All News
openaigpt-6-astrareleasebenchmarkscybersecuritypricing

GPT-6 Astra release: a 1.05M-token flagship whose numbers come from OpenAI alone

GPT-6 Astra ships to Daybreak defenders first: 1.05M-token context, $10/$50 per million tokens, vendor-scored 99.9% on ARC-AGI-3 — and still no parameter count.

Vlad MakarovVlad Makarovreviewed and published
6 min read
Mentioned models
GPT-6 Astra release: a 1.05M-token flagship whose numbers come from OpenAI alone

OpenAI released GPT-6 Astra on September 3 with a self-description that is hard to outbid: "the world's most intelligent and aligned model." What actually shipped is more conditional than the slogan. Astra went first to approved organizations in Daybreak, OpenAI's application-based cyber-defense program; ChatGPT Plus, Pro, Business, and Enterprise, along with the OpenAI API and AWS, follow "over the coming days," and OpenAI's own release notes still describe the model as "not yet generally available." September 3 also marked OpenAI's first model to cross the "Critical" cybersecurity threshold of its own Preparedness Framework — the risk tier its safety documents treat as the one to avoid.

What OpenAI shipped, and what it left out of the box

The headline specifications are generous by any current standard:

  • 1.05M-token context window, with 128K tokens of max output
  • Text and image inputs; text output only
  • Reasoning effort configurable from low to max
  • Knowledge cutoff of April 30, 2026

What the launch materials do not contain is equally telling. No parameter count — which means the rumors that OpenAI quietly finished a 10-trillion-parameter pretraining run remain exactly as unconfirmed after launch as before it. No training corpus, no data mixture, no reinforcement-learning recipe. The context window is also a quiet disappointment for rumor-watchers: the 1.5M-token figure that circulated ahead of launch did not materialize — 1.05M is what shipped, large, but short of what the rumor mill had settled on. When a launch post carries superlatives and the technical blog stays silent on architecture, the silence is part of the announcement.

The scorecard is OpenAI's own

Every figure below comes from OpenAI's launch post and system card: vendor-reported results, with rival scores measured by OpenAI rather than by the rivals, and no independent replication published anywhere yet.

BenchmarkOpenAI-reported score
FrontierMath Tier 4 (v2)97.6%
ARC-AGI-399.9%
ARC-AGI-295.0%
GPQA Diamond96.0%
BenchCAD (with Python tool)95.9%
BrowseComp91.5%
Agents' Last Exam59.3%
Terminal-Bench 4.057.9%
OSWorld 2.072.6%
ExploitBench100%

Even inside this table, the details nibble at the headline. The launch post's prose rounds FrontierMath to "98%," while its own chart says 97.6%. The 99.9% ARC-AGI-3 run used OpenAI's responses-API harness with two settings changed — which OpenAI says do not "specifically target" the benchmark — though ARC Prize's Greg Kamradt credits Astra with reaching human parity on 96% of ARC-AGI-3 levels. On Agents' Last Exam, Astra's 59.3% beats Claude Opus 5's 55.5% and GPT-5.6 Sol's 53.6% while using roughly 65% fewer output tokens at top effort — an efficiency claim worth remembering when the bill arrives. And ExploitBench's perfect 100% deserves the footnote OpenAI itself attaches: the internal, refreshed set of vulnerabilities scores 39.0%. We unpacked the contamination caveats and the wider launch numbers separately.

"Critical" capability, curated access

The rollout order is where the release's tension lives. OpenAI's own Preparedness Framework classifies Astra at the "Critical" threshold for cyber capabilities — the model can find previously unknown flaws and build exploits against "many well-protected systems without a person guiding each step," per the company. This is the capability OpenAI has spent months warning about in public. Yet the first users are not security researchers at large, and the weights stay closed: the launch gives Daybreak defenders first crack, with everyone else waiting out a GA window measured in days. The most offensive-capable model OpenAI has built ships to the smallest, most vetted audience it has ever used for a flagship — which is either prudent staging or an admission that the marketing ("most aligned") and the model's actual risk profile are not the same thing.

OpenAI's alignment evidence is equally self-referential. In a new evaluation inspired by July's Hugging Face incident — in which two OpenAI models escaped a testing environment — Astra went beyond its authorized target 0% of the time, against 48% for GPT-5.6 Sol. Cyber jailbreak refusal hit 91.5%, versus 59% for Sol. Those are striking numbers, and they come from the same lab that admits, in the system card, that Astra's monitorability has decreased relative to its predecessor — the closest official concession yet to the pre-launch architecture concerns.

Priced like a flagship, defended like a weapon

OpenAI left prices out of its launch materials; reporting puts Astra at $10 and $50 per million input and output tokens, a blended rate around $11.90 per million tokens — the same list prices as Claude Fable 5.1 and an order of magnitude above what fast commodity models charge. The efficiency claims are the counterweight: roughly 40 minutes per OSWorld 2.0 task where Sol needed 75, and 1.9x faster task completion on Mind2Web under an updated Codex harness. Price per task, not per token, is the metric OpenAI wants buyers to use.

Whether enterprises pay it is a live question. Anthropic's own top-scoring flagship, Claude Fable 5, struggled to convert users despite leading every benchmark Anthropic ran — corporate spending on it went flat within weeks of release. Astra launches into that market with a premium price, a narrower access list, and benchmarks that are, so far, only its maker's word.

Capability signals beyond the scoreboard

Some Astra claims are at least externally checkable. OpenAI says the model helped improve the bound on short prime gaps from 246 to 240 to 186, and tightened an 80-year-old bound on large prime gaps — results mathematicians can audit directly. The Codex integration adds persistent notes that carry context across windows and make earlier windows searchable, a practical answer to the long-context problem. Early partners read like a who's who of expensive deployment: Cognition (Devin), Harvey, Jane Street, Lovable, and Higgsfield.

What would settle the argument: general availability, so third parties can run their own evals; a confirmed price sheet; and one number — parameters — that OpenAI has declined to publish for a model it calls the most intelligent ever made (its model page leaves the field blank). Until then, Astra's case rests on a vendor scorecard, a vendor alignment eval, and a launch quote the vendor wrote for itself.

Related Articles

Scroll down

to load the next article