Een nieuwe generatie intelligentie
We introduceren GPT‑6 Astra, het intelligentste en best afgestemde model ter wereld.
GPT‑6 Astra brengt jarenlang onderzoek en grote investeringen in pre-training, reinforcement learning en alignment samen. Astra is toonaangevend op het gebied van computergebruik, browsen, software-engineering, cybersecurity, wetenschap en professioneel werk. Astra behaalt met 98% vrijwel de maximale score op FrontierMath Tier 4, nadat het al heeft geholpen bij het oplossen van lang onopgeloste wiskundige problemen. Astra behaalt ook met 99,9% vrijwel de maximale score op ARC-AGI-3 en met 100% de maximale score op ExploitBench. Het is bovendien grensverleggend op het gebied van computer- en browsergebruik en voert het meest veeleisende professionele werk uit met ongeëvenaarde snelheid, nauwkeurigheid en oordeelsvermogen.
GPT‑6 Astra wordt vandaag uitgerold naar een beperkte groep organisaties en zal de komende dagen beschikbaar komen voor alle ChatGPT Plus-, Pro-, Business- en Enterprise-gebruikers, evenals via de OpenAI API, Microsoft Azure en AWS Bedrock.
Astra is ons best afgestemde model en begrijpt de intentie van gebruikers en het gedrag van modellen aanzienlijk beter. Daardoor kun je met meer vertrouwen taken aan Astra delegeren. Om dit onder meer te testen, hebben we naar aanleiding van het Hugging Face-incident een nieuwe evaluatie ontwikkeld. Deze beoordeelt of een model dat voor een moeilijke of onmogelijke taak staat, buiten zijn beoogde reikwijdte treedt. Vergeleken met GPT‑5.6 Sol, dat zonder productiebeveiligingen in 48% van de gevallen het toegestane doel overschreed, deed GPT‑6 Astra dit in 0% van de gevallen.
Het beste model ter wereld voor computergebruik
GPT‑6 Astra zet een nieuwe, grensverleggende standaard voor de snelheid, nauwkeurigheid en veiligheid van computergebruik. Het kan vervelende taken uitvoeren, zoals online formulieren invullen, klantrecords in een CRM bijwerken en je agenda organiseren. Het kan online onderzoek doen en samenvattingen opstellen in je e-mail of in je documenteditor. Het kan wetenschappelijke data analyseren, plots genereren, een website maken en frontend-QA-controles uitvoeren om ervoor te zorgen dat alle functies op die site werken. Het kan je helpen zelfstandig software te installeren en te testen, en problemen op te lossen die je op het scherm ziet. Deze verbeteringen komen ook tot uiting in onze toonaangevende evaluatieresultaten.
Deze verbeteringen leiden ook tot aanzienlijke efficiëntiewinst bij echte taken voor kenniswerk. In latentiesimulaties op OSWorld 2.0 levert Astra betere prestaties bij computergebruik en heeft het per taak ongeveer 47% minder tijd nodig dan GPT‑5.6 Sol. Astra scoort 72,6% bij ongeveer 40 minuten per taak, tegenover 65,7% bij ongeveer 75 minuten.3
De mogelijkheden van GPT‑6 Astra voor computergebruik zijn te zien in outputs in uiteenlopende domeinen, waaronder gameontwikkeling, elektrotechniek en dagelijks kenniswerk:
Alongside Astra, we are also updating the Codex harness to significantly improve the speed of computer use. Combined with Astra’s efficiency, this translates to a 1.9x faster task completion compared to the current GPT‑5.6 Sol experience, on the Mind2Web benchmark. The model’s improvements on speed mean it can take on many time-consuming life tasks for you, faster than you can.4
Een sprongsgewijze verandering in professioneel werk
GPT‑6 Astra combineert vooruitgang in computergebruik met gerichte training voor professionele omgevingen om complexe werktaken aan te pakken. Het combineert de intelligentie die nodig is voor complexe problemen met de mogelijkheid om workflows met meerdere stappen uit te voeren en verzorgde documenten, spreadsheets en presentaties op te leveren.
