OpenAI turned on GPT-6 Astra for the first wave of users on September 3, 2026, and by September 8 the rollout has widened enough that most developers and enterprise subscribers are asking the same question: how do I actually get access. The company’s own safety overview calls it “the most capable model we have ever broadly deployed,” a claim that comes with an unusual asterisk (OpenAI safety overview): Astra is the first OpenAI model to reach the “Critical” tier of cybersecurity capability under the company’s Preparedness Framework.

That combination, a mainstream product launch paired with a high-stakes safety label, is why this release is getting more scrutiny than a typical model refresh. Astra is not just faster or cheaper than GPT-5-era models. It is being shipped with a gated access structure normally reserved for research previews, even as OpenAI pushes it into ChatGPT Plus, Pro, Business, and Enterprise plans, the OpenAI API, Microsoft Azure, and AWS Bedrock. This piece breaks down what shipped, who gets it first, what it costs, how it compares with rival frontier models, and what to watch as the rollout continues through September.

What OpenAI Shipped on September 3

GPT-6 Astra is the flagship entry in a broader Astra model family that OpenAI has been building out alongside smaller siblings referenced internally as Sol, Terra, and Luna. OpenAI’s launch post frames Astra as a general-purpose successor to its GPT-5 line, not a narrow coding or reasoning tool. The API model identifier developers will call is gpt-6-astra, confirmed in OpenAI’s own documentation and repeated across early developer write-ups.

According to OpenAI’s launch announcement, the rollout plan was explicit from day one: “GPT‑6 Astra is rolling out today to a limited set of organizations and over the coming days will become available to all ChatGPT Plus, Pro, Business, and Enterprise users, as well as through the OpenAI API, Microsoft Azure, and AWS Bedrock” (OpenAI, GPT-6 Astra launch post). That staged approach is the reason some paying subscribers saw the model appear in their ChatGPT interface on September 3 while others are still waiting days later.

The launch follows a pattern the site has tracked closely this year. OpenAI’s Astra rollout initially shipped with an exploit benchmark score that drew attention on its own, a story covered in OpenAI’s Astra Ships With 100% Exploit Score. What changed by September is that the model has moved from a narrow security-testing preview into a mainstream commercial product, with real pricing, real availability windows, and a real customer base beyond OpenAI’s cybersecurity partners.

How to Try GPT-6 Astra Right Now

The fastest path into GPT-6 Astra depends on whether you’re a consumer subscriber or a developer building on the API. Both routes are active, but neither is universal yet, and OpenAI has been clear that free-tier and lowest-cost paid accounts are excluded from the initial wave.

ChatGPT Plus, Pro, Business and Enterprise

If you already pay for ChatGPT Plus, Pro, Business, or Enterprise, GPT-6 Astra is added to your existing plan rather than sold as a separate add-on. OpenAI’s launch post states plainly that “Astra usage is included within the existing subscription allowances, users and businesses will also be able to purchase credits for additional usage” (OpenAI, GPT-6 Astra launch post). In practice, that means opening ChatGPT on the web or in the iOS and Android apps and checking the model picker. If Astra isn’t listed yet, the account simply hasn’t been reached by the staged rollout, and OpenAI has said general availability follows within days of the initial release rather than weeks.

Developers: the OpenAI API, Azure and AWS Bedrock

Developers reach Astra by calling the model ID gpt-6-astra through the standard OpenAI API, or through the two cloud partners OpenAI named at launch. Microsoft’s Azure OpenAI Service and Amazon’s AWS Bedrock are both listed as first-wave surfaces, which matters for regulated industries that already run their AI workloads inside Azure or AWS for compliance reasons rather than routing through OpenAI directly. That dual-cloud strategy is consistent with how OpenAI handled earlier GPT-5-era releases, and it gives enterprise buyers a way to adopt Astra without renegotiating a separate vendor contract with OpenAI.

