OpenAI Astra is live: Sept 3 launch, $10/$50 pricing, Critical-tier cyber gating
On September 3, 2026, OpenAI released GPT-6 Astra — the model it had spent August describing as its "next major model", and the first OpenAI model rated "Critical" for cybersecurity capability under its Preparedness Framework. It is live now: the API model ID is gpt-6-astra, the context window is 1,050,000 tokens, and Standard pricing is $10 per 1M input / $50 per 1M output (OpenAI's model card and pricing page, both verified September 14, 2026).
For agency owners, the planning question has moved from when to which tier, at what price, and with what gating. Three things decide that: the 272K repricing rule — prompts over 272K input tokens reprice the entire request at $20 input / $75 output per 1M; who gets the advanced cyber configuration, which is still Daybreak Blue partners rather than general users; and which surface your client can actually reach, since Astra is off by default for Enterprise workspaces until an admin enables it.
What is OpenAI Astra?
GPT-6 Astra is OpenAI's flagship frontier model, released September 3, 2026. It was first named on August 1, 2026 in a mathematics research post ("The results were achieved by an internal version of Astra, our next major model"), then referenced in OpenAI's August 18 safety-pacing post, its August 28 Cursor decision, and the September 1 Path to Astra post. The "GPT-6" branding question was settled at launch: the model card, the API id and the ChatGPT surfaces all carry it.
The launch facts come from OpenAI's own model card: model ID gpt-6-astra, a 1,050,000-token context window, 922,000-token maximum input, 128,000-token maximum output, April 30, 2026 knowledge cutoff, reasoning token support with reasoning.effort from low through max, and text plus image input with text output. It is supported on the Responses, Chat Completions and Batch endpoints; Realtime, Live, Assistants, fine-tuning, embeddings, images and the audio endpoints are not supported.
Confirmed by OpenAI
- August 1 — Named "our next major model"; an internal version produced ten math results with Lean 4 certificates; the runs "would cost roughly $2,000 at Sol API rates."
- August 7 — Disclosed it could not rule out Astra meeting the "Critical" cybersecurity capability threshold under its Preparedness Framework. Non-compliant workloads were paused; testing moved to isolated environments with government agencies and selected AI-safety organizations.
- August 18 — Two-week reinforcement-learning (RL) pause on deployment-bound models; largest planned frontier RL run on hold; ~20% inference-compute monitoring overhead.
- August 28 — Restarted the large frontier RL run after new safety and security requirements were in place; notified SpaceX it will wind down the contract providing OpenAI models to Cursor, with Astra named as the upcoming model it will not provide under that contract.
- September 1 — Confirmed Astra is the first model to meet the Critical cyber capability threshold under the Preparedness Framework: "with the right tools and access, it can find previously unknown security flaws and develop ways to exploit them across many well-protected systems without a person guiding each step."
- September 1 — Said it plans to make Astra available "soon," but "access to its most advanced cybersecurity capabilities will be more limited" — initially a small group of testers, then Daybreak Blue partners for defensive use.
- September 1 — Released benchmark results: 100% on ExploitBench; on an internal 20-vulnerability V8 benchmark Astra achieved much higher arbitrary code-execution rates than GPT-5.6 Sol using far fewer output tokens, and discovered and used two zero-day vulnerabilities as part of an exploit chain (being disclosed to maintainers).
- September 1 — Reported Astra "outperforms industry leading AI models such as GPT-5.6 Sol and Anthropic's Mythos on cybersecurity benchmarks" (WIRED), and built a full browser-compromise chain that escaped a sandbox and executed commands on the host in expert-led assessments.
- September 3, 2026 — Released GPT-6 Astra (model ID
gpt-6-astra) with a published model card and pricing; live in the OpenAI API and in ChatGPT Work and Codex from September 4.
Resolved at launch
- Release date — September 3, 2026. The Sept 3–10 window that circulated before launch is history, not a pending question.
