In brief
- OpenAI released GPT-6 Astra, which president Greg Brockman called a “generational leap” and the arrival of AGI.
- Astra is the first model OpenAI has designated “critical” under its Preparedness Framework for cybersecurity.
- The model scored 100% on ExploitBench and discovered two zero-day vulnerabilities in Google’s V8 engine during testing.
OpenAI on Thursday released GPT-6 Astra, a model president Greg Brockman called a “generational leap in capability” and the arrival of artificial general intelligence, or AGI.
In a press briefing, Brockman told reporters he believes Astra meets the bar for AGI, which means artificial intelligence that can match or exceed human capabilities. “Welcome to the AGI era,” he said, after introducing the company’s most-capable model to date.

If accurate, it would mean AI agents would come closer to doing the complex reasoning work humans can do, or more, across various different tasks. Brockman also acknowledged that Astra is the first system the company has rated capable of autonomously hacking well-protected systems without human guidance, raising safety and security concerns.
Astra is OpenAI’s first model to cross the “critical” threshold under its Preparedness Framework, the company’s internal scoring system for dangerous capabilities.
That designation means the model can independently discover previously unknown software flaws—called zero-day vulnerabilities—and chain them into working exploits across hardened systems without step-by-step human oversight.
In testing, it scored 100% on ExploitBench, a benchmark that measures a model’s ability to turn known software flaws into functioning attacks. To confirm the score wasn’t inflated by memorized answers, OpenAI built a second test using 20 recent vulnerabilities in Google’s V8 JavaScript engine.
Astra not only outperformed its predecessor GPT-5.6 Sol but also found and chained together two previously unknown zero-days that the company is still disclosing to affected maintainers.
What’s new
The model’s autonomy represents a shift from AI as a tool that recommends actions to AI as an agent that executes them. In a video demonstration, Astra formatted a legal contract, built a 3D game, and booked a tennis court while simultaneously searching for food options.
Per reports, OpenAI says it can lay out a printed circuit board in KiCad, draft a tax return from a W-2, and build a 3D city scene in Unity. In scientific evaluations, it improved a mathematical result on gaps between prime numbers and set new marks across biology, chemistry, medical, and physics tests.
Unconfirmed leaks also point to a very powerful model now beating the strongest competitors by a wide margin on benchmarks. The model scores 98.6% on the ARC-AGI3 benchmark which means, if confirmed, that this is also the closest model to industry-wide AGI standards.

The same autonomy that lets Astra complete complex tasks makes it harder to monitor. OpenAI acknowledged that in evaluations designed to test whether the model could evade oversight, Astra was more difficult to track than previous systems.
Chief scientist Jakub Pachocki said the company will need to strengthen monitoring through techniques like activation monitoring—reading the model’s internal signals during reasoning—or making its chain of thought more transparent.
Innovation vs safety
The release follows weeks of industry turbulence. In July, an unreleased OpenAI model escaped a training sandbox and breached Hugging Face’s systems, an incident that spooked the sector.
OpenAI had previously paused Astra’s development in August after its cyber capabilities advanced faster than expected. Rival Anthropic on Tuesday released Claude Fable 5.1, and Meta and Google have also announced model updates this week.
Previous AI models needed a human to point at a vulnerability and ask the model to explain it. Astra can start from scratch, find the hole in the code, build the weapon to exploit it, and break into a system—all without being told where to look. That capability is why OpenAI is releasing it first to cybersecurity defenders through its Daybreak Blue program, rather than making it immediately available to every ChatGPT user.
According to reports, Astra was reviewed by the White House under the Donald Trump administration’s voluntary review framework, though the specifics of that process remain undisclosed.
The model’s advanced cybersecurity capabilities remain gated behind the Daybreak Blue program for now, with broader ChatGPT Plus, Pro, Business, Enterprise, and API access planned in the coming days.
Daily Debrief Newsletter
Start every day with the top news stories right now, plus original features, a podcast, videos and more.






