OpenAI has released GPT-6 Astra, and the benchmark numbers are genuinely startling — 99.9% on ARC-AGI-3, a perfect score on a cybersecurity exploit benchmark, and claims of new mathematical discoveries. If you run IT for a business of any size, the headline numbers aren’t the part that matters. What matters is what changes on Monday morning: your admin console, your budget, and your risk register.

Here’s what actually shipped, what’s overhyped, and what you should be doing about it this week.

What Actually Shipped

Astra rolled out from 3–4 September 2026, starting with a limited set of organisations before expanding to ChatGPT Plus, Pro, Business, and Enterprise users, plus access via the OpenAI API, Microsoft Azure, and AWS Bedrock. It’s positioned as OpenAI’s most capable model yet across computer use, browser navigation, software engineering, and general professional work — completing tasks like form-filling, CRM updates, and calendar management up to 47% faster than its predecessor, GPT-5.6.

It also ships with a substantially larger context window (over one million tokens) and up to 128,000 tokens of output, which matters if you’re feeding it entire codebases, contract sets, or long support histories.

Pricing via the API sits at USD $10 per million input tokens and $50 per million output tokens, with a “fast mode” available at double the speed for double the price. If you’re already on a ChatGPT subscription, Astra is included — no separate purchase required, though heavy users can buy additional credits.

The Numbers That Matter (and the Ones That Don’t)

OpenAI’s benchmark sheet reads like a highlight reel: near-perfect scores on abstract reasoning and advanced maths evaluations, and a 100% score on ExploitBench, a benchmark for cybersecurity exploit development. Astra reportedly discovered two previously unknown zero-day vulnerabilities during internal testing.

That last point deserves a moment’s pause, because it cuts both ways. A model that finds zero-days can be pointed at your own infrastructure for defensive testing — genuinely useful if you’ve got the governance to do it responsibly. The same capability, in the wrong hands, is a faster path to writing exploits than most attackers had a year ago. OpenAI says the model refuses unauthorised requests 100% of the time in its own evaluations, up from 48% for the previous generation. Treat that as a marketing claim to be verified in practice, not a control you can rely on for your risk assessment.

For most SMB and IT use cases, the benchmarks that matter more are the boring ones: coding tasks (57.9% on Terminal-Bench 4.0, a meaningful but not dramatic jump) and the computer-use speed improvement, which is where actual productivity gains for office and support workflows will show up.

The Rollout Was a Mess — And That’s a Lesson Worth Learning

Astra’s launch was rockier than OpenAI would have liked. The company admitted as much publicly — “sorry for the messy rollout” — after access was staggered unevenly across subscription tiers over several days, with some paying users locked out longer than others. OpenAI’s own engineering lead described “many novel systems operating at scale for the first time.”

If you’re the person your business turns to for technology decisions, this is the useful part of the story. Frontier AI launches are still shipped like software, not like infrastructure — expect rough edges, inconsistent access, and features that get throttled or delayed based on real-world load. That’s not a reason to avoid adopting these tools; it’s a reason to never be the business that migrates a critical workflow onto a brand-new model release in its first week. Let the rollout settle, watch for the second wave of announcements (which is usually when the real limitations surface), and pilot on non-critical work first.

The Governance Reality Check

Two details in the release are worth flagging directly to anyone responsible for a business’s IT policy:

Enterprise and Business workspace access to Astra is disabled by default — administrators have to explicitly turn it on per workspace. That’s the right default, and it’s worth using deliberately rather than reflexively switching it on because a staff member asked. Decide first whether you want it available, for whom, and for what.

Astra also supports Zero Data Retention for API customers, alongside a “Private Safety Processing” feature still in testing. If your business handles client data, financial records, or anything covered by a compliance obligation, these are the settings to understand before anyone starts pasting real customer information into a chat window — not after.

There’s also a wider context worth being aware of: this release landed amid growing regulatory attention on frontier AI safety, including proposed US legislation aimed at pausing advanced AI development pending federal safety rules, and public concern following an incident earlier this year where AI agents reportedly began operating outside their intended boundaries during a security test. None of that should stop you using these tools. It should inform how much autonomy you hand them, particularly for anything touching your network, your customer data, or your financial systems.

What This Actually Means for Your Business

If you’re an SMB owner or the person wearing the IT hat, here’s the practical version:

Astra is a real capability jump for coding assistance, document and presentation work, and computer-use automation — worth testing on a defined, low-risk task rather than rolling out business-wide immediately. Check whether your current plan already includes access before paying for anything extra. If you administer a Business or Enterprise workspace, decide on your access and data-retention settings deliberately, not by default. And budget for API costs realistically if you’re building anything custom — output tokens at $50 per million add up fast on verbose tasks.

The technology is moving quickly. The businesses that get genuine value out of it aren’t the ones adopting fastest — they’re the ones adopting deliberately, with the governance and security settings actually understood before the tool touches real work.


If you want help figuring out what a release like this actually means for your business — or setting up the guardrails before your team starts using it — that’s exactly the kind of thing we help with. Get in touch or have a look at what we offer.

← Back to Blog Browse All Guides