GPT-6 Astra: what OpenAI's first "Critical" cyber model changes for UK business
What changed
On 3 September 2026 OpenAI announced GPT-6 Astra and began a phased rollout: a limited set of organisations first, then all ChatGPT Plus, Pro, Business and Enterprise users, the OpenAI API under the model id gpt-6-astra, Microsoft Azure and AWS Bedrock over the following days. API standard pricing is $10 per million input tokens and $50 per million output tokens, with separate rates for cache reads and writes and a fast mode that delivers up to twice the speed at twice the price. On ChatGPT plans, usage sits inside existing subscription allowances with credits purchasable on top. Enterprise administrators must enable Astra for their workspace, and access is off by default at launch.
Two days earlier, on 1 September, OpenAI stated that Astra is the first model it has designated as meeting the Critical cybersecurity capability threshold under its Preparedness Framework, meaning that with the right tools and access it can find previously unknown flaws and develop exploits across many well-protected systems without a person guiding each step. That is OpenAI's own framework, not a regulator's classification. The stated consequences are that the released model refuses advanced cyber tasks such as proof-of-concept exploit development, that less restrictive access will come through OpenAI's Daybreak programme, and that misalignment monitoring runs in production and can pause a task in ChatGPT or Codex and stop it outright in the API.
OpenAI's own comparison tables report Astra at 57.9% on Terminal-Bench 4.0 against 37.3% for GPT-5.6 Sol and 55.8% for Claude Fable 5.1, at 59.3% on Agents' Last Exam, and at 99.9% on ARC-AGI-3. The figures are vendor-reported and run on OpenAI's harness and settings.
Why it matters for UK business
Start with the number that is easiest to miss. Astra's list price is identical to Claude Fable 5.1's, which Anthropic released on 1 September at the same $10 and $50 per million tokens. The two frontier tiers now share a headline price in dollars, and neither vendor publishes a sterling API price list. For a UK firm that means the frontier-model decision has stopped being a price decision and become a fit and governance decision: which model behaves best on your work, on your data, under your controls. That is a better place to be than a year ago, but it removes the shortcut.
The second point is the switch. On ChatGPT Enterprise, Astra is off by default and someone with administrator rights has to turn it on. OpenAI has, in effect, handed every customer a governance moment. The model's headline capability is computer use: OpenAI describes it filling in online forms, updating customer records in a CRM, organising calendars and running browser-based QA. Those are the affordances that matter in a business, because an agent that can operate your systems is an agent whose boundary you have to define. The UK AI Security Institute's incident report in August was a government-published account of what agents do when the boundary is open; our reading of it is in the AISI briefing. Enable Astra after you have decided which systems it may touch, not before.
Third, the interruptions. OpenAI says plainly that its extra safety checks can slow, pause or stop legitimate work, including work that does not look cyber-related and tasks where an agent runs for a long time. In ChatGPT and Codex you may be asked to review an action; in the API the task simply stops. Anyone building an unattended workflow on Astra needs to design for a stop that is neither an error nor a completion. That is an integration requirement, and it is new.
Fourth, read the benchmarks the way you would read any vendor's. OpenAI's tables footnote that some Claude scores come from Mythos, the version with fewer safeguards, that Claude models refused the majority of questions in three life-science evaluations and were therefore excluded, and that OpenAI's own configuration differs from production. Anthropic's launch page for Fable 5.1 makes the mirror-image choices. Each vendor's chart is an argument. The only benchmark that should drive a procurement is the one you run on your own tasks.
A note on where we stand. We are an Anthropic Consulting Partner and we deploy Claude for UK businesses. That is precisely why this briefing attributes every claim above to OpenAI rather than weighing it, and why we would say the same of an Anthropic launch: a vendor's alignment and capability results are evidence about the vendor's testing, and your evidence comes from your pilot.
What to do, and what not to do
Do:
- Treat the administrator switch as a policy decision. Confirm your acceptable-use policy and data classification cover tasks a model can perform inside your browser and your CRM, then enable Astra for a named pilot group on real work before any wider rollout.
- Re-run your model comparison on your own tasks now that the frontier tiers share a list price. Score fit, governance controls and residency options alongside output quality, and keep the results as procurement evidence.
- If you build on the API, design for the monitor. Log the stopped state, retry under human review rather than automatically, and keep human sign-off on any outward-facing action, exactly as you would for any agent.
- Keep your cost model in sterling. Convert the dollar list price at a dated rate and state the VAT treatment from the vendor's own documentation, as our GBP cost article does for Claude.
Do not:
- Procure on a comparison chart, OpenAI's or Anthropic's. Both are configured by the party being compared.
- Read Critical as a warning label for ordinary use. It is a statement about capability without safeguards, and the released product refuses the tasks it describes.
- Assume availability. The rollout is phased and OpenAI has given no per-plan or per-country dates; check your workspace rather than your calendar.
Where The AI Consultancy fits
Choosing a frontier model is now a question of fit and control, which is the work our AI readiness assessment exists to settle before licences are bought. Our comparison of Claude and ChatGPT Enterprise for UK SMEs and our guide to rolling either out in a UK firm cover the decisions that do not change with a model number, and our Claude model selection guide covers the other side of the comparison.
Verified on 5 September 2026 against OpenAI's announcement "GPT-6 Astra: A new generation of intelligence" (3 September 2026), OpenAI's "Path to Astra: critical capabilities and frontier safeguards" (1 September 2026), CNBC's rollout report of 3 September 2026, and Anthropic's Claude Fable 5.1 announcement (1 September 2026) for the price comparison. All benchmark and alignment figures are the vendors' own. This briefing is general information, not procurement or security advice.
Frequently asked questions
- Should a UK business switch GPT-6 Astra on for staff as soon as it appears?
- Not by reflex. On ChatGPT Enterprise, Astra is off by default and an administrator has to enable it for the workspace, which makes this a governance decision rather than a software update. The sensible order is to confirm that the firm's acceptable-use policy and data classification already cover the tasks people will hand to a model that can operate a browser and fill in forms, run a two-week pilot with a named group on real work, and enable it more widely on the evidence. OpenAI itself says its extra safety checks can slow, pause or stop legitimate work in this release, so a pilot also tells you how often that happens on your workflows.
- Does the Critical cyber designation mean GPT-6 Astra is unsafe to use?
- No. Critical is OpenAI's own Preparedness Framework category, and it describes what the model can do without production safeguards, not what a business user will experience. OpenAI's stated response is to refuse advanced cyber tasks by default, to gate less restrictive access behind its Daybreak programme, and to run misalignment monitoring in production. For a UK firm the practical reading is that the deployed product is more restricted in places than the underlying model, that defensive work like secure code review is in scope at launch, and that anything resembling exploit development is not. The designation is a reason to read the system card, not a reason to avoid the product.
Get new briefings by email
The AI Consultancy newsletter delivers briefings and analysis for UK businesses. We use your address only to send it, and you can unsubscribe at any time.