GPT-6 Astra shipped on September 3, and it arrived with an asterisk no model has carried before: it is the first model OpenAI has ever rated Critical for cybersecurity, because it can find zero-day vulnerabilities in hardened systems and turn them into working exploits without a human guiding it. The rest of the model is generally available. That specific capability is not, it ships gated, behind split access rather than open to everyone. That decision is a precedent, and if you defend infrastructure for a living, it is worth understanding what it does and does not protect you from.
What "gated capability" actually means
Normally a model ships and everything it can do ships with it. Astra breaks that pattern: OpenAI decoupled the dangerous capability from the general release. You can use GPT-6 Astra; you cannot casually ask it to weaponize a zero-day, because that path is restricted to vetted, controlled access.
This is a genuinely new governance shape. It says the capability is real enough that open release was judged too dangerous, but useful enough (to defenders, researchers, governments) that it should exist under control rather than not at all. It is the AI equivalent of a dual-use technology being export-controlled instead of either banned or sold freely.







