
Summary
- OpenAI unveiled GPT-6 Astra in a YouTube video on September 3, saying it posted the best scores yet on long-horizon computer-use benchmarks and in software engineering.
- OpenAI called it the best-aligned model yet, citing improved honesty and reduced deceptive behavior — but the same model was also the first to be rated "critical" for cybersecurity risk under OpenAI's own framework, a finding disclosed two days earlier.
- Starting today, it rolls out first to enterprise and Trusted Access Program customers and to ChatGPT Work, with Codex, the API, and AWS following within days.
A model that operates your computer for you has arrived
OpenAI introduced GPT-6 Astra in a video posted to YouTube on September 3. The company called it "the smartest and most aligned model in the world," saying it posted the best scores yet on long-horizon, computer-use benchmarks spanning multiple professions and desktop apps. The pitch is that whatever can be done on a computer, Astra now does faster than a person would. OpenAI also said it's the best its models have ever been at software engineering.
To unpack that: in the safety card OpenAI published on September 1, Astra scored a perfect result on ExploitBench and demonstrated the ability to independently discover two zero-day vulnerabilities, which is what earned it a "critical" cybersecurity risk rating. Calling it the "best-aligned model" doesn't mean that risk has been resolved — it refers to a separate set of improvements around honesty and reduced deceptive behavior.
OpenAI also promoted Astra as its best-aligned model ever, with better honesty and less deceptive behavior. But what we reported on the same model two days earlier tells a somewhat different story.
Alignment gains and a safety rating: two sides of the same model
According to the safety card OpenAI released on September 1, Astra scored a perfect result on ExploitBench and, in self-modification testing, showed it could discover and exploit two zero-day vulnerabilities on its own. That made it the first model to cross the "critical" threshold for cybersecurity under OpenAI's Preparedness Framework. The honesty and deception improvements touted in this announcement sit on a separate axis from that cybersecurity risk. One measures whether the model deceives people; the other measures what systems the model can break into — so improving on one doesn't lower the risk rating on the other.
Scenes of Astra taking over the desktop
The launch video shows Astra handling a string of desktop tasks. A request to draw a yellow circle turns into a rocket window, which then gets built into a 3D model in Blender. Astra also puts together a sales presentation for a raincoat line's next season in a bright, playful tone. Asked to list an orange table bought years ago at a flea market on eBay, it finds a photo sitting in the downloads folder, attaches it, and even works a note about a small dent into the listing description. The same session goes on to string together more requests one after another: building an asteroid-dodging game controlled with arrow keys and a spacebar boost, reordering the beef bowl dish from last week, drafting a law firm's licensing agreement and narrowing the liability clause in the licensor's favor, booking a tennis court, and exporting the finished rocket model as an STL file for 3D printing.
The video also includes a "Put That There" clip credited to the MIT Media Lab, Chris Schmandt, and Eric Hulteen. It's a nod to an early natural-language interface demo that moved on-screen objects using only speech and gesture — a reminder that attempts to fuse voice and screen control go back decades.
How to get access
Access to Astra is staggered depending on which group of users you're in.
| Timing | Channel | Who gets it |
|---|---|---|
| Today (Sept 3) | Enterprise / Trusted Access Program | Priority-access customers |
| Starting today | ChatGPT Work | Broad rollout |
| Within days | Codex | Plus, Pro, Business, and Enterprise plans |
| Within days | API / AWS | API and AWS customers |
OpenAI recommends using the ChatGPT desktop app to get the full sense of what Astra can do. The desktop app is built to work alongside the screen and other apps, which lines up with Astra's ability to operate the computer on a user's behalf.
In practice, the scenarios from the video translate directly to work tasks. When drafting product materials, for instance, you can specify the tone and color scheme by voice while also handing off attaching files and inserting photos. Chores that normally require jumping between apps — finding and attaching a photo when listing a used item online, cleaning up a condition description, or picking out and adjusting a single contract clause — can all be handed over at once.
Editor's take
Throughout August, OpenAI laid the groundwork for Astra piece by piece, rolling out a computer-use history, a Work tutorial, and demos linking the computer and browser together. This announcement is the final piece of that rollout, and the most aggressive computer-use model OpenAI has shipped so far. The underlying structure — directly manipulating whatever's on screen, drafting across multiple apps, leaving the human only to give final approval — is the same skeleton ChatGPT Work already demonstrated. Astra just backs it up with top benchmark scores.
Set the alignment improvements next to the cybersecurity rating, though, and the picture reads differently. Deploying models of this size in real work tends to produce the same conclusion every time: as a model gets smarter, both what it can do and what it could do if misused grow together. Better honesty means the model lies to users less — it says nothing about whether the range of systems it can break into has shrunk. Any business planning to put Astra to work should evaluate those two claims separately, even though they arrived in the same announcement. Given that OpenAI has already flagged priority access for defensive partners and the possibility that normal tasks could get halted by false positives, it's safer to start with a narrow scope for auto-approval during early rollout.
Over the coming weeks, as the Codex and API channels open up, real-world reports from development teams should start accumulating. That's when it should become clearer which one actually drives the pace of adoption: the top computer-use benchmark score, or the "critical" safety label attached to it.





Comments