# OpenAI Opens GPT-6 Astra to Business Subscribers Days After Rating It Critical for Cyber Capability

The model scored 100% on ExploitBench and found two previously unknown zero-day vulnerabilities in testing, so OpenAI is shipping it with refusals on offensive security work and a vetted-defender carve-out.

- Published: 2026-09-06T06:32:46.692Z
- Canonical: https://polylog.news/ai/2026-09-06/openai-opens-gpt-6-astra-to-business-subscribers-days-after
- Publisher: Polylog (AI desk)
- Section: tech
- Sources: [Polylog editors](https://polylog.news)

OpenAI has moved GPT-6 Astra from a staged launch into broad paid availability. The Russian-language technical channel AI ML Big Data [reported](https://t.me/ai_machinelearning_big_data/10846) that Pro, Enterprise and Business Premium subscribers now reach the model directly inside ChatGPT Work, inside the Codex development environment and through the applications programming interface (API), with Plus and standard Business accounts to follow over several days.

The capability numbers OpenAI published are large. The company reports 72.6% on OSWorld 2.0 against 65.7% for its prior model at roughly 47% less time per task, 97.6% against 83.0% on FrontierMath Tier 4, and 92.7% against 76.9% on ScreenSpot-Pro, which measures whether a model can locate and click the correct pixel in a dense interface. Every one of those figures comes from [OpenAI's own launch material](https://openai.com/index/gpt-6-astra/) rather than from independent reproduction, and the OSWorld and ScreenSpot comparisons are drawn against GPT-5.6 Sol, OpenAI's previous release, not against Anthropic's or Google's current models.

The security classification is the part that changes how engineers must deploy it. OpenAI says Astra is the first model to reach the Critical cybersecurity tier of its Preparedness Framework, meaning it can develop working zero-day exploits against hardened real-world systems without human direction. It scored [100% on ExploitBench](https://thehackernews.com/2026/09/gpt-6-astra-scores-100-on-exploitbench.html) for turning documented vulnerabilities into working exploits, and 39% on the June to August 2026 slice covering vulnerabilities disclosed after training. [CSO Online reported](https://www.csoonline.com/article/4218679/openai-launches-gpt-6-astra-its-first-model-to-cross-a-critical-cybersecurity-threshold.html) that the public deployment refuses proof-of-concept exploit generation, with looser access promised to vetted defenders through a program OpenAI calls Daybreak.

For builders, the [API documentation](https://t.me/ai_machinelearning_big_data/10844) is where the structural change shows up. Astra supports asynchronous tool calling, so the model keeps reasoning or answers independent parts of a request while an application executes a tool and returns the result later against the original call identifier. Context runs to 1,050,000 tokens with up to 128,000 output tokens, and pricing is $10 per million input tokens and $50 per million output tokens, well above the $1.25 and $4.25 Meta charges for Muse Spark on its standard tier.

The clearest way to read this is that OpenAI is doing two things at once. It is asserting a capability jump that only it has measured, and it is using a self-defined safety tier to justify gating the most commercially valuable version of that capability behind a vetting program it controls.

## What this means

A vendor that both writes the cyber-capability threshold and decides who passes it now controls the access point between offensive security tooling and the market. Security vendors and penetration-testing firms that depend on model access become dependent on OpenAI's Daybreak vetting, while defenders without that access face attackers who may reach comparable capability through open-weight models with no refusal layer. The $10 and $50 per million token pricing also separates Astra from the price war running at the low end, so cost-sensitive agent workloads keep flowing to Meta, Google and Chinese open-weight stacks.

## What to watch

- Whether any independent group reproduces the ExploitBench and OSWorld results, since so far only OpenAI has published them, and a large gap between vendor and third-party numbers would indicate the benchmark design, not the model, produced the score.
- How wide the Daybreak vetted-defender program opens, because a narrow list keeps advanced offensive capability concentrated among a small number of approved users, and a broad one tests whether refusal training holds up once real customers use it.
- Whether open-weight releases from Chinese or European labs approach the same exploit-development scores, which would make OpenAI's gating commercially costly rather than protective.
