Building on yesterday's coverage, the story changed: GPT-6 Astra is moving from limited tests into paid, production access, and OpenAI has clarified who will get its most powerful cybersecurity functions.
What happened is practical and precise. Astra is now available across paid ChatGPT tiers, the OpenAI API, and through major clouds. OpenAI is still phasing access: the fiercest cyber‑capabilities are locked behind vetted Daybreak programs, while general reasoning and software automation are available more broadly.
Why this matters is simple. OpenAI says Astra is the first model it classifies as "Critical" for cybersecurity. With the right tools and access, the model can discover previously unknown software flaws and even develop ways to exploit them. That is a new level of automation for both defenders and adversaries.
How it works, in plain terms: think of Astra as an expert team you can give tools and a long memory. It can run commands, inspect systems, use web tools and hold very large amounts of context across a single task. That lets it carry out long, multi-step workflows that older models could not finish.
What changes now is concrete. Security teams get a powerful automation engine for finding and patching bugs faster, and OpenAI is committing funding and subsidised access for critical defenders. At the same time, OpenAI says offensive-grade features will be restricted to vetted partners. Pricing is public for wider use, so companies can plan for the cost of production deployments rather than hoping for free trials.
The open question is governance. Can gating, subsidies and review processes keep powerful agent capabilities useful for defense while preventing misuse? The technology is no longer hypothetical. The real test will be whether policy and operational safeguards move as fast as the model did.