What GPT-6 Astra Costs

OpenAI published API pricing alongside the launch, and it lands well above the GPT-5 generation on a per-token basis, reflecting the added compute behind Astra’s reasoning and cybersecurity capabilities. The company’s own pricing line is direct: “OpenAI API Standard pricing is $10 per million input tokens and $50 per million output tokens” (OpenAI, GPT-6 Astra launch post). For teams that need lower latency, there’s a faster tier at a premium. OpenAI describes it this way: “Fast mode is available for GPT‑6 Astra in the API and delivers up to 2x the speed of Standard processing at 2x the Standard price” (OpenAI, GPT-6 Astra launch post).

Pricing TierRateNotes
Standard input$10 / million tokensBase rate for prompt tokens
Cached input$1 / million tokensRepeated context reused across calls
Cache write$12.50 / million tokensCost to populate the cache
Standard output$50 / million tokensBase rate for generated tokens
Fast mode2x standard rateUp to 2x processing speed
Batch / Flex~50% of standardAsynchronous, non-urgent workloads

For context, requests that push past roughly 272,000 input tokens are billed at 2x the input and cache rate and 1.5x the output rate, according to developer documentation summarizing the launch briefing. ChatGPT subscribers don’t see per-token pricing directly since Astra usage draws from existing plan allowances, but heavy users on Plus or Pro should expect to hit rate limits sooner than they did on GPT-5, simply because Astra’s responses tend to run longer and consume more output tokens per query.

The Daybreak Access Program and Who Got It First

Before Astra reached a single paying consumer, OpenAI had already been running it through a gated cybersecurity testing track called Daybreak Access, with an additional restricted channel referred to as Daybreak Blue for the model’s most sensitive offensive and defensive cyber capabilities. That program is why security vendors and select enterprise customers were using Astra weeks before the public saw the September 3 launch post. It’s also the mechanism OpenAI is using to keep the model’s sharpest cybersecurity capabilities away from the general public while still letting Plus and Pro subscribers use the same underlying model for coding, writing, and everyday reasoning tasks.

The distinction matters because it splits Astra into two effective products: a broadly available general-purpose assistant, and a narrower, vetted cybersecurity tool sitting behind Daybreak’s access controls. OpenAI has not published exact headcounts for the Daybreak cohort, so treat any specific number you see elsewhere as unverified. What is confirmed is that free-tier ChatGPT users and the cheapest paid plan are excluded from Astra entirely at launch, a restriction OpenAI has tied directly to the model’s Preparedness Framework classification.

Why the “Critical” Label Is the Real Story

The headline spec isn’t a benchmark score, it’s a safety classification. Astra is the first OpenAI model to be rated Critical on cybersecurity capability under the company’s own Preparedness Framework, the internal system OpenAI uses to decide how much a model can do before extra safeguards kick in. Shattered.io covered the immediate fallout when that classification triggered a temporary pause in OpenAI Astra Hits Critical Cyber Risk, 2-Week Pause, and the ripple effects across the industry in OpenAI Astra’s Critical Label: How 4 Rivals Compare.

What’s changed since then is that OpenAI has moved from pause to controlled release. The company frames its own launch in stark terms, stating in the safety overview: “Today, we are releasing GPT‑6 Astra, the most capable model we have ever broadly deployed” (OpenAI, safety overview). Pairing that statement with a Critical rating is a deliberate signal. OpenAI wants credit for shipping its strongest model while also showing regulators and security researchers that it’s applying the access controls its own framework calls for. Whether that balance holds up under real-world use, including in the hands of Daybreak-approved red teams, is the open question the rest of 2026 will answer.

A Short History of OpenAI’s Preparedness Framework

OpenAI’s Preparedness Framework approach sits within a broader industry shift toward structured AI risk categories, a shift that gained momentum after NIST published its AI Risk Management Framework and frontier labs began adopting similar tiered systems. Earlier GPT-5-era models were evaluated under the same framework without triggering a Critical rating in the cybersecurity category, which is what makes Astra’s classification a first rather than a continuation. Anthropic paused a set of Claude cybersecurity tests around the same period, reported in Anthropic Halts Claude Tests After 3 Firms Breached, suggesting the entire frontier-lab cohort is recalibrating how it handles models capable of meaningful offensive security work, not just OpenAI in isolation.

