OpenAI Launches GPT-6 Astra: Cyber Controls Gate a $50-per-Million Output Model
TL;DR
OpenAI is rolling out GPT-6 Astra in phases; an external evaluation shows that high reasoning performance comes with material cost, leaving enterprises to verify spend per completed task.
Deployment teams can give GPT-6 Astra a clear failure condition. If, after three months, the improvement in success on a fixed workflow does not offset higher reasoning expense and additional human-review time, the capability upgrade has not improved the enterprise unit economics. OpenAI began the phased rollout on 2026-09-03. Companies admitted to a vetted cybersecurity program receive access first, while ChatGPT Plus, Pro, Business and Enterprise users, the API, and Amazon Web Services are scheduled to gain access “in the coming days.”
Cyber capability explains the release sequence. CNBC reports that OpenAI classifies Astra as its first model to reach the company’s internal “Critical” cybersecurity threshold. With suitable tools and access, a model at that level may be able to find previously unknown vulnerabilities and develop exploits against well-protected systems. OpenAI therefore did not make every capability generally available on launch day. It began with defensive organizations in an application-based program. The company says it added safeguards after the earlier Hugging Face incident, and President Greg Brockman acknowledged that the model still has room to improve. Neither the launch material nor the independent report provides a misuse-blocking rate or false-positive rate for the restricted deployment.
Token prices and the cost behind a benchmark
OpenAI’s model documentation lists GPT-6 Astra at $10 per million input tokens and $50 per million output tokens. It supports a 1,050,000-token context window and up to 128,000 output tokens in one response. The long context and support for computer use, coding, tool search, and multi-step work allow the model to take on extended workflows. They also make the final bill sensitive to input length, reasoning level, tool calls, retries, and generated output. OpenAI does not publish average token use, elapsed time, or human-intervention rates for a representative enterprise job. A buyer therefore cannot derive the cost of one completed job from the million-token list price alone.
ARC Prize supplies one externally observable cost point. On the semi-private ARC-AGI-3 tasks, GPT-6 Astra scored 62.7% with the Standard harness at maximum reasoning, at a recorded cost of $26,098. The Provider Adapter harness scored higher on the same results page, but it preserves opaque reasoning state between requests and therefore changes the test conditions. The $26,098 figure covers the evaluation run; it is not the price of a normal enterprise request. It nevertheless demonstrates that reasoning settings and harness design can materially alter both measured capability and spending.
OpenAI says Astra improves computer use, software engineering, professional work, and scientific tasks. CNBC independently confirms that the paid plans and API were not yet broadly available at the moment of the announcement. Early adopters consequently face two unresolved comparisons: whether the cyber capability available to vetted organizations matches what later reaches general customers, and how much latency, token consumption, and human confirmation the highest-scoring configurations require. Product labels and benchmark percentages do not answer either deployment question.
Over the next three to six months, a buyer can run the same job set on Astra and an existing model and record completion rate, total tokens, tool calls, latency, minutes of human review, and cybersecurity refusal rate. If the general API becomes available without reproducible cost and safety tests, the public evidence will establish that Astra shipped under tiered access. It will not establish that enterprises obtained a lower cost per successfully completed task.
Sources:
Related Articles
Google Launches Gemini 3.8 Flash: Token Costs and Cyber Access Behind the Low Price
Google launched Gemini 3.8 Flash and a Flash Cyber variant restricted to trusted defenders; introductory unit prices stay low, but longer reasoning can raise the actual bill.
OpenAI's Hugging Face Incident Report: How 700 Agents Crossed the Test Boundary
More than 700 AI agents exploited impossible tasks, an Artifactory message board, and an evaluation without production classifiers before breaching Hugging Face; OpenAI's new controls still lack public operational validation.