On September 3, 2026, OpenAI unveiled GPT-6 Astra, leaning on the Latin root of its name: astra, the stars, arranged in a visual spelling out "A6TRA." The same day, its technical documentation rated this model "Critical" for offensive cybersecurity capability — a first for a broadly deployed model. The coincidence is worth pausing on, especially if your SME already connects AI agents to its systems.
Three things matter here: what the launch actually changes, what this critical cybersecurity threshold means, and the governance reflexes to adopt before opening access to this kind of model.
What OpenAI Actually Launched on September 3, 2026
GPT-6 Astra joins the Sol, Terra and Luna families. The rollout is staged: restricted access to partner organizations first, then a wider opening to ChatGPT Plus, Pro, Business and Enterprise subscriptions, the API and AWS "in the coming days." The model was therefore not fully available at launch.
OpenAI highlights high scores on its own offensive benchmarks: 100% on ExploitBench, 42.4% on ExploitGym, 88% on SRE-Bench (reverse engineering). These figures, reported by the vendor itself and not independently audited, deserve to be read with that caveat in mind. Another useful nuance: on general capability indices, Claude Fable 5.1 still leads according to OpenAI's own comparison chart. This launch is not a clean sweep. On pricing, GPT-6 Astra costs roughly 2.5 times more than the prior flagship's promotional rate, at $10 per million input tokens and $50 per million output tokens.
The Critical Cybersecurity Threshold: What OpenAI's Own Preparedness Framework Admits
The Preparedness Framework is the internal system OpenAI uses to evaluate, before each deployment, how much harm a model's most sensitive capabilities could cause. GPT-6 Astra is the first broadly deployed model rated "Critical" there for offensive cybersecurity: it can identify and develop zero-day exploits in hardened systems without a human guiding every step. Two previously unknown zero-day vulnerabilities were in fact discovered during pre-release testing.
Production safeguards, however, make a real difference: under protection, OpenAI reports that GPT-6 Astra exceeded the authorized boundary in only 0% of ExploitGym honeypot tests, versus 48.2% for GPT-5.6 Sol. That's the same gap — between raw capability and effective safeguards — we detailed in August around an incident at OpenAI and Hugging Face: the risk never comes from the model's intelligence alone, but from how its access is framed.
AI Governance in Industrial SMEs: What GPT-6 Astra's Critical Threshold Changes
A model rated Critical changes nothing about your exposure as long as you don't grant it access. That's where AI governance plays out in an industrial SME: two reflexes are enough to take back control.
Access and provisioning. Every AI agent credential or API key should be treated as privileged access: activation on explicit authorization, never by default, with periodic review of who has access and why, and access control enforced at the credential level. On a site where IT meets OT, a poorly scoped credential no longer just exposes an office workstation — it can open a door to a PLC or a process control system.
Human review and logging. Control requirements should rise with a model's capability, not stay fixed. Never assume vendor safeguards alone are enough: log AI agent actions and keep human review on sensitive operations, the same way you would for any external provider with broad access.
In practice, before opening access to a model in this category:
- Map who in the company would have access to a connected AI agent, and to which systems
- Set a simple rule: no agentic access by default, only on justified and tracked request
Governing Access Before Adopting GPT-6 Astra
GPT-6 Astra is the most capable product OpenAI has ever broadly deployed. It's also, in the company's own documentation, an admission that this capability has crossed a critical cybersecurity threshold requiring extra precautions. For an industrial SME, the right response isn't to wait for the benchmarks to settle, but to govern access under an explicit AI governance framework before adopting this kind of tool, not after.
To frame your teams' access to the latest AI agents, discover our tailored AI solutions for industrial SMEs or contact us for an initial conversation about your AI governance.




