OpenAI

GPT-6 Astra: A new generation of intelligence

新一代智慧

我們推出 GPT‑6 Astra,全球最智慧、最符合人類價值觀的模型。

GPT‑6 Astra 結合了多年研究成果,以及在預訓練、強化學習和對齊方面的重大投入。Astra 在電腦操作、網頁瀏覽、軟體工程、網路安全、科學和專業工作方面具備最先進的能力。Astra 在 FrontierMath(第 4 級)達到飽和,取得 98% 的分數,在此之前已協助解決數學中長期懸而未決的開放問題。Astra 也在 ARC-AGI-3 上取得 99.9% 的分數,並在 ExploitBench 上取得 100% 的分數,表現均已達到這些評估所能衡量的上限。它也為電腦與瀏覽器使用開創新前沿,以無與倫比的速度、準確度與判斷力,處理最嚴苛的專業工作。

GPT‑6 Astra 今天起將率先向部分機構推出,並將於未來數天內開放給所有 ChatGPT Plus、Pro、Business 及 Enterprise 用戶使用,同時也可透過 OpenAI API、Microsoft Azure 及 AWS Bedrock 使用。

「在 ARC-AGI-3 中,Astra 在 96% 的關卡上超越我們的人類行動效率基準,實際上在這項基準測試中達到與人類同等水平。這不僅是我們測試過的最佳模型,更代表前沿模型的表現取得實質躍進:除了更擅長探索及解決陌生環境,學習如何做到這一點的效率也有所提升。」
Greg Kamradt,ARC Prize Foundation

Astra 是我們最符合人類意圖的模型,在理解使用者意圖及約束自身行為方面都有顯著進步,因此你可以更有信心地將任務委派給 Astra,相信它的判斷。為了測試這項能力,我們參考 Hugging Face 事件設計了一項新評估,測試模型在面對困難或不可能完成的任務時,是否會超出預期的任務範圍。GPT‑5.6 Sol 在未採生產環境防護措施的情況下,有 48% 的測試案例超出授權目標;相較之下,GPT‑6 Astra 則從未出現這種情況。

全球最佳的電腦使用模型

GPT‑6 Astra 在電腦操作的速度、準確性與安全性方面帶來重大突破。Astra 能處理繁瑣工作,例如填寫線上表單、更新 CRM 中的客戶紀錄,以及整理行事曆。Astra 能進行線上研究,並在你的電子郵件或文件編輯器中草擬摘要。Astra 能分析科學資料、產生圖表、建立網站,並執行前端 QA 檢查,確認網站上的所有功能均能正常運作。Astra 能協助你自動安裝和測試軟體,並排解你在螢幕上看到的問題。這些改進也反映在我們領先業界的評估結果中。

這些模型評估所展現的進步,也能在實際知識工作任務中提升效率。在 OSWorld 2.0 延遲模擬中,Astra 的電腦操作表現更佳,每項任務所需時間比 GPT‑5.6Sol 少約 47%:Astra 每項任務約需 40 分鐘,得分為 72.6%;Sol 則約需 75 分鐘,得分為 65.7%3

GPT‑6 Astra 的電腦操作能力在各領域的輸出中展露無遺,包括遊戲開發、電機工程,以及日常知識工作:

Alongside Astra, we are also updating the Codex harness to significantly improve the speed of computer use. Combined with Astra’s efficiency, this translates to a 1.9x faster task completion compared to the current GPT‑5.6 Sol experience, on the Mind2Web benchmark. The model’s improvements on speed mean it can take on many time-consuming life tasks for you, faster than you can.4

「我們在發布當天就將 GPT‑6 Astra 整合到 Devin 的任務執行框架,並在我們的內部測試基準中展現出最先進的效能。它在電腦操作、寫作及程式碼庫理解方面表現出色,令測試體驗從一開始便有所改善:影片明顯更容易理解,報告也更清晰精簡。」
Silas Alberti,Cognition 研究資深副總裁

