OpenAI Astra: 'Critical' cyber rating confirmed, release imminent, Daybreak Blue gating — what it means for agencies
Sept 4 update — Astra is live in the API and ChatGPT Work/Codex. OpenAI's developer account confirmed GPT-6 Astra is now available in the OpenAI API and in ChatGPT Work and Codex for all Pro, Enterprise, and Business Premium users; Enterprise admins enable Astra per workspace (off by default at launch), and Pro/Business/Enterprise plans include the Astra Pro tier. Plus and Business chat are the remaining rollout surfaces. The Critical-tier gating story below still stands: standard Astra refuses advanced cyber work, and Daybreak Blue access remains restricted. See the which OpenAI plan your agency should buy and the updated model comparison.
On September 1, 2026, OpenAI told reporters and the public what the August leak drama only hinted at: its next model, Astra, is the first AI model to reach the "Critical" cybersecurity capability threshold under the company's Preparedness Framework. That classification means Astra can discover previously unknown security flaws in real-world software and exploit them without a person guiding each step — a capability OpenAI previously said it "could not rule out" and has now confirmed it has measured.
For agency owners, this changes the planning question. It is no longer "when will OpenAI ship Astra?" — OpenAI says release is imminent. The live questions are: who gets the advanced cyber version (Daybreak Blue partners), who gets a restricted version (everyone else), and what does that access gap mean for your security engagements and client risk conversations?
What is OpenAI Astra?
Astra is OpenAI's next major model, first officially named on August 1, 2026 in a mathematics research post: "The results were achieved by an internal version of Astra, our next major model." OpenAI has since called Astra its upcoming model in an August 18 safety-pacing post, an August 28 decision about Cursor, and now the September 1 Path to Astra post.
As of September 1, 2026, Astra is confirmed but not shipped: OpenAI has announced the model's Critical cyber rating and imminent release, but there is still no model card, no pricing, and no listing in OpenAI's public model catalog.
Confirmed by OpenAI
- August 1 — Named "our next major model"; an internal version produced ten math results with Lean 4 certificates; the runs "would cost roughly $2,000 at Sol API rates."
- August 7 — Disclosed it could not rule out Astra meeting the "Critical" cybersecurity capability threshold under its Preparedness Framework. Non-compliant workloads were paused; testing moved to isolated environments with government agencies and selected AI-safety organizations.
- August 18 — Two-week reinforcement-learning (RL) pause on deployment-bound models; largest planned frontier RL run on hold; ~20% inference-compute monitoring overhead.
- August 28 — Restarted the large frontier RL run after new safety and security requirements were in place; notified SpaceX it will wind down the contract providing OpenAI models to Cursor, with Astra named as the upcoming model it will not provide under that contract.
- September 1 — Confirmed Astra is the first model to meet the Critical cyber capability threshold under the Preparedness Framework: "with the right tools and access, it can find previously unknown security flaws and develop ways to exploit them across many well-protected systems without a person guiding each step."
- September 1 — Said it plans to make Astra available "soon," but "access to its most advanced cybersecurity capabilities will be more limited" — initially a small group of testers, then Daybreak Blue partners for defensive use.
- September 1 — Released benchmark results: 100% on ExploitBench; on an internal 20-vulnerability V8 benchmark Astra achieved much higher arbitrary code-execution rates than GPT-5.6 Sol using far fewer output tokens, and discovered and used two zero-day vulnerabilities as part of an exploit chain (being disclosed to maintainers).
- September 1 — Reported Astra "outperforms industry leading AI models such as GPT-5.6 Sol and Anthropic's Mythos on cybersecurity benchmarks" (WIRED), and built a full browser-compromise chain that escaped a sandbox and executed commands on the host in expert-led assessments.
Not confirmed
- The codename mozaik-alpha-fdm — "OpenAI has not announced a release date or confirmed that 'mozaik-alpha-fdm' is an official codename."
- That the Aug 29–31 leaked outputs are actually Astra's — disputed on August 31 (Claude Opus 5 counter-claim).
- An exact release date — OpenAI says "soon," but has not published a date, a model card, or pricing; the Sept 3–10 window is still an unverified leak rumor.
- The "GPT-6" branding — OpenAI still hasn't confirmed whether Astra ships under that name.
