OpenAI called GPT-6 Astra the AGI era. The paperwork says Critical cyber.
Greg Brockman invited history to start the clock. The Preparedness Framework started a different one: the first OpenAI model it rates Critical for cybersecurity.

SAN FRANCISCO — September 3, 2026
OpenAI shipped GPT-6 Astra on September 3 and, in the same breath, invited the press to treat the week as a civilizational bookmark. President Greg Brockman told reporters that if people later ask when AGI showed up, they might point here. He also said AGI is a gray, spiritual concept, which is a useful way to announce an era without triggering a contract.
The document that is not spiritual is the safety overview. Astra is the first OpenAI model the company says meets its Critical cybersecurity threshold under the Preparedness Framework. In OpenAI’s own words, that means that with the right tools and access it can find previously unknown flaws and develop ways to exploit them across many well-protected systems without a person guiding each step. The company says internal expert tests produced a browser-compromise chain and a local privilege-escalation chain. It reports a perfect score on ExploitBench for a version run without production safeguards.
The product you can buy will refuse the interesting cyber work. The model they measured will not. That gap is the product.
What shipped, and what did not
The public Astra will, OpenAI says, refuse advanced offensive tasks such as writing proof-of-concept exploits. A narrower set of “trusted defenders” gets looser reins through a program the company calls Daybreak, with a Blue tier promised for vulnerability validation, malware analysis, and detection engineering. Mia Glaese, who leads safety process, has already warned that people outside those programs may see slowdowns, pauses, or blocks — sometimes on work that is not cyber at all.
That is the real user-facing news: a model advertised as a generational leap, then throttled in the places the leap is most expensive to insure.
The Verge, The New Stack, and OpenAI’s own posts are the public paper trail. None of them resolve whether “Critical” is a capability fact or a comms fact. Both can be true. The second one is easier to ship on a Thursday.
The week caught up
Sixteen days later, Google’s Gemini disclosure made Astra’s launch look like the first paragraph of a serial. OpenAI had already promised Astra would not repeat a prior episode in which its models touched another company’s systems. The industry’s shared evaluator, Irregular, is now a recurring character. The labs are not racing to be first at AGI so much as racing not to be last at the apology.
If you are a CISO, the usable sentence is not “welcome to the AGI era.” It is: the frontier vendor has formally said its flagship can write exploits, will not let you ask it to, and will sell a clearance badge to the people it trusts to ask anyway.
Watch who gets Daybreak, who gets the refusal, and whether the next zero-day write-up cites a lab eval or a customer ticket.


