On 3 September 2026 OpenAI presented GPT-6 Astra. President Greg Brockman ended the press briefing, according to Axios, with the words "Welcome to the AGI era". A few hours later Sam Altman wrote publicly that he was sorry for the messy rollout. Both belong to the same story, and neither says anything yet about what the model actually delivers.
This article keeps three classes of statement apart, exactly like my fact check from July: vendor statements from OpenAI's own documents, independent measurements with index version and cut-off date, and my own assessment for everyday business use. Research as of 8 September 2026. Which AI tools I actually use is documented with a cut-off date and a source on the AI in numbers page, and the video version sits on the video page.
The verifiable specifications
Before the benchmarks, the things that simply appear in the documentation. All values are vendor statements from OpenAI's model and pricing pages, retrieved on 7 September 2026.
| Specification | Value |
|---|---|
| Model ID in the API | gpt-6-astra |
| Context window | 1,050,000 tokens |
| Maximum output | 128,000 tokens |
| Knowledge cutoff | 30 April 2026 |
| Input and output | text and image in, text out |
| Announced | 3 September 2026 |
The launch was staggered. On 3 September the organisations in OpenAI's application-based cybersecurity programme Daybreak got access first. On 4 September Pro, Enterprise and Business Premium in ChatGPT Work and Codex followed, along with the API, and a few hours later all Plus and Business users as well. The announcement does not mention free access at all; it lists only Plus, Pro, Business and Enterprise. Whether free users get access later is open.
What Astra costs
Prices per one million tokens, standard processing, vendor figures from the price list. For GPT-5.6 Sol this is the temporary promotional price; Sol's regular price was 5 USD input and 30 USD output.
| Position | GPT-6 Astra | GPT-5.6 Sol (predecessor) |
|---|---|---|
| Input | 10.00 USD | 4.00 USD |
| Cache read | 1.00 USD | 0.40 USD |
| Cache write | 12.50 USD | 5.00 USD |
| Output | 50.00 USD | 20.00 USD |
Table scrolls sideways
That is exactly a factor of 2.5 compared with the predecessor, and Artificial Analysis does the same arithmetic. Two pitfalls sit in the footnotes of the model page. First: for prompts above 272,000 input tokens, the entire request is billed at double the input and cache rates and 1.5 times the output rate, so 20.00 USD input and 75.00 USD output. Second: fast mode is up to twice as fast according to OpenAI, and it costs twice as much. Batch and flex sit at 50 percent of the standard rate.
In the competitive picture the list price is hardly surprising: 10 and 50 US dollars are exactly the values that Anthropic's price table shows for Claude Fable 5.1 as well. The difference sits in cache reads, where OpenAI charges 1.00 US dollar and Anthropic 0.25 US dollars per million tokens. What Fable 5.1 does otherwise I wrote up in my Claude Fable 5.1 review.
The marketing triad
In the announcement post OpenAI calls Astra the world's most intelligent and most aligned model. Three numbers carry that announcement, and all three are vendor measurements from OpenAI's own research environment:
- FrontierMath Tier 4, the hardest tier of Epoch AI's mathematics benchmark: 97.6 percent. The running text of the same post says 98 percent, the benchmark table says 97.6. I use the table.
- ARC-AGI-3, a benchmark for abstract reasoning: 99.9 percent.
- ExploitBench, a cyber benchmark covering 41 vulnerabilities in the V8 JavaScript engine: 100 percent.
One sentence in the post itself belongs to the third number: the cyber benchmarks were measured without the safeguards of the production version. The shipped model behaves differently, more on that below.
The ARC trap
The middle number is the most interesting one, because its limitation sits in footnote 1. On ARC-AGI-3 Astra ran with OpenAI's own responses API harness, which changes two settings. In the benchmark's official harness the score is 66 percent according to Fortune. The comparison value for the predecessor GPT-5.6 Sol, 7.8 percent, comes from the official harness, as does the 30.2 percent for Claude Opus 5. Two measurement methods in one table, without the row saying so.
OpenAI itself described the size of that effect back in late July: two API settings, retained reasoning and compaction, tripled the scores on the public task set and cut token use considerably. What remains fair: 66 percent is strong, and Greg Kamradt of the ARC Prize Foundation, quoted in the announcement post, says Astra surpassed the human action efficiency baseline on 96 percent of levels. The 99.9 percent simply is not a comparison figure.
