OpenAI Astra is live: Sept 3 launch, $10/$50 pricing, Critical-tier cyber gating

Published August 31, 2026 · Updated September 14, 2026By ABD Legacy LLC
Launched Sept 3, 2026 GPT-6 Astra gpt-6-astra in the API Daybreak Blue AI security agencies
Sept 14, 2026 refresh — Astra shipped. OpenAI released GPT-6 Astra on September 3, 2026 (model ID gpt-6-astra). It is live in the OpenAI API and in ChatGPT Work and Codex for Pro, Enterprise and Business Premium users, at $10 per 1M input / $50 per 1M output with a 1,050,000-token context window. This page has been rewritten from OpenAI's own model card and pricing page: the pre-launch framing — no published model card, no pricing, an imminent release, GPT-6 branding unconfirmed — is gone, the Sept 3–10 leak window is closed, and the leak material is retained as history. Full tier table and per-task math: GPT-6 Astra API pricing. Model comparison: GPT-6 Astra computer-use guide for agencies.
Sept 1 update (history) — Critical rating confirmed. This post originally covered the Aug 29–31 leak of claimed Astra outputs. On September 1, 2026, OpenAI confirmed the far bigger story: Astra is the first model to reach the "Critical" cybersecurity capability threshold under its Preparedness Framework, can find previously unknown security flaws and exploit them without step-by-step human guidance, and said release was imminent ("we plan to make Astra available soon") — with its most advanced cyber capabilities gated to Daybreak Blue early-access partners at launch. The leak section below is retained as history. Everything about the Critical rating, release timing, and access gating reflects OpenAI's Sept 1 announcement.

On September 3, 2026, OpenAI released GPT-6 Astra — the model it had spent August describing as its "next major model", and the first OpenAI model rated "Critical" for cybersecurity capability under its Preparedness Framework. It is live now: the API model ID is gpt-6-astra, the context window is 1,050,000 tokens, and Standard pricing is $10 per 1M input / $50 per 1M output (OpenAI's model card and pricing page, both verified September 14, 2026).

For agency owners, the planning question has moved from when to which tier, at what price, and with what gating. Three things decide that: the 272K repricing rule — prompts over 272K input tokens reprice the entire request at $20 input / $75 output per 1M; who gets the advanced cyber configuration, which is still Daybreak Blue partners rather than general users; and which surface your client can actually reach, since Astra is off by default for Enterprise workspaces until an admin enables it.

What is OpenAI Astra?

GPT-6 Astra is OpenAI's flagship frontier model, released September 3, 2026. It was first named on August 1, 2026 in a mathematics research post ("The results were achieved by an internal version of Astra, our next major model"), then referenced in OpenAI's August 18 safety-pacing post, its August 28 Cursor decision, and the September 1 Path to Astra post. The "GPT-6" branding question was settled at launch: the model card, the API id and the ChatGPT surfaces all carry it.

The launch facts come from OpenAI's own model card: model ID gpt-6-astra, a 1,050,000-token context window, 922,000-token maximum input, 128,000-token maximum output, April 30, 2026 knowledge cutoff, reasoning token support with reasoning.effort from low through max, and text plus image input with text output. It is supported on the Responses, Chat Completions and Batch endpoints; Realtime, Live, Assistants, fine-tuning, embeddings, images and the audio endpoints are not supported.

Confirmed by OpenAI

Resolved at launch

Still open

What actually shipped on September 3, 2026

OpenAI's model card is the first-party source for all of this, re-read on September 14, 2026:

Where you can use it. The API (gpt-6-astra) plus ChatGPT Work and Codex for Pro, Enterprise and Business Premium users, with ChatGPT Plus and Business chat as the remaining rollout surfaces. Astra Pro — the higher Work/Codex tier — is available on Pro, Business and Enterprise plans and is off by default for Enterprise admins until they enable it. On September 10, 2026 OpenAI temporarily paused new $200/month Pro subscription signups, citing Astra demand and infrastructure strain (TechCrunch, The Verge).

Not Astra: the September 8 Navier–Stokes result

On September 8, 2026 OpenAI published Navier–Stokes results produced by an internal system it describes as "significantly more capable than GPT-6 Astra" — roughly 10,000 coordinated agents over 88 hours, with about 17 hours to formalize and verify the result in Lean with GPT-6 Astra. That internal system is not gpt-6-astra. Do not attribute the Navier–Stokes result to Astra, and do not read it as evidence of Astra's own capability.

