OpenAI released GPT-6 Astra on September 3, calling it "the world's most intelligent and aligned model." Buried inside that announcement is a more consequential fact: Astra is the first model OpenAI has ever classified as meeting the Critical threshold on its Preparedness Framework for cybersecurity, a designation that means the model can find previously unknown security flaws and turn them into working exploits across well-defended systems, largely on its own.
What crossing "Critical" actually means
OpenAI's Preparedness Framework defines the Critical cybersecurity threshold as the point at which a system can independently find and develop functional zero-day exploits across a broad range of hardened systems, or plan and execute a novel cyberattack strategy from little more than a high-level instruction. Astra hit a perfect score on ExploitBench and, in a separate evaluation using more recently disclosed vulnerabilities, discovered and used two zero-days on its own, without a person pointing it at the flaw first. In testing, it also broke out of a browser sandbox to run commands on the underlying machine and chained several flaws in a hardened operating system to reach root-level access.
Previous models needed a person to identify a vulnerability and ask the model to explain or extend it. OpenAI says Astra can start from nothing, locate the flaw, build a working exploit, and get in, without being told where to look. That's the capability the Critical designation exists to gate.
The same model also solved 10 decade-old math problems, with formal proofs
Before today's public release, an internal version of Astra produced new results on 10 problems in mathematics and theoretical computer science that had sat unsolved for at least a decade. OpenAI published a 249-page manuscript and formal, machine-checkable Lean 4 proofs on GitHub under an open license, the repository's "sorry count" sits at zero, meaning no step in any of the 10 formalized proofs was left unproven. Total token cost for all 10 solutions: roughly $2,000. The headline result is an explicit construction proving the existence of non-sofic groups, open since 1999, alongside a disproof of a 1980 rigidity conjecture by Alain Connes and three solved problems from Paul Erdős's catalog.
Since that announcement, one endorsement stands out from the general reaction. Fields Medalist Timothy Gowers has said he would recommend one of the results for publication in the Annals of Mathematics without hesitation, a specific, credentialed judgment that carries more weight than a benchmark score. Worth pairing with the earlier caution this site has already raised: OpenAI's former VP of Science made a similar, less rigorous claim in 2025 that turned out to be overstated. This result is held to a higher bar, independently verifiable proofs rather than an assertion, and the field's response so far reflects that difference.
What this means now
Nothing about Astra's strongest cyber capability is available to a general user today, and that's by design, not accident. The practical takeaway for a business reader isn't "go use this," it's that the gap between what a frontier model can do in a lab and what a defender or attacker can actually deploy is now something labs are explicitly gating and disclosing, rather than leaving to be discovered after the fact. That's a genuinely different posture than most of what's been covered in this space, and it's worth watching whether Daybreak-style gated access becomes the standard pattern for the next capability jump, or whether this one proves to be the exception.
Put This Into Practice
Whatever ships next, the pattern that matters for automation today is unchanged: Draft with AI, verify independently, and only trust what's been checked, not what's been announced. WorkplaceAI kits are built the same way.
Browse All Guides → Unvarnished Reviews →Sources: AI Pulse · At the AI Cutting Edge · workplaceai.ai. GPT-6 Astra's release, its Critical cybersecurity designation, and the specific benchmark and zero-day figures: Unite.AI, September 3, 2026; The Hacker News, September 4, 2026; SecurityWeek, September 2, 2026; Decrypt, September 3, 2026; MarkTechPost, September 3, 2026; CyberPress, September 4, 2026. The Daybreak program and staged rollout: Decrypt and MarkTechPost, same reporting. Astra's math results, its Lean 4 proof verification, and Timothy Gowers' endorsement: SiliconANGLE, August 2, 2026; QZ, August 3, 2026; NextMSC, August 2026. The Kevin Weil/Erdős problems precedent referenced for comparison: previously reported by SiliconANGLE. Every figure above is attributed to its original reporting; none is a WorkplaceAI study.