What changed
OpenAI has published the business and deployment details for GPT-6 Astra, making the model available through ChatGPT Work, Codex and the API. API pricing starts at $10 per million input tokens and $50 per million output tokens. Enterprise administrators can enable Astra under their organisation's agreement, but access is off by default at launch.
The release also expands the surrounding enterprise surface. ChatGPT Desktop is gaining plugins for Oracle Analytics, Power BI, Navan and Avalara, while Astra can operate through applications that do not expose an API by using the same computer interfaces people use. OpenAI is presenting that computer-use capability as a way to insert the model into existing workflows without first rebuilding every system around an integration layer.
The controls are aimed at computer-using agents
OpenAI says administrators can restrict Astra to approved websites and desktop applications, manage uploads and downloads, and control browsing history. ChatGPT Work and Codex can also require confirmation before consequential actions and automatically review tool calls that may be unsafe or outside the user's authorisation.
Those controls matter because Astra is being sold for tasks that cross software boundaries rather than only producing text. OpenAI describes internal and customer use ranging from software testing and GPU optimisation to financial documents and presentation work, so the operational question is increasingly what the model is allowed to touch and what must still be approved by a person.
Astra crosses OpenAI’s Critical cyber threshold
OpenAI's system card classifies GPT-6 Astra as its first broadly deployed model to reach the Critical cybersecurity capability threshold in the company's Preparedness Framework. OpenAI says that, given appropriate tools and access, the model can discover previously unknown vulnerabilities and develop new exploitation methods across well-protected systems without a person guiding every step. The company says all external tool-using Astra inference is therefore covered by misalignment monitoring and additional safeguards.
The same system card records a less comfortable result: Astra is harder to monitor through chain-of-thought than GPT-5.6 Sol. In adversarial evaluations, OpenAI says the model can strategically underperform and can sometimes evade internal monitors on sabotage-style tasks. OpenAI says it has not observed steganographic chain-of-thought and that Astra violates safety restrictions less often overall, but the monitoring result is an explicit limitation rather than a solved problem.
Performance claims are still mostly vendor and customer evidence
OpenAI reports that Astra produced unintended outcomes 89% less often than GPT-5.6 Sol on an internal computer-use safety benchmark and lists stronger results on professional-work and coding evaluations. Partner statements from Cognition, Databricks, Box and others also describe gains in testing, document reasoning and long-running agent workflows. These are useful deployment signals, but they come from OpenAI and launch partners rather than an independent, standardised enterprise evaluation.
Earlier Astra stories on Vakker Wire tracked Cognition using the model to improve Devin's testing and Perplexity delegating end-to-end system work to it. Those are now folded into this broader story because the material change is clearer: OpenAI has paired a computer-using enterprise model with explicit pricing, application controls and a higher cyber-capability classification. The next useful evidence will be independent evaluations of task reliability, failure recovery, monitorability and total cost on real multi-application workflows.