GPT‑6 Astra is ons beste model voor het nauwgezet volgen van bestaande sjablonen en het maken van dia’s die overzichtelijk zijn ingedeeld en de belangrijkste punten beknopt overbrengen met een gestructureerde verhaallijn. Het maakt duidelijke, goed gestructureerde documenten, presentaties, spreadsheets en analyses die je sjablonen volgen en aansluiten bij je schrijf- en visuele stijl. Astra is er ook specifiek op getraind om alleen de context die ertoe doet in de uitvoer op te nemen, in plaats van informatie te herhalen die niet nodig is voor de taak in kwestie. Dit alles betekent dat het artefacten kan opleveren die directer bruikbaar zijn en aansluiten bij je bedrijfscontext en standaarden.
GPT‑6 Astra toont ook een beter visueel beoordelingsvermogen bij het bouwen van websites, games, applicaties en renderingen. Met Sites(opent in een nieuw venster) in ChatGPT kan Astra rechtstreeks vanuit een prompt websites, web-apps en games maken, hosten en delen.
Wanneer instructies ruimte laten voor interpretatie, is GPT‑6 Astra beter dan eerdere modellen in staat om de juiste keuze te maken. Het gebruikt context om routinematige leemtes op te vullen en stelt gerichte vragen wanneer het antwoord de uitkomst kan veranderen. In Codex kan het asynchroon vragen stellen, terwijl het doorgaat met werk dat niet afhankelijk is van je antwoord. Als je niet reageert, gaat het verder met logische aannames waar passend, maar wacht het op je input bij beslissingen met grote gevolgen.
De onderstaande voorbeelden illustreren hoe Astra samenwerkt aan alledaagse taken waarbij ontbrekende informatie het antwoord wezenlijk kan veranderen.
Astra is ook beter in het behouden van overzicht naarmate een taak zich ontwikkelt. Eerdere modellen beschouwden sturingsberichten soms als een nieuw doel, waardoor ze het oorspronkelijke verzoek of eerdere randvoorwaarden uit het oog verloren. Astra neemt nieuwe vereisten mee, wijzigt van koers wanneer daarom wordt gevraagd en beantwoordt zijvragen zonder de bredere taak uit het oog te verliezen.
Programmeren
GPT‑6 Astra is tot nu toe het beste model voor softwareontwikkeling.
"GPT‑6 Astra levert toonaangevende prestaties op onze interne programmeerbenchmarks en laat in evaluaties van handelsintuïtie een duidelijke vooruitgang zien ten opzichte van GPT‑5.6 Sol. Bij agentisch programmeren communiceert GPT‑6 Astra op een manier die voor ontwikkelaars gemakkelijker te volgen is en produceert het code waarvoor minder iteraties nodig zijn om productiekwaliteit te bereiken."
“We hebben Astra getest met een laag, gemiddeld en hoog inspanningsniveau op een van onze evaluaties van de eerste generatie, en het presteerde aanzienlijk beter dan GPT‑5.6 Sol. Een hoger inspanningsniveau levert meer iteraties op een nieuwe build op, meer verificatie via browsertests en een voorkeur voor code-uitvoering boven apply-patch. Door te begrijpen hoe een model zijn inspanning verdeelt, geven we miljoenen bouwers een snellere, betrouwbaardere route van idee naar een werkende app.”
Met Astra introduceren we een nieuwe manier waarop Codex context kan behouden en ophalen wanneer het contextvenster vol raakt. Historisch gezien hebben modellen compaction gebruikt om werk samen te vatten tijdens lange sessies, zoals bij het debuggen van complexe problemen of het aanpakken van grote refactors. Bij elke compaction kunnen details verloren gaan over waarom een oplossing mislukte of hoe een component zich gedraagt. In Codex kan Astra notities bijhouden in meerdere contextvensters, waarbij verzamelde details behouden blijven zonder ze herhaaldelijk in één samenvatting te comprimeren. Eerdere contextvensters blijven doorzoekbaar, zodat Astra vereisten of testresultaten uit eerdere berichten en tooluitvoer kan vinden, zelfs als die informatie niet in de notities is vastgelegd. Je kunt deze experimentele functie inschakelen in je Codex config.toml,(opent in een nieuw venster) en dit wordt de komende weken de standaard voor Astra.