Astra is the first model rated 'Critical' — what that means

OpenAI's Preparedness Framework (introduced 2023) classifies frontier models by cyber capability. Under the framework's update, a "High" threshold means a model can amplify "existing pathways" to severe harm; a "Critical" threshold means a model can introduce "unprecedented new pathways" to severe harm — for example, developing functional zero-day exploits in many hardened real-world systems without human intervention, or executing end-to-end novel attack strategies against hardened targets given only a high-level goal.

Astra is the first model OpenAI has designated at Critical. CNBC confirms the company said Astra "can find previously unknown security flaws and exploit them without step-by-step guidance from humans," placing it in the most advanced category of the Preparedness Framework. OpenAI said its multi-week pause was productive: after strengthening and testing protections, it believes Astra's safeguards "sufficiently minimize the risk of severe harm for release under our Preparedness Framework."

Critical = Astra can independently find and exploit previously unknown vulnerabilities in real-world software, and can chain multiple exploits together to move deeper into a target system. OpenAI's internal figures put Astra at 100% on ExploitBench and ahead of GPT-5.6 Sol and Anthropic's Mythos on cybersecurity benchmarks — capabilities broadly in line with what OpenAI and Anthropic have been forecasting for months (WIRED).

Notable test details from OpenAI's Sept 1 post:

The Critical rating also comes with a caveat OpenAI flagged: results shown reflect capabilities with Daybreak Blue access, not the default production configuration. The model everyone else gets will be more restricted.

Advanced cyber access is still gated to Daybreak Blue

OpenAI's Sept 1 language — "We plan to make Astra available soon, but access to its most advanced cybersecurity capabilities will be more limited. Advanced cybersecurity work will initially be available to a group of testers, with access through Daybreak Blue following to expand defensive use." — is now launch fact rather than a promise. The model shipped on September 3; the access ladder it described did not change with it.

Daybreak Blue is OpenAI's early-access program for select partners in its Daybreak cybersecurity coalition — WIRED reports the partner list includes digital infrastructure providers like Cisco, Cloudflare, and Palo Alto Networks. Partners get a less-restricted version of Astra with more robust cyber capabilities, so they can harden defenses before similarly capable models are broadly available. OpenAI also said it has been working closely with government partners to ensure they are aware of Astra's cyber skills and can get access to them.

For everyone else, OpenAI is layering on safeguards: a new misalignment monitor that can slow, pause, or stop tasks it flags (including some legitimate ones — OpenAI warns the monitor may "occasionally flag legitimate activity as potential cyber misuse"), refusals of exploit requests, stronger jailbreak resistance, and chain-of-thought monitoring. OpenAI reports Astra refuses unsafe queries at a significantly higher rate than previous models (91.5% of cyber jailbreak requests vs 59% for GPT-5.6 Sol).

What Daybreak Blue access means for AI security agencies

For agencies doing offensive security, red-team, or AI-security work, the Sept 1 announcement turns model access into a positioning and risk question.

Partner vs non-partner positioning

Client risk questions to ask now

  1. Does any vendor in our stack hold Daybreak Blue access? If a vendor uses Astra for security tooling, find out which configuration they run — partner-tier or default — and what monitoring/friction applies.
  2. What can Astra do against our attack surface? With Critical-rated capability, the risk calculus changes: previously unknown flaws can be found and chained without step-by-step human guidance. Clients need to know whether their systems were tested against that capability class.
  3. Who is accountable if the misalignment monitor interrupts legitimate work? OpenAI warns the monitor can slow, pause, or stop legitimate defensive activity. Contracts for AI-security engagements should define what happens when the model's own guardrail stops a deliverable.
  4. Is our client's sensitive infrastructure in scope for an Astra-based engagement? Government agencies and selected partners are getting access; the data-handling and compliance boundaries for Astra security work need to be explicit before you point a Critical-rated model at client systems.
  5. What happens if access is recalibrated? OpenAI says it plans to keep calibrating safeguards and expanding access through programs like Daybreak — meaning today's partner-tier access can change. Build model-swap and re-scope clauses into security SOWs.

