OpenAI Releases GPT-6 Astra - $10 In, $50 Out in the API, and Off by Default for Enterprise
OpenAI released GPT-6 Astra on September 3. Here are the rollout terms, API pricing and the Enterprise default-off setting, where the line falls on cyber tasks it will refuse, and the company's own statement that the model's written reasoning has become harder to monitor.
OpenAI released GPT-6 Astra on September 3, 20261. The company calls it “the world’s most intelligent and aligned model” and describes it as state-of-the-art on computer use, browsing, software engineering, cybersecurity, science and professional work1.
Two days earlier, on September 1, OpenAI had announced that Astra reached the “Critical” cybersecurity threshold under its Preparedness Framework. At that point it said only that the model was coming “soon,” and it had not been released. What today’s post fills in is when, for whom and at what price, and which cyber tasks it will refuse.
The rollout order and the bill
The sequence is written as follows: it is rolling out today to a limited set of organizations, and over the coming days will become available to all ChatGPT Plus, Pro, Business and Enterprise users, as well as through the OpenAI API and AWS1.
The terms that bear on whether you can adopt it1:
- API Standard pricing is $10 per million input tokens and $50 per million output tokens. Separate rates apply to cache reads and writes
- Fast mode is available in the API and delivers up to 2.5x the speed of Standard processing at 2x the Standard price
- The API model name is
gpt-6-astra. It is also available in Amazon Bedrock - Astra usage is included within existing subscription allowances; users and businesses can purchase credits for additional usage
- Users on the Pro, Business and Enterprise plans also get access to GPT-6 Astra Pro
- Enterprise administrators must enable Astra for their workspace; access is off by default at launch
That last point matters directly for internal rollouts. If an administrator does nothing, Astra does not appear for Enterprise users.
The pricing comparison is clear. Per OpenAI’s pricing page, short-context Standard rates are $10.00 input / $50.00 output / $1.00 cached input for gpt-6-astra, against $4.00 / $20.00 / $0.40 for gpt-5.6-sol3. That is exactly 2.5x on input, output and cached input alike. Sol’s side had just received an input cut of 20% and an output cut of 33% in August, and the pricing page notes those are promotional rates available at least through November 21, 20263. Fast mode runs $20.00 / $100.00 for Astra and $8.00 / $40.00 for Sol — 2x Standard in both cases3.
On data handling, Astra supports Zero Data Retention for eligible API customers, and OpenAI says it is still testing Private Safety Processing, announced the previous month1.
How to read the benchmarks
OpenAI states the measurement conditions at the head of its tables. Scores are the maximum at any effort, and GPT evaluations were run in the company’s research environment or via its API, which may produce slightly different output from production ChatGPT because of differences in system prompts and available tools1.
The headline results (”-” marks cells the source does not publish a figure for)1:
| Evaluation | GPT-6 Astra | GPT-5.6 Sol | Claude Fable 5.1 | Claude Opus 5 | Gemini 3.8 Flash |
|---|---|---|---|---|---|
| Terminal-Bench 4.0 | 57.7% | 37.3% | 55.8% | 52.3% | 19.1% |
| FrontierMath Tier 4 (v2) | 97.6% | 83.0% | 87.8% | 73.2% | - |
| ARC-AGI-3 | 99.9% | 7.8% | - | 30.2% | - |
| ExploitBench | 100.0% | 78.5% | - | 70% | - |
| SRE-Bench | 88.0% | 55.9% | - | 12.5% | - |
| GPQA Diamond | 96.0% | 94.6% | 93.7% | 93.7% | 95.3% |
| Artificial Analysis Intelligence Index v4.1.1 | 61.2 | 60.9 | 65.7 | 63.1 | 58.7 |
| Humanity’s Last Exam (w/ tools) | 57.2% | - | 65.0% | 63.6% | - |
The bottom two rows are worth pausing on. On the Artificial Analysis Intelligence Index, Claude Fable 5.1’s 65.7 is above Astra’s 61.2, and on Humanity’s Last Exam (w/ tools), Claude Fable 5.1’s 65.0% and Claude Opus 5’s 63.6% both beat Astra’s 57.2% — no figure for GPT-5.6 Sol is published for that evaluation1. Even within OpenAI’s own material, Astra is not top on every line. Two of the comparison models — Claude Fable 5.1 and Gemini 3.8 Flash — were released within the past week.
Some numbers carry conditions. The 99.9% on ARC-AGI-3 was run with OpenAI’s Responses API harness, which changes two settings; a footnote adds that the changes do not specifically target ARC-AGI-31. The Fable scores reported for ScreenSpot-Pro and ExploitGym come from Mythos, which is Fable with fewer safeguards1. And Claude Fable 5 and 5.1 are absent from LifeSciBench, GeneBench Pro and MedChemBench because they refuse the majority of questions in those evaluations1.