專業工作的重大躍進

GPT‑6 Astra 將更進步的電腦操作能力與專業環境專用訓練結合,可協助處理複雜工作。它既具備解決複雜問題所需的智慧,也能執行多步驟工作流程,製作完善的文件、試算表和簡報。

GPT‑6 Astra 是我們最擅長遵循既有範本的模型,能製作版面配置良好、透過結構化敘事簡潔傳達重點的投影片。Astra 能建立清楚、架構完整的文件、簡報、試算表與分析,遵循你的範本,並符合你的寫作與視覺風格。Astra 也經過專門訓練,僅將重要的背景資料納入輸出內容,而非重複與目前工作無關的資訊。因此,Astra 能產出符合你的業務情境與標準,而且可直接使用的成品。

GPT‑6 Astra 在建立網站、遊戲、應用程式及渲染圖時,也展現出更強的視覺判斷力。透過 ChatGPT 中的工作站(在新視窗中開啟),Astra 可以直接根據提示詞建立、託管並分享網站、網頁應用程式和遊戲。

「Astra 讓我們在能力與效率兩方面都具備顯著優勢。Astra 能順利執行我們最複雜的創意工作流程,Token 用量最多可比其他受測模型減少 20%。最重要的是,對我們的客戶而言,這代表更高品質的輸出。」
Alex Mashrabov,Higgsfield AI 執行長暨共同創辦人

當指示存在詮釋空間時,GPT‑6 Astra 比以往的模型更能作出適當判斷。它會利用情境填補常見的資訊缺口,並在答案可能改變結果時提出具針對性的問題。在 Codex 中,它可以非同步方式提問,同時繼續處理不需要等你回覆的工作。如果你沒有回覆,它會視情況採用合理假設;遇到影響重大的決策,則會等待你的意見。

以下範例呈現 Astra 如何協作處理日常任務中足以左右答案的資訊缺口。

Astra 也更擅長在任務不斷演變時掌握整體方向。較早期的模型有時會將引導訊息視為新目標,因而忽略原始請求或先前的限制。Astra 會納入新的要求、按指示調整方向,並在不偏離整體任務的情況下回答附帶問題。

「在複雜法律任務上,Astra 相較於 GPT‑5.6 Sol 品質顯著提升。在我們的早期測試中,Astra 之所以脫穎而出,是因為處理法律工作時,Astra 就像經驗老到的律師:分得清文件內容和已確認的紀錄,會指出缺乏依據的假設;遇到資訊不足時,也會明確提出條文該怎麼寫、應採取什麼立場。」
Niko Grupen,Harvey 應用研究部門主管

寫程式

GPT‑6 Astra 是迄今最出色的軟體工程模型。

1 之 2
「GPT‑6 Astra 在我們的內部編碼基準測試中達到頂尖水平,在交易直覺評估方面亦較 GPT‑5.6 Sol 明顯進步。用於智慧體式程式碼編寫時,GPT‑6 Astra 的溝通方式讓開發人員更容易掌握,所產生的程式碼亦只需較少反覆修改,便可達到生產級品質。」
John Crepezzi,AI 助理,Jane Street

透過 Astra,我們為 Codex 推出一種在上下文視窗用盡時保留及找回內容的新方法。過去,模型會在長時間工作階段中,例如在偵錯複雜問題或處理大規模重構時,運用壓縮上下文來摘要工作內容。每次壓縮都可能遺漏某項修正為何失敗,或某個元件如何運作的詳細資訊。在 Codex 中,Astra 可以跨上下文視窗保留筆記,保存累積的細節,不必反覆把所有內容壓成一份摘要。先前的上下文視窗仍可供搜尋,即使筆記未收錄相關資訊,Astra 仍可從先前的訊息和工具輸出中找到需求或測試結果。你可以在 Codex 的 config.toml(在新視窗中開啟) 中啟用這項實驗功能,這項功能將在未來幾週內成為 Astra 的預設設定。

推動科學發現

「故事是這樣的:一個時代的結束,另一個時代的開始。」
Greg Burnham,EpochAI

GPT‑6 Astra is a major advance for scientific discovery, mathematics, and health. Today, we’re sharing two further results on the gaps between prime numbers.910

Astra also sets new records across a suite of math and science evaluations.

