GPT-6 Astra Found 2 Zero-Days No Human Had Seen. OpenAI Just Called an AI Model 'Critical' for the First Time
This isn't a hypothetical about what a future model might eventually do. OpenAI ran Astra against real, disclosed vulnerabilities and watched it write working exploit code for all of them, then watched it turn up two nobody had catalogued yet. That's the actual, already-happened event. Everything else here is about what changes because of it.
'Critical' is a specific rung on a ladder OpenAI built for itself years ago, not a marketing word bolted on at launch. Crossing it is supposed to trigger real deployment restrictions before a model reaches a normal account. This is the first time that ladder has actually been tested against a model OpenAI shipped.
100%
Astra's score on ExploitBench, turning known vulnerabilities into working exploits
up from 78.5% for GPT-5.6 Sol, its predecessor, per The Hacker News.
2
previously unknown zero-day vulnerabilities Astra found during pre-release testing
OpenAI is disclosing both to the vendors involved, per The Hacker News.
Sept 3, 2026
the day OpenAI classified a shipped model 'Critical' for cybersecurity for the first time
$10 / $50
Astra's API price per million input/output tokens, about 2.5x GPT-5.6 Sol's rate
per MindStudio's reporting on Astra's pricing and access tiers.
What 'Critical' actually restricts
| Who you are | What you can do with Astra |
|---|---|
| Free or Plus ChatGPT user | Chat and coding help work as normal. Generating a working proof-of-concept exploit for a real vulnerability is blocked, per Bleeping Computer. |
| Business or Enterprise admin | Access is off by default. An admin has to manually enable Astra for the workspace before anyone on the team can use it, per CSO Online. |
| Vetted org in OpenAI's Daybreak program | Broader access for legitimate cybersecurity work, gated by an approval process rather than a subscription tier. |
| API developer | Same $10 / $50 per-million-token model, with the same offensive-use restrictions enforced server-side rather than left to the developer. |
Why a model that can hack you is also the model that patches you faster
The uncomfortable symmetry here is that the skill that finds a zero-day is the same skill that finds it defensively, before an attacker does. Shrinking the cost of vulnerability research cuts both ways: it shortens the window attackers get to weaponize a flaw, and it shortens the window defenders get to patch it first.
For a security team, that trade is genuinely useful, automated scanning that used to take a specialist days can now take a model hours. For an ordinary person with a phone and a laptop, the honest answer is that this fight was already happening below the surface. What changed on September 3 is that one side of it got measurably faster, and OpenAI is on record saying it expects the other side to follow.
What to actually do about it
- 1Keep automatic updates on for your OS, browser, and every app you use regularly. A faster vulnerability-discovery cycle makes a slow patch habit the most dangerous thing on your device.
- 2Treat a specific 'zero-day' headline, about your browser, your VPN client, your router firmware, as a same-day update, not an eventually.
- 3If you self-host any software, follow that project's own security advisories directly instead of waiting for a roundup to mention it. That's where a shortened patch window bites first.
What does 'Critical' mean under OpenAI's Preparedness Framework?
It's the highest cybersecurity capability tier OpenAI defines for its own models. Reaching it means the model can find and exploit unknown vulnerabilities in hardened systems without a person guiding each step, which is supposed to trigger extra deployment restrictions before public release.
Can a regular ChatGPT user get GPT-6 Astra to hack something?
OpenAI says the public version blocks generating proof-of-concept exploits and other offensive cyber tasks. Broader access is gated behind OpenAI's vetted Daybreak program, not available on a normal account.
Did GPT-6 Astra actually find real security flaws?
Yes. During pre-release testing it discovered two previously unknown zero-day vulnerabilities, which OpenAI says it's disclosing to the affected vendors.
How is Astra different from GPT-5.6 Sol on security tasks?
On ExploitBench, a benchmark for turning known, disclosed vulnerabilities into working exploits, Astra scored 100% versus 78.5% for GPT-5.6 Sol.
Does this affect me if I don't work in cybersecurity?
Indirectly. The practical effect is a faster race between vulnerability discovery and patching on both sides. Keeping your own software updated automatically is the one lever an individual actually controls.
Try the tools ✦
Free browser tools that never upload your files.
