Skip to main content

OpenAI's GPT-6 Astra Reaches "Critical" Security Rating, Powers Autonomous Code Testing

12 SEPTEMBER 2026·2 MIN READ·3 SOURCES·Official source plus independent coverage

OpenAI launched GPT-6 Astra on September 3, marking the company's first model to achieve a "Critical" cybersecurity rating due to its ability to independently find and exploit software flaws.

OpenAI's GPT-6 Astra Reaches "Critical" Security Rating, Powers Autonomous Code Testing

Key takeaways · 3

  • 01

    GPT-6 Astra is OpenAI's first "Critical" cybersecurity model under its Preparedness Framework.

  • 02

    Astra achieved a 100 percent score on ExploitBench, up from 78.5 percent with GPT-5.6 Sol.

  • 03

    Cognition uses Astra to let Devin test code in simulators and automatically fix bugs from screenshots.

New Risk Threshold

OpenAI released GPT-6 Astra on September 3. [3] The The company designated the release as its first "Critical" cybersecurity model under its Preparedness Framework, which is its highest risk level. [3] This classification reflects the model's ability to locate and exploit previously unknown vulnerabilities across protected systems without a human guiding every step. [3]

In internal evaluations, GPT-6 Astra discovered and exploited two verified zero-day vulnerabilities. [3] The model also achieved a 100 percent score on ExploitBench, compared to a 78.5 percent score from the previous flagship model, GPT-5.6 Sol. [3]

Autonomous Code Testing

Cognition is using GPT-6 Astra to improve its autonomous software engineer, Devin. [2] The model allows Devin to test its own work and provide evidence of the results, which Cognition expects will reduce the need for manual code review. [2]

In one application, Devin uses the model to test an iPhone game called Otter Run. [2] Devin provides engineers with a recording of the game running in a simulator and a report documenting the scope of the testing. [2] Additionally, when users submit a screenshot of a bug, Astra enables Devin to fix the issue and return a screenshot of the result. [2]

What it means

The arrival of GPT-6 Astra demonstrates a dual leap in autonomous agent capabilities and associated security risks. By dramatically outperforming GPT-5.6 Sol across cybersecurity benchmarks like ExploitBench and ExploitGym, Astra proves that AI models can now conduct multi-stage network penetration and exploit discovery with minimal oversight. This same capacity for complex autonomous action is precisely what allows tools like Devin to test entire games in a simulator and fix bugs from a single screenshot. What the sources don't address: How OpenAI plans to securely grant enterprise customers access to an API capable of autonomous zero-day discovery.

GPT-6 Astra crosses a new threshold in AI capabilities by achieving autonomous exploit discovery alongside advanced software engineering utility. This development signals that the next generation of coding agents will handle end-to-end testing, while organizations must simultaneously defend against highly capable automated cyber threats.

Why it matters
Daily session

Put this to work — one session a day, built for your industry.

Create a free account for a daily session — eight questions and one real-work challenge, on the news that affects your role.

Start free

How this developed

  1. 12 September 2026

    OpenAI's GPT-6 Astra Reaches "Critical" Security Rating, Powers Autonomous Code Testing

  2. 12 September 2026

    Event created from source cluster.

Sources

AI fluency, one session a day, built for your work.