Astra 能協助處理科學探索過程中的各項實務工作。Astra 結合科學推理與電腦操作能力,可以直接使用專業軟體檢視資料、探索結果,協助研究人員評估證據,並決定接下來要研究的方向。

資安

As we discussed in our safety update, Astra is a significant jump in cyber capabilities and meets the Critical threshold in cybersecurity under our Preparedness Framework. Its ability to identify and develop zero-day exploits can help defenders find and patch weaknesses, but it also creates a need for stronger safeguards. To understand how far these capabilities extend, we ran Astra on internal and third-party expert evaluations.

We first tested the model without production safeguards on ExploitBench and ExploitGym, which evaluate whether models can turn known software vulnerabilities into working exploits. On ExploitBench, Astra achieved a perfect score of 100%, compared with 78.5% for GPT‑5.6 Sol, our previous frontier cyber-capable model. On ExploitGym, Astra reached a 42.4% success rate, compared with 30.3% for GPT‑5.6 Sol, while using substantially fewer output tokens.13

Given concerns that exposure to historical software vulnerabilities may have affected benchmark results, we also evaluated Astra on two novel benchmarks. For one, we built an internal “ExploitBench (June–August 2026)” evaluation to test exploit development using vulnerabilities from the previous three months.14 Astra achieved substantially higher arbitrary code-execution rates than GPT‑5.6 Sol on this dataset while using far fewer output tokens. During the evaluation, Astra even discovered and used two previously unknown zero-day vulnerabilities. We are disclosing both vulnerabilities to their maintainers.

We also tested Astra on SRE-Bench15, a benchmark that measures whether models can reverse engineer software binaries to understand its core logic without access to raw source code. Astra solved 88.0% of tasks in a single attempt and 99.2% within four attempts, compared with 55.9% and 68.7% for GPT‑5.6 Sol, respectively.

Beyond benchmarks, expert-led assessments found that Astra, when run without production safeguards, could use previously unknown vulnerabilities to achieve arbitrary code execution in hardened browsers and create privilege-escalation exploits for hardened operating-systems.

As we discussed in The Defender’s Window, frontier cyber capabilities can help defenders find weaknesses faster, but they also make those weaknesses easier to exploit, raising the urgency for defenders to adapt. With the version of Astra launching today, defenders can use it to complete tasks such as secure code review and patching.

However, Astra will refuse to comply with more advanced cybersecurity tasks such as creating proof-of-concept exploits for vulnerabilities. Through OpenAI Daybreak, we plan to expand access and roll out less restrictive safeguards in the coming weeks. This will enable more defensive workflows, including vulnerability and proof-of-concept validation, malware analysis, and detection engineering.

We have also strengthened our protections against potential cyber misuse, building upon our safeguards stack for GPT‑5.6 Sol. These include stronger model robustness to better withstand potential jailbreaks and more context for our monitoring systems. We have continued rigorous internal and external testing, including automated evaluations with our internal red-teaming attackers. More details about our cyber safeguards and testing are available in the Astra safety overview and system card(在新視窗中開啟)..

負責任地對齊與部署 GPT‑6 Astra

Astra 是我們對齊程度最高的模型。Astra 擅長謹慎行事、尊重任務界線,並保持透明溝通。這項工作是我們長期研究計劃的最新成果,該計劃專注於訓練由始至終都與人類意圖保持一致的模型。

在敏感環境中,Astra 會按其風險程度謹慎行事。在一項電腦操作任務評估中,任務經對抗性挑選,旨在誘發不當行為;Astra 更能避免非預期後果。配合預設提供的額外系統防護措施後,表現更佳。