- Model card — published: the GPT-6 Astra model card on OpenAI's developer docs, with
gpt-6-astraas both the model id and the default snapshot. - Pricing — published: $10.00 input / $1.00 cached input / $12.50 cache writes / $50.00 output per 1M tokens on the Standard tier (≤272K input).
- Catalog listing —
gpt-6-astraappears in OpenAI's public model documentation and in its Standard, Batch, Flex and Fast pricing tables. - The "GPT-6" branding — confirmed. It ships as GPT-6 Astra, not as a separate codename tier.
- The Sept 3–10 leak window — resolved and superseded by the September 3 launch.
Still open
- Cursor cutoff (November 12, 2026) — OpenAI's August 28 wind-down of Cursor's model access stands, and Astra remains outside that contract. What still works after the split.
- Claude Opus 5 counter-claim — the claim that the Aug 29–31 leaked outputs were Opus 5 output rather than Astra was never officially resolved. It is moot post-launch and is recorded here for the record only.
- Daybreak Blue partner list — no new official list has been published, so the September 1 framing stands. What early-access partner status means for an agency.
What actually shipped on September 3, 2026
OpenAI's model card is the first-party source for all of this, re-read on September 14, 2026:
- Context and limits. A 1,050,000-token context window, 922,000-token maximum input and 128,000-token maximum output.
- Reasoning effort ladder.
reasoning.effortsupportslow,medium,high,xhighandmax; reasoning tokens bill at output rates, so a max-effort run can cost far more than the visible answer suggests. - Tools (Responses API). Web search, file search, image generation, code interpreter, hosted shell, apply patch, skills, computer use, MCP and tool search — the computer-use and hosted-shell tools are the ones that make Astra interesting for agency delivery work.
- Not supported. Audio and video, fine-tuning, embeddings, image generation as an endpoint, speech, transcription and translation endpoints; no Free-tier access. API rate limits run from Tier 1 (500 RPM / 500K TPM) to Tier 5 (15,000 RPM / 40M TPM).
Where you can use it. The API (gpt-6-astra) plus ChatGPT Work and Codex for Pro, Enterprise and Business Premium users, with ChatGPT Plus and Business chat as the remaining rollout surfaces. Astra Pro — the higher Work/Codex tier — is available on Pro, Business and Enterprise plans and is off by default for Enterprise admins until they enable it. On September 10, 2026 OpenAI temporarily paused new $200/month Pro subscription signups, citing Astra demand and infrastructure strain (TechCrunch, The Verge).
Not Astra: the September 8 Navier–Stokes result
On September 8, 2026 OpenAI published Navier–Stokes results produced by an internal system it describes as "significantly more capable than GPT-6 Astra" — roughly 10,000 coordinated agents over 88 hours, with about 17 hours to formalize and verify the result in Lean with GPT-6 Astra. That internal system is not gpt-6-astra. Do not attribute the Navier–Stokes result to Astra, and do not read it as evidence of Astra's own capability.
Astra is the first model rated 'Critical' — what that means
OpenAI's Preparedness Framework (introduced 2023) classifies frontier models by cyber capability. Under the framework's update, a "High" threshold means a model can amplify "existing pathways" to severe harm; a "Critical" threshold means a model can introduce "unprecedented new pathways" to severe harm — for example, developing functional zero-day exploits in many hardened real-world systems without human intervention, or executing end-to-end novel attack strategies against hardened targets given only a high-level goal.
Astra is the first model OpenAI has designated at Critical. CNBC confirms the company said Astra "can find previously unknown security flaws and exploit them without step-by-step guidance from humans," placing it in the most advanced category of the Preparedness Framework. OpenAI said its multi-week pause was productive: after strengthening and testing protections, it believes Astra's safeguards "sufficiently minimize the risk of severe harm for release under our Preparedness Framework."
Critical = Astra can independently find and exploit previously unknown vulnerabilities in real-world software, and can chain multiple exploits together to move deeper into a target system. OpenAI's internal figures put Astra at 100% on ExploitBench and ahead of GPT-5.6 Sol and Anthropic's Mythos on cybersecurity benchmarks — capabilities broadly in line with what OpenAI and Anthropic have been forecasting for months (WIRED).
