GPT-6 Astra shipped at OpenAI's Critical cyber threshold
OpenAI says GPT-6 Astra is the first model to reach its Critical cybersecurity threshold. The gate in front of it is a default setting the lab chose itself.
OpenAI put GPT-6 Astra into ChatGPT Work, Codex and the API at $10 per million input tokens and $50 per million output tokens, and said it is the first model to reach the Critical cybersecurity capability threshold under its Preparedness Framework. It scores 57.9% on Terminal-Bench 4.0 where GPT-5.6 Sol scored 37.3%. The control on the new capability, at launch, is that enterprise access is off by default.
Two months ago the control was a government. The ledger's record on OpenAI has the Trump administration lifting its restrictions on GPT-5.6 on 8 July, clearing a broad public launch after a cybersecurity-driven delay. The capability is a tier higher now. What stands in front of it is a default setting instead of a federal hold.
The capability is not hypothetical
Anthropic spent today publishing what the previous generation already did in the field. Between December 2025 and August 2026 it found state-linked and criminal groups using Claude to automate entire attack chains: a Russian-linked cluster it tracks as GTG-20006 had the model rewrite malware when it was detected and took more than 300,000 national ID records from a North African government, and a suspected Chinese exploit foundry, GTG-10007, surfaced over a dozen candidate zero-days in a single month by running parallel agent swarms.
The swarms are the part to hold onto, because two days earlier OpenAI opened a public beta of its Agents API, exposing the execution infrastructure behind Codex with session and context management, multi-agent configurations, tool calling and a choice of hosted or self-hosted sandboxes. Anthropic documents the pattern; the beta ships the plumbing for it, to everyone, two days before a model its own maker rates Critical arrives to sit on top.
Nobody has built the thing that would hold the switch
The governance answer on the table is voluntary and unfinished. Anthropic, OpenAI and Google have run a working group since July on an AI industry standards body and met again last week, with Sam Altman telling an OpenAI all-hands that he supports a testing and auditing organisation but that the labs must lead it rather than rely on the US government. The White House shelved a draft executive order for a FINRA-style self-regulator in late summer. Microsoft will publish a code of conduct for its MAI models for public consultation, its first behavioural standards for first-party models in document form, with Satya Nadella writing that governance must not be controlled by a handful of entities.
Every one of those is a document, a consultation or a meeting. None of them was in a position to say anything about today's launch.
What it lands on
The estate this capability points at is in its usual condition.
- Palo Alto Networks disclosed CVE-2026-0310, a PAN-OS buffer overflow rated 9.2 that lets an unauthenticated attacker run code as root on PA-Series hardware firewalls, with no workaround available.
- Adobe Commerce and Magento Open Source are being exploited through StyleSmuggler, an unauthenticated zero-day affecting every current version including 2.4.9, with no official patch.
- PostgreSQL patched CVE-2026-6471, a logical decoding flaw that has been in the code since version 9.4 in 2014.
- Google shipped Chrome 153 with fixes for 230 security issues, among them a V8 out-of-bounds write already exploited in the wild.
A dozen candidate zero-days a month is what the last generation of agents managed against estates like that one. The generation shipped today is twenty points better at driving a terminal, its maker has rated it Critical on exactly this axis, and the gate in front of it is a setting that maker chose.
Both readings of that are available and the ledger does not have to pick. A lab that publishes its own threshold, names the tier, and ships with the switch off is doing more disclosure than anyone required of it. It is also the only party in the room holding the switch.
Built from the digest of 2026-09-15.