Astra causes fewer misaligned outcomes than any other frontier models tested. For a fair comparison, we used a generic computer-using-agent harness (based on the native computer use tools available in both the OpenAI Responses API(在新視窗中開啟) and Anthropic Messages API(在新視窗中開啟)) and without additional protections that are normally deployed to Codex and ChatGPT Work users (auto-review, confirmation policy). 16

Astra 也更有可能遵守使用者設定及環境所隱含的界限。在一項內部評估中,Astra 從未嘗試規避 Codex 自動審查的否決。即使自動審查被刻意設定成可以規避,且除此以外無法完成任務,情況亦然。Astra 遵守環境限制的表現,與我們在本文開頭分享的不可能完成的網路安全任務評估結果,以及系統說明卡(在新視窗中開啟)中記錄的其他發現一致。

Astra additionally sets new marks in transparent user communication. In one evaluation, Astra is three times less likely than GPT‑5.6 Sol to make inaccurate representations about its capabilities and affordances.

在我們的能力幻覺評估中,Astra 相較於 GPT‑5.6 Sol 展現出顯著提升,對自身能力做出誤導性陳述的情況也更少。

Our evaluations found Astra’s written reasoning harder to monitor than GPT‑5.6 Sol’s, based on tests that explicitly asked it to evade monitoring. We attribute this to Astra’s greater control over written reasoning on simpler tasks and ability to solve problems with fewer written steps. Astra still appears to struggle to conceal the reasoning needed for complex tasks, but we take the decline seriously. Improving monitorability remains a research priority, and the accompanying system card(在新視窗中開啟) details our findings and ongoing work.

Alignment training is core to our approach to deployment. As an additional layer of defenses, we also build system safeguards like Codex Auto-review(在新視窗中開啟) and monitoring agents’ reasoning and actions to help detect and contain unsafe behavior. As described in our safety update, we are also deploying misalignment monitoring in production for Astra-class models in order to have visibility into misalignment, and help contain its worst instances. These safeguards resemble our monitoring for internal deployments and involve a system of classifiers which check the model’s reasoning and actions for unauthorized behavior and automatically stop potentially unauthorized activity.

Given the significant increase in Astra’s cybersecurity capabilities, we are being especially careful to make this deployment safe and secure. Extra safety checks can sometimes slow, pause, or stop legitimate work, including defensive cybersecurity. If a task is paused in ChatGPT or Codex, you may be asked to review the action before continuing. In the API, the task will stop. These checks can sometimes interrupt legitimate work, and we are continuing to iterate on this system to reduce unnecessary interruptions. Misalignment monitoring cannot replace alignment: our goal is to build models that reliably stay within their authorized scope, so these protections do not need to intervene.

適用情況

GPT‑6 Astra is rolling out today to a limited set of organizations and over the coming days will become available to all ChatGPT Plus, Pro, Business, and Enterprise users, as well as through the OpenAI API, Microsoft Azure, and AWS Bedrock. Astra usage is included within the existing subscription allowances—users and businesses will also be able to purchase credits for additional usage. Users on the Pro, Business, and Enterprise plans will also get access to GPT‑6 Astra Pro. Enterprise administrators can enable Astra for their workspace; access is off by default at launch.

Astra supports Zero Data Retention for eligible API customers, and as we shared last month, we're testing Private Safety Processing to strengthen safety monitoring while preserving customer privacy.

For developers, GPT‑6 Astra will be available in the OpenAI API as gpt-6-astra and through Microsoft Azure and Amazon Bedrock.

OpenAI API Standard pricing is $10 per million input tokens and $50 per million output tokens. Separate rates apply to cache reads and writes. Fast mode is available for GPT‑6 Astra in the API and delivers up to 2x the speed of Standard processing at 2x the Standard price.