Notable test details from OpenAI's Sept 1 post:
- ExploitBench: 100% — perfect score on the benchmark evaluating ability to develop exploits from known vulnerabilities.
- Two zero-days found during evaluation — on an internal benchmark of 20 recently disclosed high-severity V8 vulnerabilities, Astra discovered and used two zero-day vulnerabilities as part of an exploit chain; OpenAI is disclosing them to the maintainers.
- Browser-compromise chain — against a hardened browser and OS, Astra built a full chain that escaped the sandbox and executed commands on the host.
- Local privilege escalation — it found multiple vulnerabilities in a hardened operating system and combined them into an unprivileged-user-to-root chain.
The Critical rating also comes with a caveat OpenAI flagged: results shown reflect capabilities with Daybreak Blue access, not the default production configuration. The model everyone else gets will be more restricted.
Advanced cyber access is still gated to Daybreak Blue
OpenAI's Sept 1 language — "We plan to make Astra available soon, but access to its most advanced cybersecurity capabilities will be more limited. Advanced cybersecurity work will initially be available to a group of testers, with access through Daybreak Blue following to expand defensive use." — is now launch fact rather than a promise. The model shipped on September 3; the access ladder it described did not change with it.
Daybreak Blue is OpenAI's early-access program for select partners in its Daybreak cybersecurity coalition — WIRED reports the partner list includes digital infrastructure providers like Cisco, Cloudflare, and Palo Alto Networks. Partners get a less-restricted version of Astra with more robust cyber capabilities, so they can harden defenses before similarly capable models are broadly available. OpenAI also said it has been working closely with government partners to ensure they are aware of Astra's cyber skills and can get access to them.
For everyone else, OpenAI is layering on safeguards: a new misalignment monitor that can slow, pause, or stop tasks it flags (including some legitimate ones — OpenAI warns the monitor may "occasionally flag legitimate activity as potential cyber misuse"), refusals of exploit requests, stronger jailbreak resistance, and chain-of-thought monitoring. OpenAI reports Astra refuses unsafe queries at a significantly higher rate than previous models (91.5% of cyber jailbreak requests vs 59% for GPT-5.6 Sol).
What Daybreak Blue access means for AI security agencies
For agencies doing offensive security, red-team, or AI-security work, the Sept 1 announcement turns model access into a positioning and risk question.
Partner vs non-partner positioning
- If your agency is (or becomes) a Daybreak Blue partner: you can run a less-restricted Astra with the model's full cyber capability for defensive engagements — a genuine differentiator for client work that needs frontier-grade vulnerability discovery and exploit chaining. OpenAI's stated intent is that partners get the model early to shore up defenses; that is a selling point for a security agency's pitch ("we hold OpenAI Daybreak Blue access").
- If your agency is not a partner: your Astra-based security work will run on the restricted default configuration — refusals, jailbreak resistance, and the misalignment monitor can interrupt legitimate defensive tasks (OpenAI explicitly warns the monitor may flag legitimate activity). You cannot truthfully sell "full Astra cyber capability" to clients until you have Daybreak Blue access.
- Expect the moat to widen. Access, not just model capability, is now the constraint. Non-partner agencies and their clients are behind on the capability curve by design — that is the point of the gating. Plan around the default config, or pursue partner status deliberately.
Client risk questions to ask now
- Does any vendor in our stack hold Daybreak Blue access? If a vendor uses Astra for security tooling, find out which configuration they run — partner-tier or default — and what monitoring/friction applies.
- What can Astra do against our attack surface? With Critical-rated capability, the risk calculus changes: previously unknown flaws can be found and chained without step-by-step human guidance. Clients need to know whether their systems were tested against that capability class.
- Who is accountable if the misalignment monitor interrupts legitimate work? OpenAI warns the monitor can slow, pause, or stop legitimate defensive activity. Contracts for AI-security engagements should define what happens when the model's own guardrail stops a deliverable.