Leak history (Aug 29–31, 2026) — superseded

Between August 29 and 31, 2026, the first claimed outputs from OpenAI's unreleased model circulated on X and Discord under the checkpoint codename mozaik-alpha-fdm: a Grand Theft Auto 2-style game, complete websites, 3D objects, and voxel environments, reportedly generated in a single pass on "Max effort." The leak's authenticity is disputed — pseudonymous developer teortaxesTex claimed the samples were actually Claude Opus 5 output, and Kingy's fact-check found no media showed an OpenAI model selector, an Astra model ID, the original prompt, or a complete generation session. The Sept 1 confirmation of Astra's cyber capabilities does not authenticate the leaked demos; the demos remain unverified. This section is superseded: GPT-6 Astra shipped on September 3, 2026, and the leak window it belonged to is closed.

Is Astra the same as GPT-6?

Yes. The naming question was settled at launch: OpenAI ships the model as GPT-6 Astra, and the GPT-6 name appears in the API model id (gpt-6-astra), the model card and the ChatGPT surfaces. Before September 3 it was genuinely open — GPT-6, a GPT-5.x point release, or a separate tier alongside Sol, Terra and Luna were all live possibilities.

When did GPT-6 Astra launch?

Launched September 3, 2026 and live in the OpenAI API from September 4, with a 1,050,000-token context window at $10 per 1M input / $50 per 1M output (Standard). The Sept 3–10 window that circulated before launch was a leak rumor; the launch superseded it. Advanced cyber capabilities remain gated to approved testers and Daybreak Blue partners.

The open question of "soon" closed on September 3. What remains is access, not timing: Daybreak Blue for advanced cyber work, Enterprise admin enablement for workspace access, and the November 12 Cursor cutoff for anyone standardised on Cursor's OpenAI integration.

Why OpenAI paused parts of Astra

Astra is the first OpenAI model to cross the Critical cyber capability threshold — the top of the Preparedness Framework ladder. On August 7, OpenAI said internal evaluations showed "significant advancements in agentic coding and cybersecurity," and it could not rule out critical cyber capabilities. Non-compliant work was paused; the model moved to isolated, sandboxed environments; and OpenAI confirmed "relevant government agencies and selected AI safety organizations will participate in testing."

On August 18, OpenAI published Pacing model development in an era of cyber-critical capabilities: a two-week pause in RL training on deployment-bound models, its largest planned frontier RL run on hold, and an extra monitoring requirement on all Astra inference with tools. On August 28, OpenAI restarted the large frontier RL run after the new safety and security requirements were in place (some smaller experimental runs remain held). See OpenAI paused Astra training in August.

For agencies, the takeaway is now access risk rather than delay risk: the model has shipped, but which configuration your engagements can use — and whether the guardrail monitor interrupts legitimate work — is the remaining uncertainty.

Astra and the Cursor breakup

On August 14, 2026, Cursor (Anysphere) announced it had officially become part of SpaceX after a reported $60 billion acquisition. On August 28, OpenAI notified SpaceX that it intends to wind down the contract providing OpenAI models to Cursor, with a proposed shutoff date of November 12, 2026. OpenAI's rationale: "we cannot be confident that SpaceX will use our technology within our terms of service, based on our experience with Elon Musk's companies violating contracts." Astra is explicit: no future OpenAI models — Astra included — will be provided under the contract.

Practical effects: current OpenAI models continue through the proposed transition, but if you standardized on Cursor's OpenAI integration, you now have a hard date to re-plan your model stack — see the OpenAI–Cursor split and what still works.

Is Astra better than Claude or Gemini?

On cybersecurity benchmarks OpenAI reports Astra is ahead: 100% on ExploitBench, and outperforming GPT-5.6 Sol and Anthropic's Mythos (WIRED). Treat those as vendor-reported: OpenAI's launch page publishes its own comparison table (nine categories, roughly 40 benchmarks, six models), which is not an independent tournament. The "AGI era" 99.9% ARC-AGI-3 headline is contested — reporting on September 6 found the score is harness-dependent, at 62.7% under the standard harness at max reasoning for a stated $26,098 run. Independent coding comparisons against Claude Fable 5.1 and Opus 5 are mixed, so keep any Astra coding claim attributed. For general agency work, compare shipped models directly: GPT-5.6 Sol, Claude Fable 5.1/Opus 5, and Gemini 3.x (Claude API pricing 2026 breakdown).

The September 1 announcement gives the first real benchmark signal — but it is narrow (cybersecurity) and self-reported. OpenAI notes Astra's cyber capabilities "are broadly in line with the rising hacking abilities of AI models that OpenAI and Anthropic have been forecasting for months"; Anthropic flagged similar concerns about its Mythos model earlier this year. For decisions today, compare shipped models by price and capability on our best AI coding agent pricing hub, and read OpenAI vs Anthropic for enterprise work.