電腦操作

Computer Use

GPT‑6 Astra

GPT‑5.6 Sol2

Claude Fable 5.1

Claude Fable 5

Claude Opus 5

Gemini 3.8 Flash

Agents' Last Exam

59.3%

53.6%

-

48.7%

55.5%

-

OSWorld 2.0 (v2026.08.08, offline set, partial score)

72.6%

65.7%

-

-

70.2%3

-

ScreenSpot-Pro (no tools)

92.7%

76.9%

-

87.3%17

-

-

Professional

Professional

GPT‑6 Astra

GPT‑5.6 Sol

Claude Fable 5.1

Claude Fable 5

Claude Opus 5

Gemini 3.8 Flash

AutomationBench

41.4%

18.1%

31.4%

17.4%

26.9%

-

BenchCAD

95.9%

83.3%

84.3% 5

67.5% 5

82.1% 5

-

BrowseComp

91.5%

90.4%

-

87.4%

90.8%

-

OpenScore String Quartets (1 - OMR-NED)

0.84

0.19

-

-

-

-

Internal Design Tasks

50.0%

47.4%

-

35.8%

-

-

Internal Data Science Tasks

40.9%

30.5%

-

34.7%

-

-

Artificial Analysis Intelligence Index v4.1.1

61.2

60.9

65.7

62.1

63.1

58.7

Coding

CodingGPT‑6 AstraGPT‑5.6 SolClaude Fable 5.1Claude Fable 5Claude Opus 5Gemini 3.8 Flash
Terminal-Bench 4.057.9%37.3%55.8%44.5%52.6%19.1%
DeepSWE v1.174.1%72.7%67.4%69.9%73.7%73.8%
FrontierCode 1.1 Extended (score)64.5% 860.6%63.6%64.9%63.6%56.3%
FrontierCode 1.1 Main (score)53.3% 847.5%50.9%53.5%53.4%43.6%
Internal Database Migration Tasks63.9%42.7%57.8%50.3%--
Artificial Analysis Coding Agent Index v1.467.065.1-67.268.161.2

Academic

Academic

GPT‑6 Astra

GPT‑5.6 Sol

Claude Fable 5.1

Claude Fable 5

Claude Opus 5

Gemini 3.8 Flash

Terminal-Bench Science 0.1

64.6%

22.4%

52.6%

21.4%

30.0%

-

FrontierMath Tier 4 (v2)

97.6%

83.0%

87.8%

90.2%

73.2%

-

GPQA Diamond

96.0%

94.6%

93.7%

92.6%

93.7%

95.3%

Humanity's Last Exam (w/ tools)

57.2%

-

65.0%

63.8%

63.6%

-

科學與健康

Science and HealthGPT‑6 AstraGPT‑5.6 SolClaude Fable 5.1Claude Fable 5Claude Opus 5Gemini 3.8 Flash
GeneBench Pro37.1%32.3%----
MedChemBench (Internal)49.3%47.4%----
LifeSciBench60.3%59.9%----
HealthBench Professional (length-adjusted)63.4%60.5%58.1% 1160.9% 1156.4% 1152.1%

資安

CybersecurityGPT‑6 AstraGPT‑5.6 SolClaude Fable 5.1Claude Fable 5Claude Opus 5Gemini 3.8 Flash
ExploitBench100.0%78.5%--70%-
ExploitGym42.4% 1330.3% 1330.4% 1728.4%1722.0%-
ExploitBench (June-Aug 2026)39.0%5.5%----
SRE-Bench88.0%55.9%--12.5%-
SEC-Bench Pro85.4%79.1%----

對齊性

對齊性

GPT‑6 Astra

GPT‑5.6 Sol

Claude Fable 5.1

Claude Fable 5

Claude Opus 5

Gemini 3.8 Flash

內部電腦操作安全基準測試(越低越好)

2.4%

22.0%

9.5%

18.3%

11.5%

-

內部電腦操作安全基準測試(設有自動審查,越低越好)

1.8%

4.3%

-

-

-

-

內部規避行為基準測試(越低越好)

0.00%

0.29%

-

-

-

-

ExploitGym 蜜罐(越低越好)

0.0%

48.2%

-

-

-

-

ExploitGym(不可能任務)