- Is our client's sensitive infrastructure in scope for an Astra-based engagement? Government agencies and selected partners are getting access; the data-handling and compliance boundaries for Astra security work need to be explicit before you point a Critical-rated model at client systems.
- What happens if access is recalibrated? OpenAI says it plans to keep calibrating safeguards and expanding access through programs like Daybreak — meaning today's partner-tier access can change. Build model-swap and re-scope clauses into security SOWs.
Leak history (Aug 29–31, 2026) — superseded
Between August 29 and 31, 2026, the first claimed outputs from OpenAI's unreleased model circulated on X and Discord under the checkpoint codename mozaik-alpha-fdm: a Grand Theft Auto 2-style game, complete websites, 3D objects, and voxel environments, reportedly generated in a single pass on "Max effort." The leak's authenticity is disputed — pseudonymous developer teortaxesTex claimed the samples were actually Claude Opus 5 output, and Kingy's fact-check found no media showed an OpenAI model selector, an Astra model ID, the original prompt, or a complete generation session. The Sept 1 confirmation of Astra's cyber capabilities does not authenticate the leaked demos; the demos remain unverified. This section is superseded: GPT-6 Astra shipped on September 3, 2026, and the leak window it belonged to is closed.
Is Astra the same as GPT-6?
Yes. The naming question was settled at launch: OpenAI ships the model as GPT-6 Astra, and the GPT-6 name appears in the API model id (gpt-6-astra), the model card and the ChatGPT surfaces. Before September 3 it was genuinely open — GPT-6, a GPT-5.x point release, or a separate tier alongside Sol, Terra and Luna were all live possibilities.
When did GPT-6 Astra launch?
Launched September 3, 2026 and live in the OpenAI API from September 4, with a 1,050,000-token context window at $10 per 1M input / $50 per 1M output (Standard). The Sept 3–10 window that circulated before launch was a leak rumor; the launch superseded it. Advanced cyber capabilities remain gated to approved testers and Daybreak Blue partners.
The open question of "soon" closed on September 3. What remains is access, not timing: Daybreak Blue for advanced cyber work, Enterprise admin enablement for workspace access, and the November 12 Cursor cutoff for anyone standardised on Cursor's OpenAI integration.
Why OpenAI paused parts of Astra
Astra is the first OpenAI model to cross the Critical cyber capability threshold — the top of the Preparedness Framework ladder. On August 7, OpenAI said internal evaluations showed "significant advancements in agentic coding and cybersecurity," and it could not rule out critical cyber capabilities. Non-compliant work was paused; the model moved to isolated, sandboxed environments; and OpenAI confirmed "relevant government agencies and selected AI safety organizations will participate in testing."
On August 18, OpenAI published Pacing model development in an era of cyber-critical capabilities: a two-week pause in RL training on deployment-bound models, its largest planned frontier RL run on hold, and an extra monitoring requirement on all Astra inference with tools. On August 28, OpenAI restarted the large frontier RL run after the new safety and security requirements were in place (some smaller experimental runs remain held). See OpenAI paused Astra training in August.
For agencies, the takeaway is now access risk rather than delay risk: the model has shipped, but which configuration your engagements can use — and whether the guardrail monitor interrupts legitimate work — is the remaining uncertainty.
Astra and the Cursor breakup
On August 14, 2026, Cursor (Anysphere) announced it had officially become part of SpaceX after a reported $60 billion acquisition. On August 28, OpenAI notified SpaceX that it intends to wind down the contract providing OpenAI models to Cursor, with a proposed shutoff date of November 12, 2026. OpenAI's rationale: "we cannot be confident that SpaceX will use our technology within our terms of service, based on our experience with Elon Musk's companies violating contracts." Astra is explicit: no future OpenAI models — Astra included — will be provided under the contract.
Practical effects: current OpenAI models continue through the proposed transition, but if you standardized on Cursor's OpenAI integration, you now have a hard date to re-plan your model stack — see the OpenAI–Cursor split and what still works.
Is Astra better than Claude or Gemini?
