GPT-6 Astra Crossed the Cyber-Critical Threshold. Your Agent Architecture Must Change.

A frontier model that can find and exploit unknown vulnerabilities changes the engineering problem from “Which model is best?” to “What is this agent allowed to touch?”

OpenAI describes GPT-6 Astra as its first broadly deployed model to reach the Critical level for cybersecurity capability under the company’s Preparedness Framework. According to OpenAI, Astra can—given appropriate tools and access—find previously unknown security flaws and develop ways to exploit them across well-protected systems without continuous human guidance.

That is a vendor-reported capability assessment, not proof that every Astra session is an autonomous red team. The production model also refuses advanced offensive requests, and OpenAI says it has added stronger jailbreak resistance, monitoring, isolation, and alignment safeguards. Still, the threshold matters. It tells engineering teams that the old mental model—an assistant generating code inside a chat window—is no longer sufficient.

The relevant system is now the model, its tools, its credentials, its runtime, its network reach, and the approval rules connecting them.