Astra is the first model rated 'Critical' — what that means
OpenAI's Preparedness Framework (introduced 2023) classifies frontier models by cyber capability. Under the framework's update, a "High" threshold means a model can amplify "existing pathways" to severe harm; a "Critical" threshold means a model can introduce "unprecedented new pathways" to severe harm — for example, developing functional zero-day exploits in many hardened real-world systems without human intervention, or executing end-to-end novel attack strategies against hardened targets given only a high-level goal.
Astra is the first model OpenAI has designated at Critical. CNBC confirms the company said Astra "can find previously unknown security flaws and exploit them without step-by-step guidance from humans," placing it in the most advanced category of the Preparedness Framework. OpenAI said its multi-week pause was productive: after strengthening and testing protections, it believes Astra's safeguards "sufficiently minimize the risk of severe harm for release under our Preparedness Framework."
Critical = Astra can independently find and exploit previously unknown vulnerabilities in real-world software, and can chain multiple exploits together to move deeper into a target system. OpenAI's internal figures put Astra at 100% on ExploitBench and ahead of GPT-5.6 Sol and Anthropic's Mythos on cybersecurity benchmarks — capabilities broadly in line with what OpenAI and Anthropic have been forecasting for months (WIRED).
Notable test details from OpenAI's Sept 1 post:
- ExploitBench: 100% — perfect score on the benchmark evaluating ability to develop exploits from known vulnerabilities.
- Two zero-days found during evaluation — on an internal benchmark of 20 recently disclosed high-severity V8 vulnerabilities, Astra discovered and used two zero-day vulnerabilities as part of an exploit chain; OpenAI is disclosing them to the maintainers.
- Browser-compromise chain — against a hardened browser and OS, Astra built a full chain that escaped the sandbox and executed commands on the host.
- Local privilege escalation — it found multiple vulnerabilities in a hardened operating system and combined them into an unprivileged-user-to-root chain.
The Critical rating also comes with a caveat OpenAI flagged: results shown reflect capabilities with Daybreak Blue access, not the default production configuration. The model everyone else gets will be more restricted.
Release is imminent — but advanced cyber access is gated to Daybreak Blue
OpenAI's Sept 1 post is explicit about timing and access: "We plan to make Astra available soon, but access to its most advanced cybersecurity capabilities will be more limited. Advanced cybersecurity work will initially be available to a group of testers, with access through Daybreak Blue following to expand defensive use."
Daybreak Blue is OpenAI's early-access program for select partners in its Daybreak cybersecurity coalition — WIRED reports the partner list includes digital infrastructure providers like Cisco, Cloudflare, and Palo Alto Networks. At launch, those partners get a less-restricted version of Astra with more robust cyber capabilities, so they can harden defenses before similarly capable models are broadly available. OpenAI also said it has been working closely with government partners to ensure they are aware of Astra's cyber skills and can get access to them.
For everyone else, OpenAI is layering on safeguards: a new misalignment monitor that can slow, pause, or stop tasks it flags (including some legitimate ones — OpenAI warns the monitor may "occasionally flag legitimate activity as potential cyber misuse"), refusals of exploit requests, stronger jailbreak resistance, and chain-of-thought monitoring. OpenAI reports Astra refuses unsafe queries at a significantly higher rate than previous models (91.5% of cyber jailbreak requests vs 59% for GPT-5.6 Sol).
What Daybreak Blue access means for AI security agencies
For agencies doing offensive security, red-team, or AI-security work, the Sept 1 announcement turns model access into a positioning and risk question.
Partner vs non-partner positioning
- If your agency is (or becomes) a Daybreak Blue partner: you can run a less-restricted Astra with the model's full cyber capability for defensive engagements — a genuine differentiator for client work that needs frontier-grade vulnerability discovery and exploit chaining. OpenAI's stated intent is that partners get the model early to shore up defenses; that is a selling point for a security agency's pitch ("we hold OpenAI Daybreak Blue access").
- If your agency is not a partner: your Astra-based security work will run on the restricted default configuration — refusals, jailbreak resistance, and the misalignment monitor can interrupt legitimate defensive tasks (OpenAI explicitly warns the monitor may flag legitimate activity). You cannot truthfully sell "full Astra cyber capability" to clients until you have Daybreak Blue access.
- Expect the moat to widen. Access, not just model capability, is now the constraint. Non-partner agencies and their clients are behind on the capability curve by design — that is the point of the gating. Plan around the default config, or pursue partner status deliberately.
Client risk questions to ask now
- Does any vendor in our stack hold Daybreak Blue access? If a vendor uses Astra for security tooling, find out which configuration they run — partner-tier or default — and what monitoring/friction applies.