On cybersecurity benchmarks OpenAI reports Astra is ahead: 100% on ExploitBench, and outperforming GPT-5.6 Sol and Anthropic's Mythos (WIRED). Treat those as vendor-reported: OpenAI's launch page publishes its own comparison table (nine categories, roughly 40 benchmarks, six models), which is not an independent tournament. The "AGI era" 99.9% ARC-AGI-3 headline is contested — reporting on September 6 found the score is harness-dependent, at 62.7% under the standard harness at max reasoning for a stated $26,098 run. Independent coding comparisons against Claude Fable 5.1 and Opus 5 are mixed, so keep any Astra coding claim attributed. For general agency work, compare shipped models directly: GPT-5.6 Sol, Claude Fable 5.1/Opus 5, and Gemini 3.x (Claude API pricing 2026 breakdown).
The September 1 announcement gives the first real benchmark signal — but it is narrow (cybersecurity) and self-reported. OpenAI notes Astra's cyber capabilities "are broadly in line with the rising hacking abilities of AI models that OpenAI and Anthropic have been forecasting for months"; Anthropic flagged similar concerns about its Mythos model earlier this year. For decisions today, compare shipped models by price and capability on our best AI coding agent pricing hub, and read OpenAI vs Anthropic for enterprise work.
Not to be confused with Google's Project Astra
"Astra" is overloaded. OpenAI Astra is OpenAI's flagship frontier model — shipped September 3, 2026 as GPT-6 Astra and rated Critical for cyber capability. Google's Project Astra is a DeepMind multimodal assistant prototype — "a universal assistant that sees, hears, remembers, and acts across devices and Google products" — and the two are "unrelated projects" that "happen to share a name." Add Astral (a Python tooling company) and Astra Platform (a Google Cloud product): four different products inside one keyword. Before trusting a claim about "Astra" coding, pricing, or availability, check which product the source means.
What Astra means for agency workflows
Security and red-team work. The Critical rating reframes Astra from "coding model" to "frontier cyber tool." Agencies that can access the Daybreak Blue configuration get capability for vulnerability discovery and exploit chaining that general users still do not have; non-partner agencies should expect restricted behavior and monitoring on security-adjacent prompts.
Coding and agent work. OpenAI's internal evaluations show "significant advancements in agentic coding and cybersecurity," and the shipped model supports long-horizon, tool-using generation through computer use and the hosted shell. The agency differentiator shifts from "we prompt well" to "we supervise agents that build" — the staffing and pricing conversation is live now.
One-shot generation (unverified). The leak claims a full website or a playable game in a single pass on Max effort. If real, that compresses scoping-to-prototype timelines dramatically — but provenance is disputed, so don't re-plan delivery on it yet.
Cost planning. Max effort "spends substantially longer reasoning than GPT-5.6 Sol," and reasoning tokens bill at output rates — $50 per 1M on Standard, $75 per 1M once a prompt passes the 272K input threshold — so a max-effort fleet can dominate an invoice even where the headline rate looks workable. Published rates, worked per-task examples and the 272K cliff math are on the GPT-6 Astra API pricing rate card and in the Astra cost outlook; the Cursor cut's cost impact is in what the Cursor cut means for your model stack costs.
Model mix. Astra has shipped and stays barred from Cursor, so expect pressure to consolidate around OpenAI's own surfaces (ChatGPT, Codex) or rebalance toward Claude and Gemini in the IDE. Keep client contracts flexible: model-swap and token-burn clauses protect you when the frontier shifts mid-engagement.
How much does OpenAI Astra cost?
Standard pricing is $10 per 1M input tokens, $50 per 1M output tokens, $1 per 1M cached input and $12.50 per 1M cache writes (prompts up to 272K input). Prompts over 272K input tokens reprice the entire request at $20 input / $75 output / $2 cached per 1M. Batch and Flex run at 50% of Standard and Fast mode at 2x, which puts Astra Standard at roughly 2.5x GPT-5.6 Sol's promo rates ($4/$20).
