.
Expand Defender Access
The same scalability could make automated vulnerability discovery more widely available to legitimate security teams, if access is carefully controlled.
Key facts
- Model
- GPT-6 Astra
- Cybersecurity rating
- Critical, the first such rating OpenAI has assigned under its Preparedness Framework
- Previously unknown vulnerabilities found
- Two, during testing against recently disclosed vulnerabilities
- ExploitBench score
- 100% without production safeguards, compared with 78.5% for GPT-5.6 Sol
- ExploitGym score
- 42.4% without production safeguards, compared with 30.3% for GPT-5.6 Sol
- Initial access
- Limited organizations first; enterprise workspaces have Astra disabled by default
- Planned defender program
- Daybreak, intended to provide broader capabilities to vetted defenders