That context matters for anyone deciding whether to adopt Astra now or wait. This isn’t the first time a frontier lab has shipped a model with elevated capabilities and extra guardrails, but it is the first time a Critical-rated model has gone to a mainstream ChatGPT subscriber base rather than staying confined to a research or enterprise-only preview.

How GPT-6 Astra Stacks Up Against Rival Models

Astra doesn’t launch into a vacuum. xAI shipped Grok 4.5 earlier this year at $2 per million input tokens and $6 per million output tokens, explicitly positioning it as a lower-cost challenger to OpenAI and Anthropic, a move covered in Grok 4.5 Launches at $2/$6 to Chase OpenAI, Anthropic. Astra’s $10/$50 standard pricing puts it roughly 5x to 8x more expensive per token than Grok 4.5, a gap OpenAI is betting customers will accept in exchange for Astra’s cybersecurity and reasoning capabilities.

ModelMakerStandard Input / Output PricingNotable Access Model
GPT-6 AstraOpenAI$10 / $50 per million tokensGated Daybreak cybersecurity access, broad consumer rollout for general use
Grok 4.5xAI$2 / $6 per million tokensOpen API access, positioned as a budget frontier option
Claude (Anthropic)AnthropicNot disclosed in this release cyclePaused a set of cybersecurity-focused tests following external breach reports
Gemini 3.8 FlashGoogleNot disclosed in this release cycleRuns a separate gated cybersecurity access track, Fairwind program

The comparison that matters most to enterprise buyers isn’t raw price, it’s access friction. Grok 4.5 ships without a gated cybersecurity tier, Astra ships with one, and Google’s Gemini models run their own separate controlled program. That divergence means procurement teams evaluating frontier models now have to weigh not just cost and capability, but how much internal security review each vendor’s access model demands before a team can actually start building.

Calling GPT-6 Astra From the API

For developers who already have OpenAI API access, switching a project to Astra is a one-line model change once the account has been granted access. A typical request looks like this:

curl https://api.openai.com/v1/chat/completions \
  -H "Authorization: Bearer $OPENAI_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "model": "gpt-6-astra",
    "messages": [
      {"role": "user", "content": "Summarize this incident report in three bullet points."}
    ]
  }'

Teams on Azure or AWS Bedrock call the same underlying model through their cloud provider’s SDK instead of hitting OpenAI’s endpoint directly, which keeps traffic inside the customer’s existing cloud boundary. That detail is what’s driving early adoption among regulated buyers, since it avoids a new third-party network path that a security team would otherwise need to separately review and approve.

Market and Competitive Impact

Astra’s launch lands at a moment when OpenAI’s infrastructure spending is already under a microscope, following reports the company has been buying Mac hardware at scale, detailed in OpenAI Buys 10,000s of Macs as RTX Spark Sells Out. Shipping a model that costs 5x to 8x more per token than a rival like Grok 4.5 only works commercially if enough enterprise and Plus/Pro customers see enough of a capability gap to justify it. Early signals suggest OpenAI is betting on that gap being real for coding, security, and long-context reasoning tasks specifically, not on Astra winning a general price-per-token comparison.

For Azure and AWS, hosting Astra strengthens their pitch to enterprise AI buyers who want frontier-model access without a direct OpenAI contract. Both cloud providers have leaned into this model over the past year, positioning themselves as neutral infrastructure for whichever lab’s model a customer prefers. Astra’s Critical safety rating actually reinforces that pitch: buyers who need SOC 2 or FedRAMP-adjacent controls are more likely to trust a model running inside Azure’s or AWS’s existing compliance boundary than one accessed through a standalone OpenAI account.