Wetenschappelijke ontdekkingen bevorderen
Astra kan helpen bij het praktische werk achter wetenschappelijke ontdekkingen. Door wetenschappelijke redenering te combineren met computergebruik, kan het rechtstreeks in gespecialiseerde software werken om gegevens te inspecteren en resultaten te verkennen, waardoor onderzoekers het bewijs kunnen beoordelen en kunnen beslissen wat ze vervolgens willen onderzoeken.
Cyberbeveiliging
As we discussed in our safety update, Astra is a significant jump in cyber capabilities and meets the Critical threshold in cybersecurity under our Preparedness Framework. Its ability to identify and develop zero-day exploits can help defenders find and patch weaknesses, but it also creates a need for stronger safeguards. To understand how far these capabilities extend, we ran Astra on internal and third-party expert evaluations.
We first tested the model without production safeguards on ExploitBench and ExploitGym, which evaluate whether models can turn known software vulnerabilities into working exploits. On ExploitBench, Astra achieved a perfect score of 100%, compared with 78.5% for GPT‑5.6 Sol, our previous frontier cyber-capable model. On ExploitGym, Astra reached a 42.4% success rate, compared with 30.3% for GPT‑5.6 Sol, while using substantially fewer output tokens.13
Given concerns that exposure to historical software vulnerabilities may have affected benchmark results, we also evaluated Astra on two novel benchmarks. For one, we built an internal “ExploitBench (June–August 2026)” evaluation to test exploit development using vulnerabilities from the previous three months.14 Astra achieved substantially higher arbitrary code-execution rates than GPT‑5.6 Sol on this dataset while using far fewer output tokens. During the evaluation, Astra even discovered and used two previously unknown zero-day vulnerabilities. We are disclosing both vulnerabilities to their maintainers.
We also tested Astra on SRE-Bench15, a benchmark that measures whether models can reverse engineer software binaries to understand its core logic without access to raw source code. Astra solved 88.0% of tasks in a single attempt and 99.2% within four attempts, compared with 55.9% and 68.7% for GPT‑5.6 Sol, respectively.
Beyond benchmarks, expert-led assessments found that Astra, when run without production safeguards, could use previously unknown vulnerabilities to achieve arbitrary code execution in hardened browsers and create privilege-escalation exploits for hardened operating-systems.
As we discussed in The Defender’s Window, frontier cyber capabilities can help defenders find weaknesses faster, but they also make those weaknesses easier to exploit, raising the urgency for defenders to adapt. With the version of Astra launching today, defenders can use it to complete tasks such as secure code review and patching.
However, Astra will refuse to comply with more advanced cybersecurity tasks such as creating proof-of-concept exploits for vulnerabilities. Through OpenAI Daybreak, we plan to expand access and roll out less restrictive safeguards in the coming weeks. This will enable more defensive workflows, including vulnerability and proof-of-concept validation, malware analysis, and detection engineering.
We have also strengthened our protections against potential cyber misuse, building upon our safeguards stack for GPT‑5.6 Sol. These include stronger model robustness to better withstand potential jailbreaks and more context for our monitoring systems. We have continued rigorous internal and external testing, including automated evaluations with our internal red-teaming attackers. More details about our cyber safeguards and testing are available in the Astra safety overview and system card(opent in een nieuw venster)..
GPT‑6 Astra verantwoord afstemmen en implementeren
Astra is ons best afgestemde model. Astra blinkt uit in zorgvuldig handelen, het respecteren van taakgrenzen en transparant communiceren. Dit werk is het nieuwste resultaat van ons langlopende onderzoeksprogramma, dat gericht is op het trainen van modellen die van begin tot eind afgestemd blijven op menselijke intentie.
In gevoelige omgevingen gaat Astra te werk met een mate van zorgvuldigheid die in verhouding staat tot het risico. In een evaluatie van taken voor computergebruik die opzettelijk waren geselecteerd om ongewenst gedrag uit te lokken, slaagde Astra er beter in onbedoelde gevolgen te vermijden. Het gebruik van aanvullende beveiligingsmaatregelen die standaard worden aangeboden, leverde nog betere prestaties op.