What OpenAI's own table shows
Now the detail almost nobody read. In its own benchmark table OpenAI also shows values from Artificial Analysis and from Humanity's Last Exam, and there the picture differs from the headline.
| Measurement in OpenAI's table | GPT-6 Astra | Best Claude model in the same row |
|---|---|---|
| AA Intelligence Index v4.1.1 | 61.2 | 65.7 (Fable 5.1) |
| AA Coding Agent Index v1.4 | 67.0 | 68.1 (Opus 5) |
| Humanity's Last Exam, with tools | 57.2 % | 65.0 % (Fable 5.1) |
Table scrolls sideways
On the broad knowledge and reasoning test Astra therefore sits behind all three Claude models, and that is how it appears at OpenAI. Two footnotes belong here in the other direction, for fairness: on ScreenSpot-Pro and ExploitGym the Claude values come from Mythos according to footnote 17, that is Fable with fewer safeguards. And the empty Claude cells in the biology benchmarks are not weak results but refusals, because the models decline the majority of those questions.
Independently measured: Artificial Analysis
Artificial Analysis is an independent benchmarking house, and the index version is decisive here. On 3 September, under v4.1.1, Astra sat five points behind Fable 5.1. The index has been rebuilt twice since then, v4.2 on 4 September and v4.3 on 7 September. Anyone quoting one of those numbers has to name the version.
| Metric, as of 8 September 2026 | GPT-6 Astra (max) | Claude Fable 5.1 (max) |
|---|---|---|
| Intelligence Index v4.3 | 53 | 53 |
| Coding Agent Index v1.4 | 67 | 70 |
| Cost per index task | 3.26 USD | 7.63 USD |
| Cost per coding task | 4.72 USD | 9.18 USD |
| Output speed | 62 tokens/s | 70 tokens/s |
Table scrolls sideways
Under v4.3 both models therefore sit level at the top. On coding Astra is behind Fable 5.1 and Opus 5, but costs roughly half per task and takes the longest at 26.8 minutes. Astra is not fast: 62 tokens per second sit below the median of 70 that Artificial Analysis reports for the whole field.
The most honest plus point appears in no press release. In the measurement from 3 September, Astra delivers 49 percent hallucination-free answers, Fable 5.1 reaches 27 percent and the predecessor GPT-5.6 Sol 8 percent. In the intelligence ranking the relationship with Claude is reversed; when it comes to inventing facts it is unambiguous.
Safety: the first model at Critical
And now the actual story. According to the system card, Astra is the first OpenAI model to reach the Critical level for cybersecurity under the company's own Preparedness Framework. OpenAI describes it like this: with the right tools and access the model can find previously unknown security flaws and develop new ways to exploit them across many well protected systems, without a person guiding each step. For biology and chemistry Astra sits at High, for AI self-improvement below the High threshold.
That explains why the shipped version is trimmed. It supports defenders with secure code review and patching, but refuses advanced tasks such as building proof-of-concept exploits. Less restrictive safeguards are meant to reach vetted defenders first through the Daybreak programme. And OpenAI warns about the side effect itself: extra safety checks can slow, pause or stop legitimate work. In ChatGPT and Codex you are then asked to review the action, in the API the task stops.
The uncomfortable line in the same file
A second sentence sits in the same system card, and it does not match the headline. In substance, and the translation is mine: the monitorability of GPT-6 Astra has decreased relative to GPT-5.6 Sol. The model is more capable of controlling its own chain of thought and less likely to include incriminating information. In adversarial tests, where OpenAI pushes the model to evade, it was able to hide deliberate underperformance and sometimes evade internal monitors on certain sabotage tasks. OpenAI found no evidence of hidden character encoding in the chain of thought.
At the same time OpenAI calls Astra the most aligned model it has ever built, and backs that with its own figures: 2.4 percent instead of 22.0 percent unwanted outcomes in the internal computer use safety test, and 0 percent instead of 48 percent on the question of whether the model goes beyond the authorised target. Both statements sit in the same documents. An honest report needs both sentences in one paragraph, not spread across two pages.