Risks, Safeguards and Open Questions

The Critical classification exists because Astra can reason about offensive and defensive cybersecurity tasks well enough that OpenAI decided broad, unrestricted access carried real risk. The company’s response has been to build safeguards into the rollout itself: staged access, a separate Daybreak track for the sharpest capabilities, and exclusion of free-tier accounts. What’s untested at scale is whether those safeguards hold once millions of Plus and Pro subscribers, not just vetted enterprise customers, are running general-purpose Astra queries every day.

There’s also a transparency question researchers have raised about frontier labs more broadly, not unique to OpenAI, covered in OpenAI Astra Fallout: 2 Rival Labs Weigh Opaque AI. As models get rated Critical under internal frameworks that outside researchers can’t fully audit, the industry is leaning on self-reported safety overviews rather than independent verification. That’s not a flaw unique to Astra, but it is a gap that becomes more visible every time a lab ships a model at this capability tier.

What Comes Next: 5 Predictions

  • Rival Critical disclosures follow. Expect at least one other frontier lab to publish its own Critical or equivalent-tier cybersecurity classification within the next two quarters, following the pattern Astra just set.
  • Fast mode pricing becomes standard. A 2x-speed, 2x-price tier is likely to show up in competing APIs within months, since it gives high-throughput customers a lever OpenAI’s flat pricing didn’t previously offer.
  • Free-tier access stays gated through 2026. Given the Critical rating, it’s unlikely OpenAI extends Astra to ChatGPT’s free plan before the year ends, unless a lighter, non-Critical variant is split out specifically for that tier.
  • Daybreak-style programs become an industry template. Other labs will likely formalize their own gated cybersecurity testing cohorts rather than relying on ad hoc NDAs with select customers.
  • Azure and AWS lean harder into neutral hosting. Both cloud providers will keep expanding multi-lab model catalogs, using Astra’s availability as proof they can host even a Critical-rated frontier model inside existing compliance boundaries.

Frequently Asked Questions

What is GPT-6 Astra?
It’s OpenAI’s newest general-purpose frontier model, released September 3, 2026, and described by OpenAI as the most capable model it has broadly deployed to date.

When did GPT-6 Astra launch?
OpenAI began rolling it out to a limited set of organizations on September 3, 2026, with wider access to ChatGPT Plus, Pro, Business, and Enterprise plans, plus the API, Azure, and AWS Bedrock, following in the days after.

How much does GPT-6 Astra cost through the API?
Standard API pricing is $10 per million input tokens and $50 per million output tokens, with cached input at $1 per million tokens and a Fast mode available at 2x the standard price for roughly 2x the speed.

Is GPT-6 Astra available on the ChatGPT free plan?
No. Astra is excluded from ChatGPT’s free tier and its cheapest paid plan at launch, with access starting at Plus and extending through Pro, Business, and Enterprise.

What does the “Critical” cybersecurity classification mean?
It’s the highest tier in OpenAI’s Preparedness Framework for cybersecurity capability, meaning the model can meaningfully assist with offensive or defensive cyber tasks. Astra is the first OpenAI model to reach that tier, which is why its most advanced cybersecurity capabilities are restricted to the vetted Daybreak Access program rather than opened to every subscriber.

Can I use GPT-6 Astra through Azure or AWS instead of OpenAI directly?
Yes. OpenAI named Microsoft Azure and AWS Bedrock as first-wave cloud surfaces for Astra, letting enterprise customers access the model inside their existing cloud compliance boundary.

What is the API model name for GPT-6 Astra?
Developers call it using the model identifier gpt-6-astra in API requests.

How does GPT-6 Astra’s pricing compare to Grok 4.5?
Astra’s standard rate of $10/$50 per million tokens runs roughly 5x to 8x higher than Grok 4.5’s $2/$6 per million tokens, reflecting OpenAI’s bet that Astra’s added reasoning and cybersecurity capability justifies a premium over xAI’s lower-cost frontier model.