Skip to content

Enterprise software, read for what it costs and who signs for it.

OpenAI says its new model can break into hardened systems. AWS now sells it.

ERP LEADERS desk ·
Video: OpenAI, official YouTube channel, 04 Sep 2026

CSO Online reported that GPT-6 Astra is the first model OpenAI has placed in the Critical cybersecurity tier of its Preparedness Framework. That tier covers models capable of exploiting previously unknown flaws.

Astra shipped on 4 September and scored 100% on ExploitBench, up from 78.5% for GPT-5.6 Sol. AWS announced general availability through Amazon Bedrock yesterday.

OpenAI says the released model is restricted to secure code review and patching, and refuses prompts asking it to write exploits. In ChatGPT for business, an administrator must enable it.

In OpenAI's developer launch an engineer gave Astra control of his screen and the model operated the applications itself. OpenAI ran that sequence at 28 times speed.

The risk changes once Astra receives an SAP identity, API access and permission to alter production. Those controls sit with the enterprise.

Greyhound Research's Sanchit Vir Gogia told CSO Online: “OpenAI being able to monitor Astra does not mean an enterprise can audit Astra.”

🎥 Video: OpenAI, official YouTube channel, 4 Sep 2026. Link in the first comment.

Who approves the SAP identity and enables the model?

What the captions say

  1. An OpenAI engineer hands his laptop to the model.
  2. This is GPT-6 Astra, released on 4 September.
  3. It edits the illustration itself, sped up 28 times.
  4. OpenAI rates it Critical for cyber capability, a first.
  5. OpenAI reports 100 percent on ExploitBench, up from 78.5.
  6. The shipped version refuses to write proof-of-concept exploits.
  7. AWS made it generally available on Bedrock yesterday.
  8. Enterprise access stays off until an admin turns it on.

Sources

More video reports