In mid-August, OpenAI halted its largest reinforcement learning run for safety reasons for the first time: Astra had crossed a "critical" threshold in cyber-offense capability. A little over two weeks later, the model shipped — GPT-6 Astra is now available to enterprises in the Trusted Access Program, exposed as gpt-6-astra in the API and on Amazon Bedrock, with ChatGPT Plus, Pro, Business and Enterprise access rolling out over the coming days; Pro and above also get GPT-6 Astra Pro.
Specs and pricing: 1M context, five reasoning tiers
The official docs list a 1,050,000-token context window, 128K max output, and an April 30, 2026 knowledge cutoff. API pricing is $10 per million input tokens, $1 cached, $50 output; requests beyond 272K input tokens are billed at 2x input and 1.5x output rates. reasoning.effort spans low, medium, high, xhigh and max, and Fast mode offers 2.5x speed at 2x price. That lands exactly on Claude Fable 5.1's $10/$50 — the benchmarking intent is obvious.
The scorecard: computer use is the headline
In OpenAI's eval tables, Astra's edge concentrates in end-to-end long tasks: AutomationBench 41.4% (GPT-5.6 Sol 18.1%, Claude Fable 5.1 31.4%), OSWorld 2.0 offline set 72.6%, ScreenSpot-Pro 92.7%, Agents' Last Exam 59.3%. On long context, MRCR v2 8-needle reaches 96.3% in the 512K-1M band (Sol 73.8%). One number deserves attention: on the Artificial Analysis Intelligence Index v4.1.1, Astra scores 61.2 — behind Claude Fable 5.1's 65.7. General intelligence is not its trump card.
Read the 99.9% ARC-AGI-3 carefully
OpenAI reports 99.9% on ARC-AGI-3, against 7.8% for Sol and 30.2% for Claude Opus 5. But that figure comes from OpenAI's own adapter harness; ARC Prize's independent runs show 17% to 63% on the standard stateless harness depending on reasoning tier, and a full reproduction of the 99.9% configuration costs tens of thousands of dollars. Both readings are real — just always attach the conditions.
The safety loop: the pause reason became the release headline
August's pause was about cyber capability crossing a line; September's announcement puts safety benchmarks front and center: Astra triggers the ExploitGym honeypot at 0.0% (the comparison model listed by OpenAI: 48.2%), internal circumvention benchmark 0.00%, internal hallucination benchmark 4.2% (vs 12.2%). Independent lab Irregular measured Astra solving 86 of 226 FrontierCyber challenges (Sol: 34), including zero-days in browsers and a cloud database — the offense capability is real, which is exactly why the guardrail numbers deserve a close read.
For developers buying by the token, Astra's $10/$50 buys not chat quality but the combination of computer use, long context and safety margin. And when you see a number like 99.9%, ask first: whose harness?
Reference: https://openai.com/index/gpt-6-astra
Specs and pricing: https://developers.openai.com/api/docs/models/gpt-6-astra