OpenAI officially unveiled GPT-6 Astra on Thursday, its new frontier model — and the security industry's first extended look at how the company plans to gate capabilities that its own benchmarks place at the top of the scale.
What the Model Can Do
OpenAI says Astra saturates ExploitBench — an evaluation of a model's ability to turn known software vulnerabilities into working exploits — with a perfect 100% score, up from 78.5% for GPT-5.6 Sol, its previous frontier cyber-capable model. The company also reports substantially higher arbitrary code-execution rates when testing against flaws disclosed between July and August 2026, including two zero-day vulnerabilities in unspecified software.
Left unrestricted, OpenAI says, Astra can use previously unknown vulnerabilities to achieve code execution in hardened browsers and develop privilege-escalation exploits for hardened operating systems.
The release comes days after OpenAI said the model had reached the "Critical" threshold under its Preparedness Framework — the first model to do so — a designation we covered alongside Anthropic's disclosure of Claude-related security failures earlier this week.
What's Gated
The version being rolled out is deliberately limited. OpenAI says Astra's public release is restricted to secure code review and patching, and refuses prompts that ask it to create proof-of-concept exploits for vulnerabilities — the exact task it scores perfectly on.
Broader access is planned through OpenAI Daybreak in the coming weeks, with less restrictive safeguards enabling "vulnerability and proof-of-concept validation, malware analysis, and detection engineering." The company has also added jailbreak robustness, expanded monitoring context, and safeguards intended to detect and contain misalignment, while warning that safety checks can sometimes interrupt legitimate defensive work.
Astra is rolling out first to a small set of organizations, ahead of availability to ChatGPT Plus, Pro, Business, and Enterprise users and through the OpenAI API, Microsoft Azure, and AWS Bedrock.
A $1 Billion Defender Program
Alongside the launch, OpenAI announced Daybreak for Frontline Defenders, a $1 billion commitment providing subsidized model access, training, and technical assistance to critical-infrastructure sectors: water systems, electricity providers, state and local governments, banks, nonprofits, open-source maintainers, and security-constrained organizations.
A pilot with the Multi-State Information Sharing and Analysis Center (MS-ISAC) will equip an initial group of public-sector and water-system defenders with Daybreak access and guided training.
The framing is a race narrative: OpenAI argues there is a "narrowing" window for defenders to close security gaps before attackers exploit the same model capabilities. For an industry already using automated code analysis to screen smart contracts and infrastructure, the arrival of a model that can chain zero-days unassisted — even a restricted one — sharpens both sides of that equation.
TrustGrade covers security tooling and defense across crypto infrastructure. Verified, registry-backed security scoring arrives with TrustGrade Code Scoring in December 2026.