Building on our coverage two days ago, OpenAI has begun a staged rollout of GPT-6 Astra that gives vetted cybersecurity teams gated access to a new "computer use" ability.
OpenAI published its Astra materials last week and has started by placing the model in the hands of selected cyber‑defense organisations, with broader paid access to follow and free-tier users excluded. The company says Astra is its most capable and most aligned model yet and that safety must be the top priority as it moves into real-world deployment.
Why you should care: this is the first time a mainstream provider has delivered an AI that can not only suggest fixes or commands, but actually operate a computer-like environment in multi-step sequences, and which in testing found previously unknown vulnerabilities. That combination raises the stakes for both defenders and attackers.
How it works, in plain terms: think of Astra as a very fast digital assistant with hands and a mouse. Instead of only answering questions, it can navigate interfaces, run commands and chain steps together to complete tasks. In controlled tests it discovered and weaponized zero-day bugs, which is why OpenAI classifies it at a "Critical" cybersecurity readiness level and restricts offensive uses to a vetted Daybreak defender program.
What changes now: defenders will get more powerful tooling and OpenAI is backing access with a $1 billion subsidy program for organisations that protect critical services. At the same time, offensive capabilities exist in a production model for the first time, so the industry is effectively moving to a two-tier landscape where advanced functions are gated to trusted programmes rather than broadly available. And no, this does not mean anyone can run Astra on a laptop, use requires paid access and substantial cloud infrastructure.
What's next: the real test is whether gating plus subsidies can let defenders benefit without making advanced offensive techniques easier to replicate. Will restricted access slow misuse, or simply shift the advantage to whoever builds the next open workaround? We'll be watching whether policy and competition keep pace with the capability.
