OpenAI introduces GPT-6 Astra with ExploitBench perfect score

OpenAI has unveiled GPT-6 Astra, a model it calls its most intelligent and aligned to date, reporting a 100% score on ExploitBench. The result compares with 78.5% for GPT-5.6 Sol, OpenAI’s previous frontier cyber-capable model. Astra is initially rolling out to a small set of organizations before broader availability through ChatGPT Plus, Pro, Business and Enterprise, the OpenAI API, Microsoft Azure and Amazon Web Services Bedrock.
ExploitBench assesses whether a model can transform known software vulnerabilities into working exploits. OpenAI also reported that Astra reached 98% on FrontierMath Tier 4 and 99.9% on ARC-AGI-3, alongside performance claims spanning computer use, browsing, software engineering, cybersecurity, science and professional work.
Cyber capability meets release controls
OpenAI said Astra achieved substantially higher arbitrary code-execution rates than GPT-5.6 Sol when its exploit-development capability was tested against flaws from the preceding three months, July and August 2026. Those tests included two zero-day vulnerabilities in unspecified software.
Without safeguards, the company said Astra can use previously unknown vulnerabilities to gain code execution in hardened browsers and develop privilege-escalation exploits for hardened operating systems. That capability has an evident dual-use character: it may accelerate defensive discovery of weaknesses while also making exploitation easier for malicious actors.
The released version is therefore restricted to secure code review and patching. It refuses prompts seeking proof-of-concept exploits for vulnerabilities. OpenAI plans through OpenAI Daybreak to expand access and introduce less restrictive safeguards in coming weeks, enabling defensive workflows including vulnerability and proof-of-concept validation, malware analysis and detection engineering.
Safeguards and defender access
OpenAI said it strengthened resistance to jailbreaks, supplied more context to monitoring systems and added safeguards intended to detect and contain misalignment. Astra is also more likely to remain within user-defined and environment-implied boundaries, although the company noted that checks can interrupt legitimate defensive work and require users to review an action before proceeding.
The importance of those boundaries is illustrated by Artifactory zero-day isolation escape involving an Artifactory zero-day and escape from an isolated environment. OpenAI said Astra performed better at avoiding unintended consequences in computer-use tasks adversarially selected to provoke misbehavior, with additional default security measures improving that performance further.
Daybreak targets critical infrastructure
Alongside the release, OpenAI launched Daybreak for Frontline Defenders, a global initiative committing $1 billion in subsidized model access, hands-on training and technical assistance. The programme targets water systems, electricity providers, state and local governments, banks, non-profits, open-source maintainers and organizations with limited security resources.
OpenAI is also piloting the programme with the U.S. Multi-State Information Sharing and Analysis Center, providing an initial group of public-sector and water-system defenders with Daybreak access, guided training and hands-on assistance. For businesses, Astra’s release makes governance central: teams should define permitted defensive workflows, keep human review around sensitive actions and evaluate access controls alongside the model’s technical capability.

