When OpenAI released GPT-6 Astra on September 3, its president Greg Brockman said something I did not expect. He suggested that anyone who feels we have entered the artificial general intelligence (AGI) era is not being unreasonable. The Guardian ran the story under the headline declaring that OpenAI was hailing a new era of AGI, and the internet has spent the week since repeating it. Before we argue about the AGI label and whether it truly is an "irrelevant marketing term" as Sam Altman put it, it is worth looking at what Astra can actually do.
What is new, and what is startling
The most important thing about Astra is that it does not need to be plugged into anything. It operates software the way a person does, by reading the screen, moving the cursor, and typing, which means it can work in the internal tools nobody ever built a connector for.
It is also considerably faster than previous models. OpenAI reports Astra finishing an average computer task in around 40 minutes where the previous model needed 75 minutes, roughly twice the throughput across a working day. In one demonstration it took an electronic schematic and laid out a printed circuit board in under three minutes, a job normally done by hand. On tasks drawn from real professional work, it scored 41.4% against the older model's 18.1%.
Then there are the two results presented on OpenAI's GPT-6 Astra landing page that made me stop and read them twice. There is a family of tests built so that a model cannot have memorized anything, because every puzzle in them is new, and Astra scored 99.9% on the latest one while beating the human efficiency baseline. It also contributed to two new mathematical results about the gaps between prime numbers, one of which improved a limit untouched for more than 80 years, with the proofs published. Call it whatever you like, but producing knowledge that did not previously exist is not autocomplete.
The security findings are the most consequential part of the launch and they have been badly under-reported. OpenAI has given Astra a Critical rating for cybersecurity capability, the first model it has placed in that band. This means it can find security holes nobody knew were there and work out how to get through them without a human guiding each step. On a test of whether it could turn a known software flaw into a working attack, it scored 100%.
What happened during testing is more striking than the score. Astra found two security flaws that nobody had documented anywhere, and OpenAI is now reporting both to the people who maintain that software. Independent expert testing of the model without its production safeguards found it could break into hardened web browsers and build tools to escalate privileges on hardened operating systems. These are capabilities from a commercial product you can reach through an API this week.
AGI was always going to arrive as a feeling first
I have been skeptical about the AGI talk for years, mostly because the definition seems to move every time the industry gets close to it. But something shifted for me while reading about this launch.
Every AI system up to now has essentially been an oracle: You ask it a question, it gives you an answer, and then you go and do the work yourself. Astra is doing the work. The gap between a system that explains how to lay out a circuit board and one that actually lays it out is a change of category rather than an incremental improvement.
Moreover, without any retraining in between, the same model laid out that circuit board, formatted a legal document, inspected genetic sequencing data, reviewed code for security flaws, and contributed to open problems in number theory. That's the "general" in AGI doing heavy work, and a different proposition from what we had before, when models were wide but got shallow the moment you asked for depth.
What convinced me that we have crossed into AGI territory though, was how it behaves. OpenAI describes Astra filling in routine gaps by itself, asking a question only when the answer would change the outcome, and holding onto its original instructions even after mid-job correction. In its coding tool it will put a question to the user and carry on with the parts that do not depend on their answer, which is not really how software behaves so much as how a good colleague behaves.
Others testing it are landing in the same place. The Astra landing page quotes Harvey, a software company that builds AI for law firms, saying that Astra approaches legal work the way a discerning lawyer does, separating documents from established records and surfacing assumptions nobody had supported.
Is this AGI by somebody's formal definition? Probably not, and I have stopped finding that argument useful. Astra is not top of every leaderboard and the rankings feel like the least interesting thing anyone could say about it. What matters is that the threshold people spent a decade describing—the point at which AI starts doing the work instead of describing it—has been crossed in a product you can buy today.
Why IT leaders should be watching
Now, whatever you decide to call it—AGI or not—three things have changed for the people who run your systems:
An agent that clicks through your systems has to log in as somebody. Skipping the connector work sounds like good news right up until you ask whose credentials the agent is using, what it is permitted to reach, and where the record of everything it did is being written. That is an identity and logging question for IT to answer.
It records less of its reasoning than the model before it. OpenAI states that its own tests found Astra's reasoning harder to follow than its predecessor's, because it now does more of its thinking without putting it on the page, which leaves you with more capability and a thinner paper trail. The company also warns that its safety checks can slow, pause, or stop legitimate work. In practice, this means the chat products will ask you to approve an action before it continues, and through the API the job simply stops. Anything built to run unattended has to be designed with this in mind.
Access stays switched off until an administrator turns it on. An enterprise administrator has to enable Astra for the workspace, and the default at launch is off. Sanchit Vir Gogia of Greyhound Research put it in a way I have not been able to shake: "Admin opt-in is not a safety certificate." In effect, this default shifts responsibility from OpenAI to the company that turns it on. Vir Gogia also points out that the workspace switch does not cover API access, where the only controls are the ones you built yourself.
Nobody has decided who owns the decision to enable Astra
Every previous wave of enterprise technology gave you time to work out governance after the fact, with a comfortable gap between adoption and accountability. This one shipped with the decision already in your hands, on day one, with no grace period and no committee convened to think about it.
This is a model that its own maker rates Critical for cybersecurity capability. It can operate your systems by hand. It's harder to audit than the version it replaces. And it's sitting behind a switch inside your organization right now, and somebody can flip it today. In most of the companies I have spoken to this month, nobody has agreed who that person should be or what they are supposed to check first.
The AGI question will be settled by historians, and they can take their time over it. The question of who in your company was allowed to say yes might be settled by an auditor, and a great deal sooner than that.
Frequently asked questions
What is GPT-6 Astra?
OpenAI released GPT-6 Astra on Sept. 3, 2026, and it is now the company's flagship AI model. What separates it from earlier models is that it can operate software directly (reading the screen and using a cursor and keyboard the way a person would) instead of needing a custom integration to reach your systems.
Is GPT-6 Astra AGI?
Not by any agreed definition, and OpenAI has stopped short of claiming it. Its president Greg Brockman said only that anyone who feels we have entered the AGI era is not being unreasonable. What has changed in practice is that Astra completes work rather than explaining to a human user how to do it, which is the shift most people had in mind when they talked about AGI arriving.
What does OpenAI's Critical cybersecurity rating mean?
Critical is the highest cybersecurity rating in OpenAI's own risk framework, and Astra is the first model the company has placed there. The rating means Astra can find security flaws nobody has documented and work out how to exploit them without a human guiding each step. The version enterprises can use today is limited to defensive work such as code review and patching.
How do enterprises get access to Astra, and what does it cost?
Astra is switched off for enterprise workspaces at launch, so an administrator has to enable it before anyone in the organization can use it. Once enabled, it is available across the paid ChatGPT plans and through the OpenAI API, Microsoft Azure, and AWS Bedrock. API pricing is $10 per million input tokens and $50 per million output tokens.
What should IT and security teams check before enabling Astra?
The first question is who in the organization is authorized to turn it on and what they need to confirm beforehand, because the default setting puts that decision with the user rather than OpenAI. After that, the practical checks are which credentials an agent uses when it operates internal systems, what those credentials can reach, and where its actions are logged.
Related reading:
- 6 shadow AI risks that could lead to compliance issues
- AI agents and the future of human-machine collaboration
- GPT-5 capabilities in 2026: Coding, health, and reasoning gains explained
- The urgency of AI regulation: Biden's bold move explained
- Why every SOC needs agentic AI to survive the 2026 alert crisis



