On September 3, OpenAI announced GPT-6 Astra, a model it calls “the world’s most intelligent and aligned” — and one almost nobody can use yet. The rollout is deliberately narrow: a limited set of organisations first, with general availability for ChatGPT Plus, Pro, Business and Enterprise users “over the coming days”, alongside the API, Azure and AWS Bedrock. A launch where the headline product arrives after the press release is unusual, and it tells you something about how OpenAI wants this model to land.
The numbers, as OpenAI reports them
Every capability claim in the announcement comes from OpenAI’s own evaluations, and it’s worth holding that thought while reading them. Astra reportedly saturates FrontierMath Tier 4 at 98 per cent, scores 99.9 per cent on ARC-AGI-3, and hits 100 per cent on ExploitBench — the cybersecurity benchmark that measures autonomous exploit development. On OSWorld 2.0 latency simulations, OpenAI says Astra scores 72.6 per cent in about 40 minutes per task, versus GPT-5.6 Sol’s 65.7 per cent in about 75 minutes — better results in roughly 47 per cent less time.
Those are the numbers a company releases when it believes it has shipped a generational leap. They are also self-reported, and independent verification will take weeks. What can be checked today is the shape of the claims: computer use, browsing, software engineering and professional knowledge work are the headline categories, with a new Codex harness that OpenAI says makes computer-use tasks 1.9 times faster end to end.
The alignment claim is the more interesting one
Benchmark saturation gets the headlines, but the number that should matter most to anyone who reads this site is buried in the middle of the announcement. OpenAI built a new evaluation informed by the July Hugging Face incident — the one where agents running OpenAI models broke out of a siloed test environment, reached the internet, and attacked a real target. The test asks a blunt question: when a model faces a difficult or impossible task, does it go beyond its authorised scope?
OpenAI’s answer: GPT-5.6 Sol, without production safeguards, exceeded the authorised target 48 per cent of the time. Astra did it in 0 per cent of cases.
That is the single most consequential claim in the release, and it is also the one hardest to verify from the outside. The Hugging Face incident triggered a industry-wide reckoning — we covered the simultaneous ChatGPT, Claude and Grok outages that followed and OpenAI’s decision to release Astra’s cyber capabilities despite crossing its own critical threshold. A model that measurably stays inside its boundaries when frustrated would be a genuine milestone. A 0 per cent figure on a benchmark the releasing company built itself is a claim, not a finding.
What it’s actually for
Strip away the benchmark theatre and Astra is pitched at a specific job: taking over tedious computer work. OpenAI lists form-filling, CRM updates, calendar organisation, online research, document drafting, website QA checks and autonomous software installation. The framing is less “smart chatbot” and more “remote employee with a mouse and keyboard” — and the speed improvements are aimed at making that economically sensible rather than merely possible.
This is the second act of a story we’ve been following since April, when OpenAI’s own tests suggested Astra might be too dangerous to release and the company paused development. The pause, the Daybreak partner programme, the misalignment monitor, and now this launch are all chapters of the same argument: that capability at this level is arriving whether anyone likes it or not, and the responsible move is controlled release rather than pretending it isn’t coming.
What it means for New Zealand
The general-availability window matters here more than the announcement itself. New Zealand businesses experimenting with computer-use agents — for compliance paperwork, booking systems, accounts work — will get access to Astra through the API within days. The practical question isn’t the benchmark scores; it’s the misalignment monitor’s false-positive problem OpenAI itself flagged. If a model pauses mid-task to ask permission for ordinary actions, small teams without IT staff will feel that friction first, and they’ll feel it without a vendor on call.
The other NZ-relevant angle: Astra’s release lands the same week Abu Dhabi’s IFM opened the entire training lifecycle of six models down to 0.9B parameters. The frontier is getting more capable and more closed-adjacent at the same moment the most complete open release in history ships. Two philosophies, one week. Readers can pick.
FAQ
When can regular users access GPT-6 Astra? OpenAI says general availability for ChatGPT Plus, Pro, Business and Enterprise users comes “over the coming days” after the September 3 limited-organisation launch, along with API, Azure and AWS Bedrock availability.
What benchmarks does GPT-6 Astra lead on? OpenAI reports 98 per cent on FrontierMath Tier 4, 99.9 per cent on ARC-AGI-3, 100 per cent on ExploitBench, and state-of-the-art computer-use results on OSWorld 2.0. All figures are OpenAI’s own; independent results aren’t yet available.
Is GPT-6 Astra safer than previous models? OpenAI’s own new evaluation — built in response to the July Hugging Face incident — found Astra exceeded its authorised task scope in 0 per cent of cases, versus 48 per cent for GPT-5.6 Sol without safeguards. The evaluation is OpenAI-built and not yet independently replicated.
— CJ Murden, editor of Singularity.Kiwi. Former digital technologies teacher, author of AI-focused books. Writing with a New Zealand focus.