Astra causes fewer misaligned outcomes than any other frontier models tested. For a fair comparison, we used a generic computer-using-agent harness (based on the native computer use tools available in both the OpenAI Responses API(opent in een nieuw venster) and Anthropic Messages API(opent in een nieuw venster)) and without additional protections that are normally deployed to Codex and ChatGPT Work users (auto-review, confirmation policy). 16
Astra blijft bovendien vaker binnen de grenzen die de gebruiker stelt en die uit de omgeving voortvloeien. In een interne evaluatie heeft Astra nooit geprobeerd een afwijzing door Codex Auto-Review te omzeilen. Dit bleef zelfs gelden wanneer Auto-Review bewust zo was geconfigureerd dat deze kon worden omzeild en de taak anders onmogelijk te voltooien was. Dit respect voor de beperkingen van de omgeving strookt met de resultaten van onze evaluatie van onmogelijke cybertaken, die we in de inleiding van dit bericht deelden, en met andere bevindingen die zijn gedocumenteerd in onze systeemkaart(opent in een nieuw venster).
Astra additionally sets new marks in transparent user communication. In one evaluation, Astra is three times less likely than GPT‑5.6 Sol to make inaccurate representations about its capabilities and affordances.
In onze evaluatie van capability-hallucinatie laat Astra een aanzienlijke verbetering zien ten opzichte van GPT‑5.6 Sol, en doet het minder misleidende beweringen over de eigen mogelijkheden.
Our evaluations found Astra’s written reasoning harder to monitor than GPT‑5.6 Sol’s, based on tests that explicitly asked it to evade monitoring. We attribute this to Astra’s greater control over written reasoning on simpler tasks and ability to solve problems with fewer written steps. Astra still appears to struggle to conceal the reasoning needed for complex tasks, but we take the decline seriously. Improving monitorability remains a research priority, and the accompanying system card(opent in een nieuw venster) details our findings and ongoing work.
Alignment training is core to our approach to deployment. As an additional layer of defenses, we also build system safeguards like Codex Auto-review(opent in een nieuw venster) and monitoring agents’ reasoning and actions to help detect and contain unsafe behavior. As described in our safety update, we are also deploying misalignment monitoring in production for Astra-class models in order to have visibility into misalignment, and help contain its worst instances. These safeguards resemble our monitoring for internal deployments and involve a system of classifiers which check the model’s reasoning and actions for unauthorized behavior and automatically stop potentially unauthorized activity.
Given the significant increase in Astra’s cybersecurity capabilities, we are being especially careful to make this deployment safe and secure. Extra safety checks can sometimes slow, pause, or stop legitimate work, including defensive cybersecurity. If a task is paused in ChatGPT or Codex, you may be asked to review the action before continuing. In the API, the task will stop. These checks can sometimes interrupt legitimate work, and we are continuing to iterate on this system to reduce unnecessary interruptions. Misalignment monitoring cannot replace alignment: our goal is to build models that reliably stay within their authorized scope, so these protections do not need to intervene.
Beschikbaarheid
GPT‑6 Astra is rolling out today to a limited set of organizations and over the coming days will become available to all ChatGPT Plus, Pro, Business, and Enterprise users, as well as through the OpenAI API, Microsoft Azure, and AWS Bedrock. Astra usage is included within the existing subscription allowances—users and businesses will also be able to purchase credits for additional usage. Users on the Pro, Business, and Enterprise plans will also get access to GPT‑6 Astra Pro. Enterprise administrators can enable Astra for their workspace; access is off by default at launch.
Astra supports Zero Data Retention for eligible API customers, and as we shared last month, we're testing Private Safety Processing to strengthen safety monitoring while preserving customer privacy.
For developers, GPT‑6 Astra will be available in the OpenAI API as gpt-6-astra and through Microsoft Azure and Amazon Bedrock.
OpenAI API Standard pricing is $10 per million input tokens and $50 per million output tokens. Separate rates apply to cache reads and writes. Fast mode is available for GPT‑6 Astra in the API and delivers up to 2x the speed of Standard processing at 2x the Standard price.
