News·7 min read

GPT-6 Astra Found 2 Zero-Days No Human Had Seen. OpenAI Just Called an AI Model 'Critical' for the First Time

Quick answer ✦OpenAI released GPT-6 Astra on September 3, 2026, and classified it as the first model to cross the 'Critical' threshold for cybersecurity capability under its own Preparedness Framework, per CSO Online's reporting. Tested without production safeguards, Astra scored 100% on ExploitBench, OpenAI's benchmark for turning a known vulnerability into a working exploit, up from 78.5% for its predecessor GPT-5.6 Sol, and it independently found two previously unknown zero-day vulnerabilities during evaluation, which OpenAI says it's now disclosing to the affected software makers, per The Hacker News. The version that reaches ordinary accounts blocks the offensive half of that capability: standard ChatGPT and API access can't be used to generate a working proof-of-concept exploit, per Bleeping Computer's reporting.

This isn't a hypothetical about what a future model might eventually do. OpenAI ran Astra against real, disclosed vulnerabilities and watched it write working exploit code for all of them, then watched it turn up two nobody had catalogued yet. That's the actual, already-happened event. Everything else here is about what changes because of it.

'Critical' is a specific rung on a ladder OpenAI built for itself years ago, not a marketing word bolted on at launch. Crossing it is supposed to trigger real deployment restrictions before a model reaches a normal account. This is the first time that ladder has actually been tested against a model OpenAI shipped.

100%

Astra's score on ExploitBench, turning known vulnerabilities into working exploits

up from 78.5% for GPT-5.6 Sol, its predecessor, per The Hacker News.

2

previously unknown zero-day vulnerabilities Astra found during pre-release testing

OpenAI is disclosing both to the vendors involved, per The Hacker News.

Sept 3, 2026

the day OpenAI classified a shipped model 'Critical' for cybersecurity for the first time

per CSO Online's reporting.

$10 / $50

Astra's API price per million input/output tokens, about 2.5x GPT-5.6 Sol's rate

per MindStudio's reporting on Astra's pricing and access tiers.

What 'Critical' actually restricts

Who you areWhat you can do with Astra
Free or Plus ChatGPT userChat and coding help work as normal. Generating a working proof-of-concept exploit for a real vulnerability is blocked, per Bleeping Computer.
Business or Enterprise adminAccess is off by default. An admin has to manually enable Astra for the workspace before anyone on the team can use it, per CSO Online.
Vetted org in OpenAI's Daybreak programBroader access for legitimate cybersecurity work, gated by an approval process rather than a subscription tier.
API developerSame $10 / $50 per-million-token model, with the same offensive-use restrictions enforced server-side rather than left to the developer.

Why a model that can hack you is also the model that patches you faster

The uncomfortable symmetry here is that the skill that finds a zero-day is the same skill that finds it defensively, before an attacker does. Shrinking the cost of vulnerability research cuts both ways: it shortens the window attackers get to weaponize a flaw, and it shortens the window defenders get to patch it first.

For a security team, that trade is genuinely useful, automated scanning that used to take a specialist days can now take a model hours. For an ordinary person with a phone and a laptop, the honest answer is that this fight was already happening below the surface. What changed on September 3 is that one side of it got measurably faster, and OpenAI is on record saying it expects the other side to follow.

What to actually do about it

  1. 1Keep automatic updates on for your OS, browser, and every app you use regularly. A faster vulnerability-discovery cycle makes a slow patch habit the most dangerous thing on your device.
  2. 2Treat a specific 'zero-day' headline, about your browser, your VPN client, your router firmware, as a same-day update, not an eventually.
  3. 3If you self-host any software, follow that project's own security advisories directly instead of waiting for a roundup to mention it. That's where a shortened patch window bites first.
What does 'Critical' mean under OpenAI's Preparedness Framework?

It's the highest cybersecurity capability tier OpenAI defines for its own models. Reaching it means the model can find and exploit unknown vulnerabilities in hardened systems without a person guiding each step, which is supposed to trigger extra deployment restrictions before public release.

Can a regular ChatGPT user get GPT-6 Astra to hack something?

OpenAI says the public version blocks generating proof-of-concept exploits and other offensive cyber tasks. Broader access is gated behind OpenAI's vetted Daybreak program, not available on a normal account.

Did GPT-6 Astra actually find real security flaws?

Yes. During pre-release testing it discovered two previously unknown zero-day vulnerabilities, which OpenAI says it's disclosing to the affected vendors.

How is Astra different from GPT-5.6 Sol on security tasks?

On ExploitBench, a benchmark for turning known, disclosed vulnerabilities into working exploits, Astra scored 100% versus 78.5% for GPT-5.6 Sol.

Does this affect me if I don't work in cybersecurity?

Indirectly. The practical effect is a faster race between vulnerability discovery and patching on both sides. Keeping your own software updated automatically is the one lever an individual actually controls.

Try the tools ✦

Free browser tools that never upload your files.

Open Tools