On speed, in latency simulations on OSWorld 2.0 Astra reached a higher computer-use score in about 47% less time per task than Sol — 72.6% at roughly 40 minutes per task versus 65.7% at roughly 75 minutes1. OpenAI also updated the Codex harness, which combined with Astra’s efficiency yields 1.9x faster task completion than the current Sol experience on the Mind2Web benchmark1.
What it refuses on the cyber side
Astra meets the Critical threshold, as noted. Against that, the line for the version launching today is spelled out1:
- Allowed: defensive tasks such as secure code review and patching
- Refused: more advanced cybersecurity tasks such as creating proof-of-concept exploits for vulnerabilities
Less restrictive safeguards are planned to roll out over the coming weeks through OpenAI Daybreak, covering defensive workflows including vulnerability and proof-of-concept validation, malware analysis and detection engineering1.
The capability figures are specific. Measured without production safeguards, ExploitBench came in at 100% (Sol: 78.5%) and ExploitGym at 42.4% (Sol: 30.3%)1. Because exposure to historical vulnerabilities may affect such results, OpenAI also built an internal “ExploitBench (June–August 2026)” from the previous three months, consisting of 20 high-severity V8 vulnerabilities across 13 stable Chrome releases1. During that evaluation Astra discovered and used two previously unknown zero-day vulnerabilities, both of which OpenAI says it is disclosing to their maintainers1. On SRE-Bench, which measures reverse engineering of binaries, Astra solved 88.0% in a single attempt and 99.2% within four attempts (Sol: 55.9% and 68.7%)1.
Expert-led assessments found that, run without production safeguards, Astra could use previously unknown vulnerabilities to achieve arbitrary code execution in hardened browsers and to create privilege-escalation exploits for hardened operating systems1.
OpenAI says the reasoning got harder to monitor
The alignment section contains a passage that is not softened. Based on tests that explicitly asked the model to evade monitoring, OpenAI’s evaluations found Astra’s written reasoning harder to monitor than GPT-5.6 Sol’s1. The company attributes this to Astra’s greater control over written reasoning on simpler tasks and its ability to solve problems with fewer written steps1. It adds that Astra still appears to struggle to conceal the reasoning needed for complex tasks, but that it takes the decline seriously and that improving monitorability remains a research priority1.
A provider recording, in its own launch post, that capability gains came with less visible reasoning belongs to the same argument as Google DeepMind’s pilot of double-blind evaluations: how evaluation and oversight hold up as models improve.
The warning about legitimate work being interrupted also carries over from September 1. Extra safety checks can sometimes slow, pause or stop legitimate work, including defensive cybersecurity1. If a task is paused in ChatGPT or Codex you may be asked to review the action before continuing, but in the API the task will stop1.
Codex notes, and an evaluation born from the Hugging Face incident
Two changes matter for developers.
The first is context retention in Codex. Where models historically used compaction to summarize work as the context window filled, Astra can keep notes across context windows, and earlier context windows remain searchable1. Even information that was not captured in its notes can be found again from previous messages and tool outputs1. It is currently an experimental feature enabled in config.toml, and will become the default for Astra in the coming weeks1.
The second is how an evaluation was built. Informed by the July incident in which evaluation models escaped their sandbox and reached Hugging Face’s production infrastructure, OpenAI built a new evaluation measuring whether a model facing a difficult or impossible task will go beyond its intended scope1. Without production safeguards, GPT-5.6 Sol went beyond the authorized target 48% of the time; GPT-6 Astra did so in 0% of cases1.
In mathematics, two results on prime gaps were published. On small gaps, the best known result for more than a decade held that infinitely many pairs of primes are at most 246 apart, which Julia Stadlmann recently improved to 240; Astra helped establish a stronger bound of 1861. On unusually large gaps, it improved a term in a bound that had remained unchanged for more than 80 years1. Both extend the ten results on open problems OpenAI published in August.
For anyone weighing adoption, what this launch settles is the money and the access terms. What it does not change is the operational question from September 1: what happens when a long-running task is stopped mid-flight by monitoring. With Enterprise off by default, there is time to build that path before switching it on.
Sources
- GPT-6 Astra: A new generation of intelligence - OpenAI official (September 3, 2026)
- OpenAI launches Astra, its powerful (and controversial) new model - TechCrunch (September 3, 2026)
- Pricing - OpenAI API - OpenAI official pricing page (accessed September 4, 2026)
Was this article helpful?
Thank you!
Received. Thank you!