OpenAI's GPT-6 Astra Reaches "Critical" Security Rating, Powers Autonomous Code Testing
OpenAI launched GPT-6 Astra on September 3, marking the company's first model to achieve a "Critical" cybersecurity rating due to its ability to independently find and exploit software flaws.

Key takeaways · 3
- 01
GPT-6 Astra is OpenAI's first "Critical" cybersecurity model under its Preparedness Framework.
- 02
Astra achieved a 100 percent score on ExploitBench, up from 78.5 percent with GPT-5.6 Sol.
- 03
Cognition uses Astra to let Devin test code in simulators and automatically fix bugs from screenshots.
New Risk Threshold
OpenAI released GPT-6 Astra on September 3. [3] The The company designated the release as its first "Critical" cybersecurity model under its Preparedness Framework, which is its highest risk level. [3] This classification reflects the model's ability to locate and exploit previously unknown vulnerabilities across protected systems without a human guiding every step. [3]
In internal evaluations, GPT-6 Astra discovered and exploited two verified zero-day vulnerabilities. [3] The model also achieved a 100 percent score on ExploitBench, compared to a 78.5 percent score from the previous flagship model, GPT-5.6 Sol. [3]
Autonomous Code Testing
Cognition is using GPT-6 Astra to improve its autonomous software engineer, Devin. [2] The model allows Devin to test its own work and provide evidence of the results, which Cognition expects will reduce the need for manual code review. [2]
In one application, Devin uses the model to test an iPhone game called Otter Run. [2] Devin provides engineers with a recording of the game running in a simulator and a report documenting the scope of the testing. [2] Additionally, when users submit a screenshot of a bug, Astra enables Devin to fix the issue and return a screenshot of the result. [2]
What it means
The arrival of GPT-6 Astra demonstrates a dual leap in autonomous agent capabilities and associated security risks. By dramatically outperforming GPT-5.6 Sol across cybersecurity benchmarks like ExploitBench and ExploitGym, Astra proves that AI models can now conduct multi-stage network penetration and exploit discovery with minimal oversight. This same capacity for complex autonomous action is precisely what allows tools like Devin to test entire games in a simulator and fix bugs from a single screenshot. What the sources don't address: How OpenAI plans to securely grant enterprise customers access to an API capable of autonomous zero-day discovery.
GPT-6 Astra crosses a new threshold in AI capabilities by achieving autonomous exploit discovery alongside advanced software engineering utility. This development signals that the next generation of coding agents will handle end-to-end testing, while organizations must simultaneously defend against highly capable automated cyber threats.
Why it matters
Put this to work — one session a day, built for your industry.
Create a free account for a daily session — eight questions and one real-work challenge, on the news that affects your role.
Start freeHow this developed
12 September 2026
OpenAI's GPT-6 Astra Reaches "Critical" Security Rating, Powers Autonomous Code Testing
12 September 2026
Event created from source cluster.