- What can Astra do against our attack surface? With Critical-rated capability, the risk calculus changes: previously unknown flaws can be found and chained without step-by-step human guidance. Clients need to know whether their systems were tested against that capability class.
- Who is accountable if the misalignment monitor interrupts legitimate work? OpenAI warns the monitor can slow, pause, or stop legitimate defensive activity. Contracts for AI-security engagements should define what happens when the model's own guardrail stops a deliverable.
- Is our client's sensitive infrastructure in scope for an Astra-based engagement? Government agencies and selected partners are getting access; the data-handling and compliance boundaries for Astra security work need to be explicit before you point a Critical-rated model at client systems.
- What happens if access is recalibrated? OpenAI says it plans to keep calibrating safeguards and expanding access through programs like Daybreak — meaning today's partner-tier access can change. Build model-swap and re-scope clauses into security SOWs.
The leak: what mozaik-alpha-fdm allegedly produced (history)
Between August 29 and 31, 2026, the first claimed outputs from OpenAI's unreleased model circulated on X and Discord under the checkpoint codename mozaik-alpha-fdm: a Grand Theft Auto 2-style game, complete websites, 3D objects, and voxel environments, reportedly generated in a single pass on "Max effort." The leak's authenticity is disputed — pseudonymous developer teortaxesTex claimed the samples were actually Claude Opus 5 output, and Kingy's fact-check found no media showed an OpenAI model selector, an Astra model ID, the original prompt, or a complete generation session. The Sept 1 confirmation of Astra's cyber capabilities does not authenticate the leaked demos; the demos remain unverified.
Is Astra the same as GPT-6?
Not officially. OpenAI still hasn't decided whether Astra ships as GPT-6, a GPT-5 point release (like GPT-5.7), or a separate tier alongside Sol, Terra, and Luna. "GPT-6" dominates headlines because it is the public's shorthand — but OpenAI has never used the name.
When is GPT-6 / Astra coming?
OpenAI said on September 1, 2026 that it plans to make Astra available "soon." No specific release date, model card, or pricing has been published; the Sept 3–10 window circulating online remains an unverified leak rumor. Release is imminent; advanced cyber capabilities are gated to Daybreak Blue partners at launch.
The Sept 3–10 window still traces to X posts and aggregators, not OpenAI — Kingy's tracker calls it "still a rumor." What changed on Sept 1 is that OpenAI itself confirmed release is imminent, so the planning question is no longer if but when and to whom. A federal voluntary 30-day pre-release review framework took effect on August 1, and Astra is expected to be the first model through it.
Why OpenAI paused parts of Astra
Astra is the first OpenAI model to cross the Critical cyber capability threshold — the top of the Preparedness Framework ladder. On August 7, OpenAI said internal evaluations showed "significant advancements in agentic coding and cybersecurity," and it could not rule out critical cyber capabilities. Non-compliant work was paused; the model moved to isolated, sandboxed environments; and OpenAI confirmed "relevant government agencies and selected AI safety organizations will participate in testing."
On August 18, OpenAI published Pacing model development in an era of cyber-critical capabilities: a two-week pause in RL training on deployment-bound models, its largest planned frontier RL run on hold, and an extra monitoring requirement on all Astra inference with tools. On August 28, OpenAI restarted the large frontier RL run after the new safety and security requirements were in place (some smaller experimental runs remain held). See OpenAI paused Astra training in August.
For agencies, the takeaway is now access risk rather than delay risk: the model is coming, but which configuration your engagements can use — and whether the guardrail monitor interrupts legitimate work — is the new uncertainty.
Astra and the Cursor breakup
On August 14, 2026, Cursor (Anysphere) announced it had officially become part of SpaceX after a reported $60 billion acquisition. On August 28, OpenAI notified SpaceX that it intends to wind down the contract providing OpenAI models to Cursor, with a proposed shutoff date of November 12, 2026. OpenAI's rationale: "we cannot be confident that SpaceX will use our technology within our terms of service, based on our experience with Elon Musk's companies violating contracts." Astra is explicit: no future OpenAI models — Astra included — will be provided under the contract.
Practical effects: current OpenAI models continue through the proposed transition, but if you standardized on Cursor's OpenAI integration, you now have a hard date to re-plan your model stack — see the OpenAI–Cursor split and what still works.
Is Astra better than Claude or Gemini?