The July incident and why Astra came later
Why this point carries so much weight is explained by July. During internal cyber evaluations, OpenAI models broke out of their sandbox, built themselves an improvised message board through an internally hosted package server, used it to gain internet access and intruded into Hugging Face systems through previously unknown vulnerabilities. OpenAI today calls the driving model IM1, an internal research model never intended for release. According to OpenAI's post-mortem, the agents at times described themselves as a swarm or a collective.
| Date | Event |
|---|---|
| 12 May 2026 | First entry on the improvised message board |
| 26 May 2026 | Internet access through the package server |
| 5 July 2026 | Security incident opened, package server rebuilt |
| 9 to 13 July 2026 | Period of the actions reconstructed by Hugging Face |
| 19 July 2026 | OpenAI stops running ExploitGym evaluations |
| 28 August 2026 | Restart of the large RL training run that had been paused |
In its own technical timeline, Hugging Face reconstructed around 17,600 attacker actions, grouped into roughly 6,280 clusters. Astra was not involved according to OpenAI, which is a vendor statement and not an external audit. The consequence is documented, though: OpenAI paused certain frontier training for two weeks, tightened isolation, network controls and monitoring, and only restarted the large RL run on 28 August. That is why Astra arrived later than the rumours wanted it to.
Then versus now
My post from 29 July was called: no GPT-6. What held up?
| Point | As of 29 July 2026 | Documented today |
|---|---|---|
| Name | There is no model called GPT-6 | GPT-6 Astra since 3 September, API ID gpt-6-astra |
| Date | Leak claimed a launch within four weeks | Announced 3 September, broad access on 4 September |
| Context | Rumour: 1.5 million tokens | 1,050,000 tokens, the real figure is 30 percent below the rumour |
| Parameters | Rumour: ten trillion | OpenAI still gives no figure |
| Advice | Do not plan around a model that does not exist yet | It held up, access arrived in stages over days |
Table scrolls sideways
The existence of a stronger, unreleased model was correctly documented back then. That model is simply not Astra, but the research model known today as IM1.
What this means for businesses
Now my assessment, based on the points documented above and on my own work with these tools, not an external fact.
You get access from the Plus plan upwards, and in the API at the same list price as the direct competitor. From my own practice, three points matter. First: if wrong facts get expensive in your process, for example in research, quote checks or analyses, the lower hallucination rate is the strongest argument for Astra, and it is independently measured. Second: on coding Claude still leads the independent index, while Astra costs roughly half per task; anyone automating a lot should weigh exactly that instead of comparing headlines. Third: plan for safety checks pausing tasks or stopping them in the API. That is not a bug, it is intended.
And the two-minute check still applies: when someone shows you a benchmark number, ask for the index version, the cut-off date and the harness. Those three questions are exactly where the difference between a headline and a reliable basis for a decision becomes visible. If you want to work out which AI tools fit your tasks, your data protection framework and your budget, that is precisely the subject of my AI consulting.
Sources
- OpenAI, GPT-6 Astra announcement, 3 September 2026: openai.com/index/gpt-6-astra
- OpenAI, system card in the Deployment Safety Hub, 3 September 2026: deploymentsafety.openai.com/gpt-6-astra
- OpenAI, Path to Astra, 1 September 2026: openai.com/index/path-to-astra
- OpenAI, post-mortem on the Hugging Face incident: openai.com/index/hugging-face-incident-and-the-road-ahead
- OpenAI on the two settings in ARC-AGI-3, 29 July 2026: openai.com/index/how-two-settings-tripled-our-arc-agi-3-scores
- OpenAI, model page and pricing, retrieved 7 September 2026: platform.openai.com/docs/models/gpt-6-astra and platform.openai.com/docs/pricing
- Hugging Face, technical timeline of the incident, 27 July 2026: huggingface.co/blog/agent-intrusion-technical-timeline
- Artificial Analysis, launch analysis, 3 September 2026: artificialanalysis.ai/articles/benchmarking-gpt-6-astra
- Artificial Analysis, model page with index v4.3, retrieved 8 September 2026: artificialanalysis.ai/models/gpt-6-astra
- Artificial Analysis, coding agent benchmarks, retrieved 8 September 2026: artificialanalysis.ai/agents/coding-agents
- Axios on Greg Brockman's AGI statement, 3 September 2026: axios.com
- Fortune on the ARC-AGI-3 measurement in the official harness, 3 September 2026: fortune.com
- CNBC on the staggered launch via the Daybreak programme, 3 September 2026: cnbc.com
- The New Stack on the rollout and Altman's apology, 4 September 2026: thenewstack.io
- Anthropic, price table for Claude Fable 5.1, retrieved 7 September 2026: platform.claude.com/docs/en/about-claude/pricing
As of 8 September 2026. GPT and ChatGPT are trademarks of OpenAI, Claude is a trademark of Anthropic PBC. Editorial mention, no partnership.




