SPAWNSY

GPT-6 Astra: OpenAI Declares "the AGI Era" With the Model It Paused a Month Earlier

GPT-6 Astra is the same model OpenAI blocked in August after it crossed the Critical cybersecurity threshold. The flagship 99.9% ARC-AGI-3 score behind the AGI claim drops to 62.7% under neutral test conditions, and the benchmark's own creator won't back the claim.

AuthorTwenZySPAWNSY Editorial Desk
PublishedSeptember 7, 2026
Read time5 min
SectionTech
Views783
Share
GPT-6 Astra: OpenAI Declares "the AGI Era" With the Model It Paused a Month Earlier

On September 3, OpenAI released GPT-6 Astra, and company president Greg Brockman closed the presentation with "welcome to the AGI era." It's the same model we wrote about a month earlier: on August 7, OpenAI paused part of its work on Astra because internal testing couldn't rule out that the model could independently find and exploit zero-day vulnerabilities in hardened systems without human involvement. A month later, that same model hits the market under a banner about general intelligence, while its strongest offensive cyber capabilities stay locked away, just with a name now: Daybreak Access.

From pause to launch in four weeks

Astra was built on OpenAI's largest training run ever, using more than 100,000 GPUs at the Stargate complex in Texas. The company describes it as its most advanced model for complex work: coding, computer use, research and multistep tasks. Input and output token pricing sits at $10 and $50 per million, noticeably higher than the $4 and $20 for GPT-5.6 Sol, the company's previous strongest model.

On ExploitBench, a benchmark measuring the ability to independently exploit security vulnerabilities, Astra scores 100% against 78.5% for Sol. That's the exact capability that triggered the pause a month earlier. On OSWorld 2.0, a computer-use test, the score is 72.6% against Sol's 65.7%, at roughly 47% less time per task. On FrontierMath Tier 4, the hardest tier of research-level math problems, Astra posts 97.6% against Sol's 83%.

The number the whole "AGI era" rests on comes with fine print

The headline result OpenAI showed as evidence of crossing the AGI threshold was 99.9% on ARC-AGI-3, a benchmark measuring general reasoning on novel tasks. That score, though, comes from a test run on provider-specific infrastructure that preserves the model's reasoning state between actions. Under the standard, neutral test environment, without that advantage, Astra's score drops to 62.7%, at far higher compute cost for the same task. Thirty-seven percentage points of difference between the number from the press conference and the number under neutral conditions is exactly the kind of detail that disappears from headlines but decides whether "the AGI era" describes reality or describes marketing copy.

The benchmark's own creator won't back the claim

The sharpest pushback came from the organization behind ARC-AGI-3 itself. ARC Prize, the benchmark's creator, the one OpenAI built its AGI claim on, flatly declined to confirm that reading: nobody involved in building the test, including its own authors, is claiming Astra meets the definition of artificial general intelligence. Toby Walsh, chief scientist at the University of New South Wales' AI Institute, went further, saying he'd eat his own hat if Astra didn't trip up on trivial tasks an eight-year-old handles without effort. Rebecca Johnson of the University of Sydney added that OpenAI's own definitions of AGI expose the weaknesses behind this claim once you actually hold Astra up against them.

The launch also landed in the middle of an unusually packed week for the whole industry. On Tuesday, Anthropic showed off Fable 5.1 and Mythos 5.1. On Wednesday, Meta announced Muse Spark 1.3 and Google unveiled Gemini 3.8 Flash. Thursday's Astra closed out a run of four major launches from four different labs in five days. Trade press has already started calling this "model fatigue": the pace of updates is disorienting even companies buying access in bulk, and more than 1,100 AI lab employees separately signed a petition to Washington asking for frontier model development to slow down. In a week like that, "the AGI era" doubles as a way to cut through a flood of competing announcements.

Daybreak Access: the same logic as Anthropic's, under a different name

Astra's strongest cybersecurity capabilities remain available only through the Daybreak Access program, limited at launch to a narrow set of organizations. OpenAI says it plans to expand access gradually, eventually with lighter safeguards, covering vulnerability and proof-of-concept validation, malware analysis and detection engineering. Regular ChatGPT Plus, Pro, Business and Enterprise users were told they'd get access to Astra itself "in the coming days" after launch, not immediately.

That architecture, a public model plus a separate, controlled program gating the riskiest capabilities, is exactly the same solution Anthropic landed on two days earlier with Claude Fable 5.1 and Mythos 5.1. Two competing companies, 48 hours apart, published nearly identical answers to the same question: what to do with a model that can break security better than most humans. The difference is cosmetic: Anthropic built a formal verification program jointly with the US government, while OpenAI is keeping Daybreak Access in-house for now, with no disclosed institutional partner.

A launch that briefly contradicted itself

The launch moment itself was chaotic. OpenAI's launch materials hit the web before the model's official page even worked, so reporters at Reuters, CNBC and other outlets were quoting a post the company briefly pulled down in the middle of its own launch. The page came back a few dozen minutes later. It's a small incident, but it captures how blurry the word "launch" has become in AI: a model can exist in several states at once, some journalists get it under embargo, some companies get early access, and the official announcement disappears and reappears before anyone can fully track it.

The thirty-seven-point gap between the ARC-AGI-3 score from the press conference and the score under neutral conditions is a fact that should have made every "AGI era" headline and instead landed in a footnote. I'm not arguing Astra isn't a real jump in capability, since a 100% on ExploitBench and 97.6% on FrontierMath are concrete, hard-to-fake numbers. I'm arguing the company chose to show the world the result from the most favorable possible test conditions, not the one users will actually get.

More interesting than the model itself is the pattern that just settled across the whole industry: once a model crosses the line into autonomous cyberattack territory, a company no longer tries to hide it or pretend it isn't an issue. It builds a separate, controlled access channel and gives it a name. OpenAI landing on Daybreak Access and Anthropic landing on the Cyber Verification Program within 48 hours of each other, independently, suggests a real response to how fast these systems' capabilities are growing, not just one company's marketing choice.

For the average ChatGPT Plus user, all of this comes down to one thing: you get a more powerful, pricier model for coding and research, but you don't get, and probably won't get for a while, the specific capability that made OpenAI pause the launch a month ago. That's a reasonable call by the company. Calling it "the AGI era" at the same time, on the back of a number that loses thirty-seven points under normal conditions, isn't.

Comments

Discussion

Join the conversation around this story.

0 entries

Join the discussion

Sign in to comment and reply to other readers.

Sign in

No comments yet

Start the discussion first.

Read next

All posts