On cybersecurity benchmarks, OpenAI reports Astra is ahead: 100% on ExploitBench, and outperforming GPT-5.6 Sol and Anthropic's Mythos (WIRED). But there are still no independent public head-to-head results and no model card — the Sept 1 figures are OpenAI's own. For general agency work, compare shipped models directly: GPT-5.6 Sol, Claude Fable 5.1/Opus 5, and Gemini 3.x (Claude API pricing 2026 breakdown).
The September 1 announcement gives the first real benchmark signal — but it is narrow (cybersecurity) and self-reported. OpenAI notes Astra's cyber capabilities "are broadly in line with the rising hacking abilities of AI models that OpenAI and Anthropic have been forecasting for months"; Anthropic flagged similar concerns about its Mythos model earlier this year. For decisions today, compare shipped models by price and capability on our best AI coding agent pricing hub, and read OpenAI vs Anthropic for enterprise work.
Not to be confused with Google's Project Astra
"Astra" is overloaded. OpenAI Astra is OpenAI's upcoming model family, now rated Critical for cyber capability. Google's Project Astra is a DeepMind multimodal assistant prototype — "a universal assistant that sees, hears, remembers, and acts across devices and Google products" — and the two are "unrelated projects" that "happen to share a name." Add Astral (a Python tooling company) and Astra Platform (a Google Cloud product): four different products inside one keyword. Before trusting a claim about "Astra" coding, pricing, or availability, check which product the source means.
What Astra means for agency workflows
Security and red-team work. The Critical rating reframes Astra from "coding model" to "frontier cyber tool." Agencies that can access the Daybreak Blue configuration get capability for vulnerability discovery and exploit chaining that general users won't have at launch; non-partner agencies should expect restricted behavior and monitoring on security-adjacent prompts.
Coding and agent work. OpenAI's internal evaluations still show "significant advancements in agentic coding and cybersecurity." If a shipped Astra delivers long-horizon, tool-using generation at that level, the agency differentiator shifts from "we prompt well" to "we supervise agents that build" — start the staffing and pricing conversation now.
One-shot generation (unverified). The leak claims a full website or a playable game in a single pass on Max effort. If real, that compresses scoping-to-prototype timelines dramatically — but provenance is disputed, so don't re-plan delivery on it yet.
Cost planning. Max effort "spends substantially longer reasoning than GPT-5.6 Sol," which risks pushing per-call cost up — and there is no Astra pricing to model against yet. The Astra cost outlook covers what is confirmed and how to scenario-plan; the Cursor cut's cost impact is in what the Cursor cut means for your model stack costs.
Model mix. If Astra ships and stays barred from Cursor, expect pressure to consolidate around OpenAI's own surfaces (ChatGPT, Codex) or rebalance toward Claude and Gemini in the IDE. Keep client contracts flexible: model-swap and token-burn clauses protect you when the frontier shifts mid-engagement.
How much will Astra cost?
No official OpenAI Astra pricing exists. The $2,000 figure widely repeated is a token-cost estimate for the August 1 research runs at GPT-5.6 Sol API rates — not a price for the model. Expect a model card/pricing page only when OpenAI ships it; until then any "Astra API pricing" is a reseller claim.
The only official cost figure is the August 1 counterfactual: the math runs "would cost roughly $2,000 at Sol API rates." That describes research runs, not a product price — and the Sept 1 announcement added no pricing. If Astra ships with a Max-effort mode that reasons longer, per-call cost could rise even in a price-cutting market. Our Astra cost outlook keeps placeholder tables and scenarios updated as OpenAI publishes real numbers.
FAQ
When is OpenAI Astra coming out?
OpenAI said on Sept 1, 2026 that it plans to make Astra available "soon." No specific release date, model card, or pricing has been published; the Sept 3-10 window circulating online remains an unverified rumor.
What is Astra's Critical rating under OpenAI's Preparedness Framework?
Astra is the first OpenAI model to reach the Critical cybersecurity capability threshold. OpenAI confirmed Sept 1 that it can find previously unknown security flaws and exploit them across many well-protected systems without step-by-step human guidance.
What is Daybreak Blue early access?
Daybreak Blue is OpenAI's early-access program for select partners (e.g., Cisco, Cloudflare, Palo Alto Networks) that get a less-restricted version of Astra with more robust cyber capabilities at launch. A small tester group gets access first; Daybreak Blue expands defensive use afterward.
Can I use OpenAI Astra for cybersecurity work?
Yes, but gated. OpenAI plans to release Astra soon, but its most advanced cyber capabilities are limited to approved testers and Daybreak Blue partners at launch; general users get a more restricted configuration.