Not to be confused with Google's Project Astra

"Astra" is overloaded. OpenAI Astra is OpenAI's flagship frontier model — shipped September 3, 2026 as GPT-6 Astra and rated Critical for cyber capability. Google's Project Astra is a DeepMind multimodal assistant prototype — "a universal assistant that sees, hears, remembers, and acts across devices and Google products" — and the two are "unrelated projects" that "happen to share a name." Add Astral (a Python tooling company) and Astra Platform (a Google Cloud product): four different products inside one keyword. Before trusting a claim about "Astra" coding, pricing, or availability, check which product the source means.

What Astra means for agency workflows

Security and red-team work. The Critical rating reframes Astra from "coding model" to "frontier cyber tool." Agencies that can access the Daybreak Blue configuration get capability for vulnerability discovery and exploit chaining that general users still do not have; non-partner agencies should expect restricted behavior and monitoring on security-adjacent prompts.

Coding and agent work. OpenAI's internal evaluations show "significant advancements in agentic coding and cybersecurity," and the shipped model supports long-horizon, tool-using generation through computer use and the hosted shell. The agency differentiator shifts from "we prompt well" to "we supervise agents that build" — the staffing and pricing conversation is live now.

One-shot generation (unverified). The leak claims a full website or a playable game in a single pass on Max effort. If real, that compresses scoping-to-prototype timelines dramatically — but provenance is disputed, so don't re-plan delivery on it yet.

Cost planning. Max effort "spends substantially longer reasoning than GPT-5.6 Sol," and reasoning tokens bill at output rates — $50 per 1M on Standard, $75 per 1M once a prompt passes the 272K input threshold — so a max-effort fleet can dominate an invoice even where the headline rate looks workable. Published rates, worked per-task examples and the 272K cliff math are on the GPT-6 Astra API pricing rate card and in the Astra cost outlook; the Cursor cut's cost impact is in what the Cursor cut means for your model stack costs.

Model mix. Astra has shipped and stays barred from Cursor, so expect pressure to consolidate around OpenAI's own surfaces (ChatGPT, Codex) or rebalance toward Claude and Gemini in the IDE. Keep client contracts flexible: model-swap and token-burn clauses protect you when the frontier shifts mid-engagement.

How much does OpenAI Astra cost?

Standard pricing is $10 per 1M input tokens, $50 per 1M output tokens, $1 per 1M cached input and $12.50 per 1M cache writes (prompts up to 272K input). Prompts over 272K input tokens reprice the entire request at $20 input / $75 output / $2 cached per 1M. Batch and Flex run at 50% of Standard and Fast mode at 2x, which puts Astra Standard at roughly 2.5x GPT-5.6 Sol's promo rates ($4/$20).

Those rates come from OpenAI's model card and pricing page, verified September 14, 2026, and they are the ones to quote to a client. The $2,000 figure that circulated before launch was a token-cost estimate for the August 1 research runs at Sol rates — not an Astra price. Two traps are worth pricing before you commit: the 272K rule, which doubles the input line and raises the output line 50% for the whole request, and cache writes at 1.25x uncached input, which means a cached prefix needs roughly two reads to pay for itself. The full tier table and worked per-task examples live on the GPT-6 Astra API pricing rate card; the Astra cost outlook carries the budgeting scenarios and the 272K cliff math.

FAQ

When did OpenAI Astra launch?

It already launched. OpenAI released GPT-6 Astra on September 3, 2026 (model ID gpt-6-astra), and it is live in the OpenAI API and in ChatGPT Work and Codex for Pro, Enterprise, and Business Premium users. The Sept 3-10 window that circulated before launch was a leak rumor; the launch superseded it.

What is Astra's Critical rating under OpenAI's Preparedness Framework?

Astra is the first OpenAI model to reach the Critical cybersecurity capability threshold. OpenAI confirmed Sept 1 that it can find previously unknown security flaws and exploit them across many well-protected systems without step-by-step human guidance.

What is Daybreak Blue early access?

Daybreak Blue is OpenAI's early-access program for select partners (e.g., Cisco, Cloudflare, Palo Alto Networks) that get a less-restricted version of Astra with more robust cyber capabilities at launch. A small tester group gets access first; Daybreak Blue expands defensive use afterward.

Can I use OpenAI Astra for cybersecurity work?

