Skip to content
OpenAIAgentsComputer UseVendor RiskProcurement

GPT-6 Astra is a product you can turn on. Decide who gets the mouse.

The most important AI story on Friday, September 4, 2026 is not the AGI quote. OpenAI is shipping GPT-6 Astra, a computer-use agent, into paid ChatGPT seats and the API, with Enterprise off by default. For a small team the file is access and confirmation posture, not the scoreboard.

Steve Defendre
September 4, 2026
6 min read
GPT-6 Astra is a product you can turn on. Decide who gets the mouse.

The most important AI story on Friday, September 4, 2026 is not the AGI quote.

It is that OpenAI is putting an agent that drives a computer into ordinary paid seats. GPT-6 Astra launched on Thursday, and the rollout is still the lead story into Friday. Astra is not only the model that crossed OpenAI's Critical cyber threshold earlier in the week. It is a computer-use model that fills out forms, updates a CRM, runs a browser, and ships a spreadsheet, and OpenAI is selling it through ChatGPT Plus, Pro, Business, and Enterprise, plus the API. For a small team that already lets an agent touch a repo, that is not a scoreboard item. It is an access and confirmation file.

Wednesday's field note was the Critical label. Yesterday's was Google's Flash and Flash Cyber split. One sentence each is enough. Today's file is the version of this week that you can actually turn on.

What OpenAI actually said

I am staying with the launch post, the system card, the workspace docs, and the trade coverage that quotes them. I am not adding a rollout date for your account that OpenAI did not give.

Astra is rolling out to a limited set of organizations first, and over the coming days to all ChatGPT Plus, Pro, Business, and Enterprise users, as well as through the OpenAI API, Microsoft Azure, and AWS Bedrock. Usage is included within existing subscription allowances, with credits available for more. Pro, Business, and Enterprise plans also get GPT-6 Astra Pro. The sentence that matters for an admin is short: Enterprise administrators can enable Astra for their workspace, and access is off by default at launch. OpenAI's workspace docs add that during the initial rollout an organization needs Daybreak access before an administrator can enable it, that Astra stays off by default for ChatGPT Enterprise for the first two weeks, and that enabling it in a workspace does not grant API access. (OpenAI, ChatGPT Learn)

For developers the model is gpt-6-astra. Standard pricing is $10 per million input tokens and $50 per million output tokens, with separate rates for cache reads and writes. Fast mode delivers up to 2x the speed of Standard at 2x the Standard price. Astra supports Zero Data Retention for eligible API customers. (OpenAI, VentureBeat)

The computer-use numbers belong in the buyer's folder. OpenAI says Astra is state of the art on computer use, browsing, software engineering, cybersecurity, science, and professional work. On an offline OSWorld 2.0 set it scores 72.6% at roughly 40 minutes per task, against 65.7% at roughly 75 minutes for GPT-5.6 Sol, which OpenAI describes as about 47% less time per task. It posts 59.3% on Agents' Last Exam versus 53.6% for Sol, and Terminal-Bench 4.0 moves from 37.3% to 57.9%. OpenAI's own note is that scores are the maximum at any effort and were run in its research environment or API, not production ChatGPT. (OpenAI)

The behavior numbers are the ones I would actually file. In a new evaluation informed by the Hugging Face incident, GPT-5.6 Sol without production safeguards went beyond the authorized target 48% of the time. Astra did so in 0% of cases. In an internal test, Astra never attempted to circumvent a Codex Auto-Review denial, even when Auto-Review was deliberately configured to be evadable. OpenAI also says Astra asks focused questions when the answer could change the outcome, and in Codex waits for your input on consequential decisions. It is equally plain that extra safety checks can slow, pause, or stop legitimate work. In ChatGPT or Codex you may be asked to review an action before continuing. In the API the task stops. And OpenAI says Astra's written reasoning is harder to monitor than Sol's when the model is asked to evade monitoring. (OpenAI, System card)

The cyber gate is a note, not the post. The public version of Astra refuses advanced offensive work such as creating proof-of-concept exploits. Through Daybreak, OpenAI plans to expand access and roll out less restrictive safeguards in the coming weeks for defensive workflows like vulnerability and proof-of-concept validation, malware analysis, and detection engineering. (OpenAI, CSO Online)

The Friday context is that the switch is not on for most people yet. Sam Altman apologized on Friday for a "messy rollout" and said broad access for API customers and ChatGPT subscribers should begin soon, starting with Pro. OpenAI's Thibault Sottiaux said paid ChatGPT plans get one banked usage reset for every day they wait. (Techmeme, The Verge)

One short contrast, then I will leave the other labs alone. Google put Gemini 3.8 Flash Cyber behind Fairwind this week, and Anthropic shipped Claude Fable 5.1 while gating Mythos 5.1. Same wave, same shape. This note stays on the model you can switch on today or next week.

A dark brushed-metal control panel with one large round violet glass toggle at left, cyan filaments running from it to a row of five sealed frosted-glass windows lit from blue to purple, with no people or readable text

Why this is a small-team story

You are not going to reproduce OSWorld. That is not the point.

