# Perplexity Gives OpenAI's GPT-6 Astra Standing Access to Production Software

OpenAI's account describes Astra writing communications, changing code, and monitoring live systems with far fewer human check-ins, weeks after the same model was rated Critical for cyber capability under OpenAI's own risk framework.

- Published: 2026-09-14T06:22:55.303Z
- Canonical: https://polylog.news/ai/2026-09-14/perplexity-gives-openai-s-gpt-6-astra-standing-access-to-pro
- Publisher: Polylog (AI desk)
- Section: tech
- Sources: [OpenAI](https://openai.com/index/perplexity-improving-accuracy-with-astra), [Polylog editors](https://polylog.news)

OpenAI published a customer account on September 14 describing how Perplexity uses GPT-6 Astra. According to [the write-up](https://openai.com/index/perplexity-improving-accuracy-with-astra), the model drafts communications, modifies software, and monitors production systems, and Perplexity's engineers check in on it considerably less often than they did with earlier models. OpenAI also says Astra builds its own small test programs that imitate the responses a dependent service would return, so it can exercise a workflow end to end before a human reviews the result.

The claim is a vendor claim. OpenAI publishes no error rate, no rollback count, and no independent measurement of how often Astra's unattended changes needed correction. Perplexity is also a close commercial partner, so the account is best read as evidence that one sophisticated customer is willing to grant that autonomy, not as a measurement of how reliable that autonomy is.

The autonomy claim coincides with a separate risk classification. CSO Online [reported](https://www.csoonline.com/article/4218679/openai-launches-gpt-6-astra-its-first-model-to-cross-a-critical-cybersecurity-threshold.html) that Astra is the first OpenAI model to reach the Critical cybersecurity tier under the company's Preparedness Framework, meaning it can autonomously find and exploit previously unknown vulnerabilities under the right conditions. OpenAI gates those offensive capabilities behind a vetted-access program called Daybreak, while the generally available model refuses the tasks. Astra is priced at $10 per million input tokens and $50 per million output tokens with roughly a one million token context window, placing it at the same headline price as Anthropic's Claude Fable 5.1.

Separately, an AI channel on Telegram [circulated a demonstration](https://t.me/aipost/8136) in which Astra built a working simulation of a violin and then trained itself to play it, later attempting original composition. That claim rests on a single unattributed post and has no primary source behind it, unlike the Bach chorale and Ableton Live demonstrations that accompanied Astra's launch and were reproduced by multiple outlets.

## What this means

The economically significant number in agent deployment is not a benchmark score, it is supervision frequency. If a customer of Perplexity's sophistication genuinely reduces check-ins on production changes, the labor cost per unit of software work falls in a way benchmark suites do not capture, and the buyer of AI shifts from a per-seat tool to a metered replacement for on-call engineering time. The counterweight is that the same model carries a Critical cyber rating from OpenAI, so the software that can be trusted to edit production is also the software with the strongest demonstrated ability to break into it, which puts the burden on customer-side permission scoping rather than model-side refusal.

## What to watch

- Whether Perplexity or any other customer publishes its own numbers on how often unattended Astra changes were reverted, which would convert a vendor narrative into a measurable reliability claim.
- Whether enterprise security teams begin requiring separate credentials and audit trails for agent-initiated production changes, a sign that agent autonomy is being treated as a privileged account rather than a developer tool.
- Whether OpenAI expands or restricts the Daybreak vetted-access program, since a widening of access would indicate the company judges the Critical cyber rating to be manageable in practice.