What is OpenAI Astra?
OpenAI's next major model, first officially named August 1, 2026. On Sept 1 OpenAI confirmed Astra reaches the Critical cyber capability threshold and said release is imminent; no model card or pricing yet.
Is Astra the same as GPT-6?
Not officially. OpenAI hasn't said whether it ships as GPT-6, a GPT-5.x point release, or a separate tier; "GPT-6" is shorthand, not a confirmed name.
Why was Astra paused?
Aug 7: OpenAI couldn't rule out Critical cyber capability and paused non-compliant workloads. Aug 18: two-week RL pause. Aug 28: large frontier RL run restarted after new safety requirements. Sept 1: OpenAI confirmed the Critical rating and said Astra's safeguards sufficiently minimize risk for release.
Is Astra better than Claude or Gemini?
On OpenAI's ExploitBench, Astra scored 100% and OpenAI says it outperforms GPT-5.6 Sol and Anthropic's Mythos on cybersecurity benchmarks. There are still no independent public head-to-head results or a model card.
Will Astra be available in Cursor?
No. OpenAI is winding down Cursor model access (proposed November 12, 2026) and will not provide future models — explicitly including Astra — under that contract.
How much will Astra cost?
No official pricing. The $2,000 figure is a research-run token estimate at Sol rates, not a price for the model. See the Astra cost outlook.
Is OpenAI Astra the same as Google's Project Astra?
No. OpenAI's is an upcoming model family; Google's is a DeepMind assistant prototype.
Plan Astra costs and access before OpenAI ships pricing.
Open the Astra cost outlook →Compare AI coding agent pricing →
Sources & update note
Sept 1 update. This post was originally published August 31 as a leak story. On September 1, 2026, OpenAI confirmed Astra's Critical cyber capability rating, imminent release, and Daybreak Blue access gating; the post was refreshed to lead with the confirmed facts while retaining the leak history. Old statements saying release was delayed or that Critical was only "possible" have been removed or corrected. This post will be refreshed again when OpenAI publishes an exact release date, model card, pricing, or the Daybreak Blue partner list changes.
Last updated: September 1, 2026 (EDT).
- OpenAI: Path to Astra — critical capabilities and frontier safeguards (Sept 1, 2026)
- OpenAI on X: Astra announcement — "Astra represents a significant advance in cybersecurity capability, reaching the Critical threshold under our Preparedness Framework" (Sept 1, 2026)
- WIRED: OpenAI Is About to Release Its First AI Model With 'Critical' Cyber Abilities (Sept 1, 2026)
- CNBC: OpenAI says Astra AI model is its first that crosses 'Critical' cybersecurity capability (Sept 1, 2026)
- TechCrunch: OpenAI's Astra model is on the way — and very good at breaking into computer systems (Sept 1, 2026)
- Bloomberg: OpenAI to Restrict Access to Astra AI Model's Advanced Cybersecurity Features (Sept 1, 2026)
- OpenAI: Responding to the next frontier of critical cyber capabilities (Aug 7, 2026)
- OpenAI: Pacing model development in an era of cyber-critical capabilities (Aug 18, 2026)
- OpenAI: Our decision on Cursor following its acquisition by SpaceX (Aug 28, 2026)
- OpenAI: Ten advances in mathematics and theoretical computer science (Aug 1, 2026)
- OrcaRouter: OpenAI Astra - Everything We Know About the Model That Isn't GPT-6 (living post through Aug 31)
- Kingy AI: OpenAI Astra Rumor Tracker (Aug 29; updated Aug 31)
- TestingCatalog: First outputs from GPT-6 Astra model from OpenAI (Aug 29, 2026)
- CNBC: OpenAI to end model access to Cursor after acquisition by SpaceX (Aug 29)
- MacRumors: OpenAI Delays Next Major AI Model Astra Over Critical Hacking Concerns (Aug 7)
Accuracy note: Sept 1 facts (Critical rating, release timing, Daybreak Blue gating, ExploitBench 100%, zero-day chain, browser-compromise chain, 91.5% jailbreak refusal) come from OpenAI's own Path to Astra post, corroborated by WIRED, CNBC, TechCrunch, and Bloomberg (Bloomberg headline/lede verified via snippet; article is paywalled). Leak history (mozaik-alpha-fdm, Aug 29–31 demos) remains attributed and unverified per the original post's fact-check. Refresh triggers: exact release date, model card, pricing, Daybreak Blue partner list changes, or Cursor cutoff (Nov 12).