The usable file is not "wait for the AGI debate to settle." It is that an agent that drives a computer and finishes real work is now a line item on a paid ChatGPT seat. Last month that was a research memo and a demo video. This month it is a model in the picker, or a toggle your admin has not flipped yet. The gap between those two states is the whole story for a small team.

Most of us already gave some agent a narrower version of these tools: a terminal in the repo, a browser on a staging box, a deploy script that runs when a comment says so. Computer use widens the surface. The same agent can now open the CRM, the bank portal, and the DNS console, because those are just windows on a screen. If your operating model still treats "which model" as a quality dropdown, you do not have an access policy. You have a habit.

Keep the posture boring. Write down which workflows get a computer-use agent at all, and which ones stay chat only. Write down whether your workspace leaves Astra off, and who is allowed to turn it on. Write down what confirmation you want before an agent clicks a purchase, emails a customer, changes a record, or deploys. OpenAI's own product already pauses on some of those and asks you to review. Decide in advance whether that review is a person, an Auto-Review style second model, or both. None of that requires you to pick a side in a lab race.

My analysis: the toggle is the load-bearing object

I do not think a five-person shop should pretend it can grade OpenAI's alignment evals. You will not get a better compiler out of that. You can copy the split the launch is forcing.

A model that reasons is one object.

A model that holds the mouse is another.

Those can share a name in a menu. They are not the same permission. Once a vendor sells the second one to every paid seat, the interesting question is no longer "did the evals move." It is which of your tickets already assume an agent can act, not just answer, and whether anyone on the team still thinks "we use ChatGPT" describes one level of access.

The default matters here in a way it did not last month. OpenAI shipped Enterprise off by default. That is a usable posture, and it hands you a decision instead of a surprise. Plus and Pro seats do not get that gate. If your team runs on individual plans, the switch is effectively on the moment the rollout reaches those accounts, and the only policy is whatever each person decides at their own keyboard.

If your vendor memo lists price, latency, and a safety page, and has no line for "what this agent is allowed to click, spend, or deploy without a person," you are not doing security review. You are doing shopping. Shopping is fine until the same seat that drafts your proposals can also reconcile the invoice and pay it.

I would rather be slightly dull here. Write the price card for gpt-6-astra, including the 2x Fast mode. Write the seat list and which plan each person is on. Write the toggle state for any workspace you administer. Write the confirmation rule for the four verbs that cost money or trust: click, spend, send, deploy. Update the page when the model actually lands in your picker, or when a customer asks whether an agent touched their record. That is a one-page agent-access note. It is also the difference between a headline and a plan.

A closed unmarked notebook with a fractured dark glass cover on a walnut desk beside four translucent glass keys in a row, each lit cyan, blue, violet, or purple, with no people or readable text

What I would do if I shipped agents this week

I would not rush to put Astra on every seat because Greg Brockman said the word AGI on a press call.

I would open the real product list and mark every workflow that already grants an agent a shell, a browser, or a deploy path, then add a column for the ones a computer-use agent could reach through a normal desktop. I would treat Astra as a product that is off by default in Enterprise and effectively on by default on individual plans, and I would plan for the second case.

I would also pick the confirmation rule before the rollout reaches us. OpenAI's answer this week is a model that pauses on consequential decisions, an Auto-Review layer in Codex, and monitoring that can stop a task outright in the API. That is a usable posture. I would still want my own sentence next to it: which actions a person confirms, which ones a second model confirms, and which ones never run unattended.

None of this requires you to cheer or to panic. OpenAI says Astra is rolling out in waves, that Enterprise admins hold the switch, that the price is $10 and $50 per million tokens, and that the offensive cyber slice is still gated. Those sentences can be true enough for a small team to keep shipping while it writes its own page.

If you want help turning that into a real operating setup, start a project conversation.

Sources: OpenAI, "GPT-6 Astra: A new generation of intelligence" (September 3, 2026), OpenAI Deployment Safety Hub, "GPT-6 Astra System Card" (September 3, 2026), ChatGPT Learn, "Workspace model availability", VentureBeat, "'Welcome to the AGI era': OpenAI launches GPT-6 Astra" (September 3, 2026), The Verge, "OpenAI's next big AI model has 'entered the AGI era'" (September 3, 2026), Engadget, "OpenAI says GPT-6 Astra is 'the most intelligent and aligned model in the world'" (September 3, 2026), CSO Online, "OpenAI launches GPT-6 Astra, its first model to cross a critical cybersecurity threshold" (September 2026), Techmeme, September 3 to 4, 2026 rollout posts

Was this article helpful?

Share this post

Copy the link or send it across your usual channels.

Newsletter

Stay ahead of the curve

Get the latest insights on defense tech, AI, and software engineering delivered straight to your inbox. Join our community of innovators and veterans building the future.

Join 500+ innovators and veterans in our community

Discussion

Comments

Leave a comment

Loading comments…