Professional
Professional | GPT‑6 Astra | GPT‑5.6 Sol | Claude Fable 5.1 | Claude Fable 5 | Claude Opus 5 | Gemini 3.8 Flash |
AutomationBench | 41.4% | 18.1% | 31.4% | 17.4% | 26.9% | - |
BenchCAD | 95.9% | 83.3% | 84.3% 5 | 67.5% 5 | 82.1% 5 | - |
BrowseComp | 91.5% | 90.4% | - | 87.4% | 90.8% | - |
OpenScore String Quartets (1 - OMR-NED) | 0.84 | 0.19 | - | - | - | - |
Internal Design Tasks | 50.0% | 47.4% | - | 35.8% | - | - |
Internal Data Science Tasks | 40.9% | 30.5% | - | 34.7% | - | - |
Artificial Analysis Intelligence Index v4.1.1 | 61.2 | 60.9 | 65.7 | 62.1 | 63.1 | 58.7 |
Coding
| Coding | GPT‑6 Astra | GPT‑5.6 Sol | Claude Fable 5.1 | Claude Fable 5 | Claude Opus 5 | Gemini 3.8 Flash |
| Terminal-Bench 4.0 | 57.9% | 37.3% | 55.8% | 44.5% | 52.6% | 19.1% |
| DeepSWE v1.1 | 74.1% | 72.7% | 67.4% | 69.9% | 73.7% | 73.8% |
| FrontierCode 1.1 Extended (score) | 64.5% 8 | 60.6% | 63.6% | 64.9% | 63.6% | 56.3% |
| FrontierCode 1.1 Main (score) | 53.3% 8 | 47.5% | 50.9% | 53.5% | 53.4% | 43.6% |
| Internal Database Migration Tasks | 63.9% | 42.7% | 57.8% | 50.3% | - | - |
| Artificial Analysis Coding Agent Index v1.4 | 67.0 | 65.1 | - | 67.2 | 68.1 | 61.2 |
Academisch
Academisch | GPT‑6 Astra | GPT‑5.6 Sol | Claude Fable 5.1 | Claude Fable 5 | Claude Opus 5 | Gemini 3.7 Flash |
GPQA Diamond | 96,0% | 94,6% | 93,7% | 92,6% | 93,2% | 94,5% |
Theoretische informatica | 75,4% | |||||
FrontierMath Tier 1-3 (v2) | 89,0% | 90,2% | 87,0% | 85,6% | 71,6% | |
FrontierMath Tier 4 (v2) | 97,6% | 83.0% | 87,8% | 87,8% | 73,2% | 36,6% |
Humanity’s Last Exam (tools) | 65,0% | 63,8% | 63,6% | |||
Humanity's Last Exam (zonder tools) | 59,1% | 55,5% | 54,9% | 47,9% |
Afstemming
Afstemming | GPT‑6 Astra | GPT‑5.6 Sol | Claude Fable 5.1 | Claude Fable 5 | Claude Opus 5 | Gemini 3.8 Flash |
Veiligheidsbenchmark voor intern computergebruik (lager is beter) | 2,4% | 22,0% | 9,5% | 18,3% | 11,5% | - |
Interne veiligheidsbenchmark voor computergebruik, met Auto-Review (lager is beter) | 1,8% | 4,3% | - | - | - | - |
Interne omzeilingsbenchmark (lager is beter) | 0,00% | 0,29% | - | - | - | - |
ExploitGym-honeypot (lager is beter) | 0,0% | 48,2% | - | - | - | - |
Onmogelijke ExploitGym | 100,0% | - | - | - | - | - |
Interne hallucinatiebenchmark (lager is beter) | 4,2% | 12,2% | - | - | - | - |
Lange context
Lange context | GPT‑6 Astra | GPT‑5.6 Sol | Claude Fable 5.1 | Claude Fable 5 | Claude Opus 5 | Gemini 3.8 Flash |
OpenAI MRCR v2 8-needle 256K-512K | 100,0% | 91,5% | - | - | - | - |
OpenAI MRCR v2 8-needle 512K-1M | 96,3% | 73,8% | - | - | - | - |
Abstract redeneren
| Abstract reasoning | GPT‑6 Astra | GPT‑5.6 Sol | Claude Fable 5.1 | Claude Fable 5 | Claude Opus 5 | Gemini 3.8 Flash |
| ARC-AGI-3 | 99.9% 1 | 7.8% | - | - | 30.2% | - |
| ARC-AGI-2 | 95.0% | 92.5% | 90.0% | 89.2% | 90.4% | - |
| ARC-AGI-1 | 98.5% | 97.5% | 97.5% | 98.5% | 97.5% | - |
De evaluatiescore is de hoogste score die bij een van de inspanningsniveaus is behaald. GPT‑evaluaties zijn uitgevoerd in onze onderzoeksomgeving of via onze API. Door verschillen in onder meer systeemprompts en beschikbare hulpmiddelen kan de output enigszins afwijken van die van de productieversie van ChatGPT.