Those rates come from OpenAI's model card and pricing page, verified September 14, 2026, and they are the ones to quote to a client. The $2,000 figure that circulated before launch was a token-cost estimate for the August 1 research runs at Sol rates — not an Astra price. Two traps are worth pricing before you commit: the 272K rule, which doubles the input line and raises the output line 50% for the whole request, and cache writes at 1.25x uncached input, which means a cached prefix needs roughly two reads to pay for itself. The full tier table and worked per-task examples live on the GPT-6 Astra API pricing rate card; the Astra cost outlook carries the budgeting scenarios and the 272K cliff math.
FAQ
When did OpenAI Astra launch?
It already launched. OpenAI released GPT-6 Astra on September 3, 2026 (model ID gpt-6-astra), and it is live in the OpenAI API and in ChatGPT Work and Codex for Pro, Enterprise, and Business Premium users. The Sept 3-10 window that circulated before launch was a leak rumor; the launch superseded it.
What is Astra's Critical rating under OpenAI's Preparedness Framework?
Astra is the first OpenAI model to reach the Critical cybersecurity capability threshold. OpenAI confirmed Sept 1 that it can find previously unknown security flaws and exploit them across many well-protected systems without step-by-step human guidance.
What is Daybreak Blue early access?
Daybreak Blue is OpenAI's early-access program for select partners (e.g., Cisco, Cloudflare, Palo Alto Networks) that get a less-restricted version of Astra with more robust cyber capabilities at launch. A small tester group gets access first; Daybreak Blue expands defensive use afterward.
Can I use OpenAI Astra for cybersecurity work?
Yes, but gated — and the gating survived launch. GPT-6 Astra is live in the API and in ChatGPT Work and Codex, but its most advanced cyber capabilities remain limited to approved testers and Daybreak Blue partners; general users get a more restricted configuration.
What is OpenAI Astra?
OpenAI's flagship frontier model, released September 3, 2026 as GPT-6 Astra. Model ID gpt-6-astra, a 1,050,000-token context window (922,000 max input, 128,000 max output), reasoning effort up to max, and $10 per 1M input / $50 per 1M output on the Standard tier.
Is Astra the same as GPT-6?
Yes — the branding question was settled at launch. OpenAI ships the model as GPT-6 Astra, and the GPT-6 name appears in the API model id (gpt-6-astra), the model card and ChatGPT. Before September 3 it was genuinely open.
Why was Astra paused?
Aug 7: OpenAI couldn't rule out Critical cyber capability and paused non-compliant workloads. Aug 18: two-week RL pause. Aug 28: large frontier RL run restarted after new safety requirements. Sept 1: OpenAI confirmed the Critical rating and said Astra's safeguards sufficiently minimize risk for release.
Is Astra better than Claude or Gemini?
On OpenAI's ExploitBench, Astra scored 100% and OpenAI says it outperforms GPT-5.6 Sol and Anthropic's Mythos on cybersecurity benchmarks — but that is OpenAI's own comparison table, not an independent tournament. The 99.9% ARC-AGI-3 headline is contested (62.7% under the standard harness at max reasoning, a stated $26,098 run), and independent coding comparisons against Claude Fable 5.1 and Opus 5 are mixed.
Will Astra be available in Cursor?
No. OpenAI is winding down Cursor model access (proposed November 12, 2026) and will not provide future models — explicitly including Astra — under that contract.
How much does OpenAI Astra cost?
Standard pricing is $10 per 1M input tokens and $50 per 1M output tokens, with cached input at $1 and cache writes at $12.50 per 1M. Prompts over 272K input tokens reprice the whole request at $20 input / $75 output per 1M. Batch and Flex are 50% of Standard and Fast mode is 2x. See the GPT-6 Astra API pricing rate card.
Is OpenAI Astra the same as Google's Project Astra?
No. OpenAI's is a shipped frontier model (GPT-6 Astra, released September 3, 2026); Google's is a DeepMind assistant prototype.
Astra pricing is live — price the tier, the 272K cliff and the gating before you quote a client.
