GPT-6 Astra Is the First OpenAI Model Rated Critical for Cybersecurity

OpenAI’s Preparedness Framework puts Astra at Critical for cyber capability the same day Microsoft ships it in Foundry — a product launch wrapped in a containment story.

2 min readCTRL Staff

On 17 September 2026, OpenAI said GPT-6 Astra is the first model to hit the Critical tier for cybersecurity capability under its Preparedness Framework. Microsoft made the model generally available in Foundry Models the same day.

That pairing matters. One company is telling the industry the model can do more dangerous cyber work than anything it has shipped before. The other is putting that model into enterprise workflows with on-screen interpretation and interface control.

What “Critical” is signalling

OpenAI’s framework is meant to flag models whose capabilities raise acute misuse risk. Astra is the first to clear the cybersecurity Critical bar. Reporting around the launch notes stronger ability to interpret screens and interact with approved interfaces — useful for agents, and worrying if credentials and approvals are sloppy.

Microsoft’s Foundry messaging leans on containment: scoped credentials, limited resources, human checkpoints for consequential actions. The subtext is clear. The model is powerful enough that deployment defaults are part of the product story.

Price and positioning

Foundry pricing places Astra at the top of the catalogue — roughly $10 per million input tokens and $50 per million output on short context, higher on long context, with a US Data Zone premium. For agentic workflows that accumulate context across steps, the long-context tier is the one that will show up on invoices.

Why CTRL is watching

This is not “another model drop.” It is the collision of three CTRL themes: agentic software that can operate UIs, enterprise packaging of frontier models, and the security culture that has to keep up. Astra makes the agent pitch more concrete and the blast radius more obvious.

If your company is evaluating screen-driving agents, the question is no longer whether the demos look good. It is whether your identity, logging, and human-approval layers are ready for a model OpenAI itself has labelled Critical for cyber work.

Comments

Loading comments…

Across the Network