Yes, but gated — and the gating survived launch. GPT-6 Astra is live in the API and in ChatGPT Work and Codex, but its most advanced cyber capabilities remain limited to approved testers and Daybreak Blue partners; general users get a more restricted configuration.

What is OpenAI Astra?

OpenAI's flagship frontier model, released September 3, 2026 as GPT-6 Astra. Model ID gpt-6-astra, a 1,050,000-token context window (922,000 max input, 128,000 max output), reasoning effort up to max, and $10 per 1M input / $50 per 1M output on the Standard tier.

Is Astra the same as GPT-6?

Yes — the branding question was settled at launch. OpenAI ships the model as GPT-6 Astra, and the GPT-6 name appears in the API model id (gpt-6-astra), the model card and ChatGPT. Before September 3 it was genuinely open.

Why was Astra paused?

Aug 7: OpenAI couldn't rule out Critical cyber capability and paused non-compliant workloads. Aug 18: two-week RL pause. Aug 28: large frontier RL run restarted after new safety requirements. Sept 1: OpenAI confirmed the Critical rating and said Astra's safeguards sufficiently minimize risk for release.

Is Astra better than Claude or Gemini?

On OpenAI's ExploitBench, Astra scored 100% and OpenAI says it outperforms GPT-5.6 Sol and Anthropic's Mythos on cybersecurity benchmarks — but that is OpenAI's own comparison table, not an independent tournament. The 99.9% ARC-AGI-3 headline is contested (62.7% under the standard harness at max reasoning, a stated $26,098 run), and independent coding comparisons against Claude Fable 5.1 and Opus 5 are mixed.

Will Astra be available in Cursor?

No. OpenAI is winding down Cursor model access (proposed November 12, 2026) and will not provide future models — explicitly including Astra — under that contract.

How much does OpenAI Astra cost?

Standard pricing is $10 per 1M input tokens and $50 per 1M output tokens, with cached input at $1 and cache writes at $12.50 per 1M. Prompts over 272K input tokens reprice the whole request at $20 input / $75 output per 1M. Batch and Flex are 50% of Standard and Fast mode is 2x. See the GPT-6 Astra API pricing rate card.

Is OpenAI Astra the same as Google's Project Astra?

No. OpenAI's is a shipped frontier model (GPT-6 Astra, released September 3, 2026); Google's is a DeepMind assistant prototype.

Astra pricing is live — price the tier, the 272K cliff and the gating before you quote a client.

See the GPT-6 Astra API pricing rate card →
Budget Astra scenarios and the 272K cliff →

Sources & update note

September 14, 2026 update. This post was originally published August 31 as a leak story, refreshed September 1 when OpenAI confirmed Astra's Critical cyber capability rating, and rewritten again on September 14, 2026 after the September 3 launch. Every pre-launch claim — that no release date, model card or pricing had been published, that the model was not yet in OpenAI's public catalog, that release was imminent, that GPT-6 branding was unconfirmed, and that the Sept 3–10 window was still a live question — has been replaced with launch facts from OpenAI's own model card and pricing page. The leak material is retained as labelled history. This post will be refreshed again when the Daybreak Blue partner list changes, on the November 12 Cursor cutoff, or when OpenAI revises its benchmarks or the Astra rate card.

Last updated: September 14, 2026 (EDT).

Accuracy note: launch facts (model id gpt-6-astra, 1,050,000-token context, 922K max input, 128K max output, Apr 30, 2026 cutoff, effort ladder to max, endpoint and tool support, tiered rate limits, Standard/Batch/Flex/Fast pricing, the 272K repricing rule) are read from OpenAI's own developer documentation — the model card and pricing page, verified September 14, 2026. The Sept 1 capabilities (Critical rating, Daybreak Blue gating, ExploitBench 100%, zero-day chain, browser-compromise chain, 91.5% jailbreak refusal) come from OpenAI's Path to Astra post, corroborated by WIRED, CNBC, TechCrunch and Bloomberg (Bloomberg verified via headline/lede snippet; the article is paywalled). The Sept 10 Pro-signup pause is reported by TechCrunch and The Verge and is attributed in the body rather than linked. Launch benchmarks are vendor-reported and the 99.9% ARC-AGI-3 figure is harness-contested — see the benchmark section. Leak history (mozaik-alpha-fdm, Aug 29–31 demos) remains attributed and unverified per the original post's fact-check. Refresh triggers: Daybreak Blue partner list, Cursor cutoff (Nov 12, 2026), official benchmark revisions, or any change to the Astra rate card.