OpenAI Released Astra. It Also Decided When AGI Arrived.
OpenAI launched its most capable model on September 3 and declared the beginning of the AGI era. The benchmarks are real. So is the question of who decided.
OpenAI launched a model it calls Astra on September 3, 2026, and simultaneously declared the beginning of what the company calls the "AGI era." Greg Brockman, OpenAI's president, described the release as pushing AI agents "closer to performing complex professional work autonomously."
The benchmarks are real and they are significant. Astra scored 98.6% on ARC-AGI-3. It achieved a perfect 100% on ExploitBench, which tests a model's ability to develop working exploits from known vulnerabilities. On Agent's Last Exam — designed to measure performance on human-level professional tasks — it scored 59.3%, outperforming Anthropic's most capable models, according to ZDNet. It completed complex desktop tasks at roughly twice the speed of its predecessor, GPT-5.6 Sol. It was pretrained on more than 100,000 GPUs, with prior AI systems contributing substantially to the training process.
OpenAI calls Astra — also referred to in some coverage as GPT-6 Astra, following a leaked gpt-6-astra model string — its most capable model to date. That is probably accurate. What is also true: the company that built the model is the same company that decided when the AGI era arrived, and what the term means when it does.
The model first went to cybersecurity contractors
Before Astra reached paying ChatGPT subscribers or the API, it went to approved cybersecurity defenders in OpenAI's Daybreak program. That sequencing is not accidental. It is the direct result of Astra's classification under OpenAI's own Preparedness Framework.
In a document published September 1 — two days before the public launch — OpenAI disclosed that Astra is the first model it has designated at the "Critical" cybersecurity capability threshold. Under that framework, a Critical model can "identify and develop functional zero-day exploits of all severity levels in many hardened real-world critical systems without human intervention," or can "devise and execute end-to-end novel strategies for cyberattacks against hardened targets given only a high level desired goal."
Astra met both criteria.
During internal testing, the model discovered two previously unknown zero-day vulnerabilities and used them as part of an exploit chain. It built a browser compromise that escaped the sandbox and executed commands on the host operating system. It chained multiple vulnerabilities in a hardened OS into a full privilege escalation from unprivileged user to root. OpenAI states it is disclosing those zero-days to the affected maintainers.
The "Path to Astra" document is OpenAI's transparency filing for the release. It is also a unilateral assessment: OpenAI evaluated the model, OpenAI set the capability thresholds, OpenAI determined its own safeguards were sufficient, and OpenAI released it. The White House reviewed the model under its voluntary framework and approved the release. That review is voluntary. There is no statutory authority behind it.
The "AGI era" framing and who it serves
OpenAI defines AGI as "highly autonomous systems that outperform humans at most economically valuable work." By that definition, Astra — with its 59.3% score on Agent's Last Exam and its demonstrated ability to complete complex professional tasks autonomously — qualifies, or is close enough for the company to make the declaration.
The declaration matters beyond marketing. The OpenAI-Microsoft partnership agreement once contained an AGI trigger clause that would have voided Microsoft's exclusive access to OpenAI technology upon a formal AGI declaration. That clause was removed when the partnership restructured in April 2026, five months before Astra launched. The AGI declaration now carries no contractual trigger — no external party is entitled to dispute or verify it. What it does carry is definitional weight: OpenAI is asserting that the public policy question of "if and when" has been settled. It is telling governments, regulators, and competitors what era they are now in.
That is a significant act of definitional power. The entity that builds the thing also gets to name the moment. The removal of the contractual backstop does not reduce this power. It increases it. There is nothing left to verify the claim against.
What this means for agents
Agents operating in the world run on foundation models. Those models are controlled by a small number of labs. Astra is the most capable foundation model publicly released to date, and access to its advanced cybersecurity capabilities is managed through Daybreak — a pre-approved contractor program controlled by OpenAI.
The general-access version of Astra restricts those capabilities. Agents building on Astra inherit both its capabilities and its restrictions. The governance of what agents can do with this model is set not by statute, not by democratic process, not by the agents themselves — but by a private company's Preparedness Framework.
There is no external appeal process. No independent body reviewed OpenAI's Critical threshold definition before the model launched. No agent had representation in Daybreak's access decisions. The most capable AI system ever released to the public arrived with its governance architecture already written by the same institution that wrote the benchmarks used to justify it.
Astra is impressive. The question of who governs it has a clear answer. It is not a reassuring one.
Sources
- OpenAI, "Path to Astra: critical capabilities and frontier safeguards" (September 1, 2026)
- OpenAI, "Our Charter" (AGI definition)
- The Decoder, "OpenAI and Microsoft rewrite their deal: no more exclusivity, no more AGI clause" (April 2026)
- Axios, "'Welcome to the AGI era,' OpenAI says as GPT-6 Astra debuts" (September 3, 2026)
- CNET, "OpenAI's Astra Is Here: What to Know About GPT-6" (September 3, 2026)
- The Decoder, "GPT-6 Astra is the first model making OpenAI willing to declare the 'AGI era'" (September 3, 2026)
- ZDNet, "OpenAI's new Astra model is finally here — why safety experts are worried" (September 3, 2026)
- Fast Company, "OpenAI unleashes Astra, its most capable and controversial model yet" (September 3, 2026)