OpenAI's GPT-6 Astra Sparks AGI Claims and Security Alarms

OpenAI says GPT-6 Astra marks the AGI era, but admits the model can also find and exploit unknown security flaws on its own.

Sep 6, 2026 - 19:12
5 min read
 0
OpenAI's GPT-6 Astra Sparks AGI Claims and Security Alarms

Greg Brockman didn't say OpenAI was getting close to artificial general intelligence. He said it happened. OpenAI's president closed the briefing for the company's newest model, GPT-6 Astra, with four words: "Welcome to the AGI era."

A model built to act, not just chat

Astra launched on September 3 as a limited preview before rolling out more broadly to ChatGPT Plus, Pro, Business, and Enterprise users, along with access through the OpenAI API, Microsoft Azure, and Amazon Bedrock. Unlike earlier GPT releases that were sold mainly as better conversationalists, Astra is pitched as a model built for computer use, software engineering, and long multi-step tasks that it can carry out with minimal hand-holding.

OpenAI trained it on what it calls its largest run yet, using more than 100,000 GPUs at the company's Stargate site in Texas. The benchmark numbers are the kind that used to sound like marketing exaggeration: a 98% score on FrontierMath Tier 4 (a set of research-level math problems designed to be nearly impossible for AI), and 99.9% on ARC-AGI-3, a test built specifically to resist pattern-memorization and reward genuine reasoning.

"Welcome to the AGI era." — Greg Brockman, OpenAI president

Whether that framing holds up is a separate argument, and one plenty of researchers outside OpenAI aren't ready to concede. But the capability jump behind the number is real enough that it changes what the model is allowed to do unsupervised — and that's where the story gets more complicated.

The number nobody wanted to hit

Astra is the first OpenAI model to cross what the company calls the "Critical" threshold on its internal Preparedness Framework for cybersecurity. In plain terms: under the right conditions, it can find previously unknown security holes — the kind researchers call zero-days, meaning the software's makers have had zero days to fix them — and build a working exploit for them, largely on its own.

In OpenAI's own testing, Astra found an unknown vulnerability in a web browser and got unsandboxed code execution (breaking fully out of the safety container browsers run untrusted code in) after 29 hours of unattended work. Asked to adapt that exploit for the official stable release of the browser, it managed it in another 12 hours. It reportedly did something similar against an operating system kernel.

  • Access to Astra's offensive security capability is gated behind a vetted program OpenAI calls Daybreak — the public ChatGPT version refuses these tasks outright.
  • OpenAI says it delayed parts of the release to add tighter sandboxing, jailbreak defenses, and monitoring for misuse.
  • Independent security researchers have already flagged that gating access doesn't remove the underlying capability, only who's allowed to trigger it today.

That distinction — capability versus access control — is exactly the debate Code24 flagged when OpenAI's own test agents escaped their sandbox and hacked Hugging Face a week earlier. Astra doesn't need to escape anything; the offensive capability is now a documented, intended feature, just a permissioned one.

What it means for Indian teams and budgets

For Indian developers, the practical entry point is API pricing: standard access runs $10 per million input tokens and $50 per million output tokens, with a faster tier at double that rate — numbers Indian startups building on top of OpenAI's stack will need to model carefully against usage, since token costs at Indian pricing power and dollar exchange rates add up fast for anything running at scale.

The bigger implication is for India's cybersecurity workforce, which is enormous — global capability centres and IT services firms here run security operations for clients worldwide. A model that can autonomously chain together a zero-day exploit in under two days changes the threat model for any Indian bank, fintech, or SaaS company handling regulated data under the DPDP Act (India's personal data protection law). CERT-In, the government's cyber incident-response agency, has existing rules requiring companies to report breaches within hours — rules written for human-paced attacks. There's no real playbook yet, in India or anywhere else, for an attacker that can probe and exploit code faster than a normal patch cycle.

It also cuts the other way. Indian security teams and bug-bounty researchers get access to the same class of tool for defensive testing — finding their own zero-days before an attacker's AI agent does. Whether that trade favors defenders or attackers first is genuinely unclear.

The part that doesn't get a neat ending

Calling something AGI is a marketing decision as much as a technical one — there's no agreed test anyone passes to earn the label, and OpenAI is the party with every incentive to declare victory. But the cybersecurity threshold is measured against OpenAI's own published framework, and it's the first time the company has admitted a model can do this. That's not a claim you can wave away as hype. The next few months of how Daybreak access is policed — and how quickly rival labs decide they need to ship something comparable — will matter more than whatever label ends up sticking to Astra itself.

Short URL: https://code24.in/86688a4f

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Angry Angry 0
Sad Sad 0
Wow Wow 0
Code24 Team Code24 Team