See the GPT-6 Astra API pricing rate card →Budget Astra scenarios and the 272K cliff →
Sources & update note
September 14, 2026 update. This post was originally published August 31 as a leak story, refreshed September 1 when OpenAI confirmed Astra's Critical cyber capability rating, and rewritten again on September 14, 2026 after the September 3 launch. Every pre-launch claim — that no release date, model card or pricing had been published, that the model was not yet in OpenAI's public catalog, that release was imminent, that GPT-6 branding was unconfirmed, and that the Sept 3–10 window was still a live question — has been replaced with launch facts from OpenAI's own model card and pricing page. The leak material is retained as labelled history. This post will be refreshed again when the Daybreak Blue partner list changes, on the November 12 Cursor cutoff, or when OpenAI revises its benchmarks or the Astra rate card.
Last updated: September 14, 2026 (EDT).
- OpenAI developer docs: GPT-6 Astra model card — model id, context window, max input/output, endpoints, tools, rate limits (verified Sept 14, 2026)
- OpenAI developer docs: pricing — gpt-6-astra rows in the Standard, Batch, Flex and Fast tables (verified Sept 14, 2026)
- OpenAI: Path to Astra — critical capabilities and frontier safeguards (Sept 1, 2026)
- OpenAI on X: Astra announcement — "Astra represents a significant advance in cybersecurity capability, reaching the Critical threshold under our Preparedness Framework" (Sept 1, 2026)
- WIRED: OpenAI Is About to Release Its First AI Model With 'Critical' Cyber Abilities (Sept 1, 2026)
- CNBC: OpenAI says Astra AI model is its first that crosses 'Critical' cybersecurity capability (Sept 1, 2026)
- TechCrunch: OpenAI's Astra model is on the way — and very good at breaking into computer systems (Sept 1, 2026)
- Bloomberg: OpenAI to Restrict Access to Astra AI Model's Advanced Cybersecurity Features (Sept 1, 2026)
- OpenAI: Responding to the next frontier of critical cyber capabilities (Aug 7, 2026)
- OpenAI: Pacing model development in an era of cyber-critical capabilities (Aug 18, 2026)
- OpenAI: Our decision on Cursor following its acquisition by SpaceX (Aug 28, 2026)
- OpenAI: Ten advances in mathematics and theoretical computer science (Aug 1, 2026)
- OrcaRouter: OpenAI Astra - Everything We Know About the Model That Isn't GPT-6 (living post through Aug 31)
- Kingy AI: OpenAI Astra Rumor Tracker (Aug 29; updated Aug 31)
- TestingCatalog: First outputs from GPT-6 Astra model from OpenAI (Aug 29, 2026)
- CNBC: OpenAI to end model access to Cursor after acquisition by SpaceX (Aug 29)
- MacRumors: OpenAI Delays Next Major AI Model Astra Over Critical Hacking Concerns (Aug 7)
Accuracy note: launch facts (model id gpt-6-astra, 1,050,000-token context, 922K max input, 128K max output, Apr 30, 2026 cutoff, effort ladder to max, endpoint and tool support, tiered rate limits, Standard/Batch/Flex/Fast pricing, the 272K repricing rule) are read from OpenAI's own developer documentation — the model card and pricing page, verified September 14, 2026. The Sept 1 capabilities (Critical rating, Daybreak Blue gating, ExploitBench 100%, zero-day chain, browser-compromise chain, 91.5% jailbreak refusal) come from OpenAI's Path to Astra post, corroborated by WIRED, CNBC, TechCrunch and Bloomberg (Bloomberg verified via headline/lede snippet; the article is paywalled). The Sept 10 Pro-signup pause is reported by TechCrunch and The Verge and is attributed in the body rather than linked. Launch benchmarks are vendor-reported and the 99.9% ARC-AGI-3 figure is harness-contested — see the benchmark section. Leak history (mozaik-alpha-fdm, Aug 29–31 demos) remains attributed and unverified per the original post's fact-check. Refresh triggers: Daybreak Blue partner list, Cursor cutoff (Nov 12, 2026), official benchmark revisions, or any change to the Astra rate card.