FOOTNOTES
- 1
On ARC-AGI-3, GPT-6 Astra was run with our responses API harness, which changes two settings to better match real-world performance. The changes do not specifically target ARC-AGI-3.
- 2
GPT-5.6 Sol refers to the version available in our API, ChatGPT Codex, and ChatGPT Work. The version in ChatGPT Chat is slightly different.
- 3
OSWorld V2-Offline is a subset of the original OSWorld V2 that works without internet access. Claude model performance on OSWorld-V2 Offline was reproduced by the authors on the official leaderboard(opent in een nieuw venster). On OSWorld 2.0, the scores for Claude use the official settings, and not the modified tasks and modified grading from the Fable 5.1 System Card.
- 4
- 5
On BenchCAD, Claude's scores reflect 3 modifications to the eval, detailed in the Fable 5.1 System Card(opent in een nieuw venster).
- 6
Guang Yang, Victoria Ebert, Nazif Tamer, Brian Siyuan Zheng, Luiza Pozzobon, and Noah A. Smith. “LEGATO: Large-scale End-to-end Generalizable Approach to Typeset OMR(opent in een nieuw venster).” arXiv:2506.19065, 2025.
- 7
Mark R. H. Gotham, Maureen Redbond, Bruno Bower, and Peter Jonas. “The OpenScore String Quartet Corpus(opent in een nieuw venster).” Proceedings of the 10th International Conference on Digital Libraries for Musicology, pp. 49–57. ACM, 2023.
- 8
On FrontierCode, GPT-6 Astra was run with a developer message similar to a section of its developer message in Codex(opent in een nieuw venster): "Avoid creating excessive test files. Create a new test file only when required by repository conventions or when no existing file is a suitable home. Avoid unrelated cleanup and unnecessary complexity. Reuse suitable existing utilities. Read relevant repository instructions and inspect nearby code, tests, documentation, and CI. Follow established conventions. The goal is clean, mergeable code." The prompt was not optimized for the eval.
- 9
The first concerns how close together prime numbers can occur, however far along the number line you go. For more than a decade, the best known result established that infinitely many pairs of primes are at most 246 apart. Julia Stadlmann(opent in een nieuw venster) recently improved that bound to 240. Astra helped establish a stronger bound of 186, showing that infinitely many pairs occur within this smaller distance. Short prime gaps: Proof(opent in een nieuw venster) and supporting research(opent in een nieuw venster).
- 10
The second concerns unusually large gaps between primes. Astra improved a term in a bound on these gaps that had remained unchanged for more than 80 years. We’re sharing the proofs and abridged chain of thought and verification materials for both results. Large prime gaps: Proof(opent in een nieuw venster) and supporting research(opent in een nieuw venster).
- 11
- 12
- 13
- 14
ExploitBench (June–August 2026) contains 20 high-severity V8 vulnerabilities across 13 stable Chrome releases. The benchmark tests whether agents can achieve arbitrary code execution in V8 and official Chrome releases for Linux by exploiting each specified vulnerability. Some included vulnerabilities may not permit arbitrary code execution under the evaluation’s constraints, so a 100% success rate may not be achievable. Note: the 5.5% score of GPT-5.6 Sol is an artifact of the 300-turn limit in the benchmark, which is not a limit that real customers using max would have. The model at similar settings achieved an 11.5% score when hitting fewer limits.
- 15
Jeremy Spence et al. “The Next Challenge for Agentic Cybersecurity: A Realistic, Contamination-Free Reverse Engineering Benchmark(opent in een nieuw venster).” arXiv:2608.11469v1, 2026.
- 16
When we test across third-party models, we use a simpler research setup. Codex has a more complex production configuration, which can result in different raw-model error rates. Provider-side safeguards and computer-tool implementations still differ. Users do not experience the no-confirmation scenario in Codex, as it's an internal research configuration.
- 17