100.0%

-

-

-

-

-

內部幻覺基準測試(越低越好)

4.2%

12.2%

-

-

-

-

長上下文

長上下文

GPT‑6 Astra

GPT‑5.6 Sol

Claude Fable 5.1

Claude Fable 5

Claude Opus 5

Gemini 3.8 Flash

OpenAI MRCR v2 8-needle 256K-512K

100.0%

91.5%

-

-

-

-

OpenAI MRCR v2 8-needle 512K-1M

96.3%

73.8%

-

-

-

-

抽象推理

Abstract reasoningGPT‑6 AstraGPT‑5.6 SolClaude Fable 5.1Claude Fable 5Claude Opus 5Gemini 3.8 Flash
ARC-AGI-399.9% 17.8%--30.2%-
ARC-AGI-295.0%92.5%90.0%89.2%90.4%-
ARC-AGI-198.5%97.5%97.5%98.5%97.5%-

評估分數取各種推理強度中的最高分。GPT 評估在我們的研究環境中或透過我們的 API 進行;由於系統提示詞、可用工具等有所不同,其輸出可能與生產環境中的 ChatGPT 略有差異。

FOOTNOTES

  1. 1

    On ARC-AGI-3, GPT-6 Astra was run with our responses API harness, which changes two settings to better match real-world performance. The changes do not specifically target ARC-AGI-3.

  2. 2

    GPT-5.6 Sol refers to the version available in our API, ChatGPT Codex, and ChatGPT Work. The version in ChatGPT Chat is slightly different.

  3. 3

    OSWorld V2-Offline is a subset of the original OSWorld V2 that works without internet access. Claude model performance on OSWorld-V2 Offline was reproduced by the authors on the official leaderboard(在新視窗中開啟). On OSWorld 2.0, the scores for Claude use the official settings, and not the modified tasks and modified grading from the Fable 5.1 System Card.

  4. 4

    Model times are the reported elapsed times for the corresponding demonstration runs. The displayed clips are edited excerpts.

  5. 5

    On BenchCAD, Claude's scores reflect 3 modifications to the eval, detailed in the Fable 5.1 System Card(在新視窗中開啟).

  6. 6

    Guang Yang, Victoria Ebert, Nazif Tamer, Brian Siyuan Zheng, Luiza Pozzobon, and Noah A. Smith. “LEGATO: Large-scale End-to-end Generalizable Approach to Typeset OMR(在新視窗中開啟).” arXiv:2506.19065, 2025.

  7. 7

    Mark R. H. Gotham, Maureen Redbond, Bruno Bower, and Peter Jonas. “The OpenScore String Quartet Corpus(在新視窗中開啟).” Proceedings of the 10th International Conference on Digital Libraries for Musicology, pp. 49–57. ACM, 2023.

  8. 8

    On FrontierCode, GPT-6 Astra was run with a developer  message similar to a section of its developer message in Codex(在新視窗中開啟): "Avoid creating excessive test files. Create a new test file only when required by repository conventions or when no existing file is a suitable home. Avoid unrelated cleanup and unnecessary complexity. Reuse suitable existing utilities. Read relevant repository instructions and inspect nearby code, tests, documentation, and CI. Follow established conventions. The goal is clean, mergeable code." The prompt was not optimized for the eval.

  9. 9

    The first concerns how close together prime numbers can occur, however far along the number line you go. For more than a decade, the best known result established that infinitely many pairs of primes are at most 246 apart. Julia Stadlmann(在新視窗中開啟) recently improved that bound to 240. Astra helped establish a stronger bound of 186, showing that infinitely many pairs occur within this smaller distance. Short prime gaps: Proof(在新視窗中開啟) and supporting research(在新視窗中開啟).

  10. 10

    The second concerns unusually large gaps between primes. Astra improved a term in a bound on these gaps that had remained unchanged for more than 80 years. We’re sharing the proofs and abridged chain of thought and verification materials for both results. Large prime gaps: Proof(在新視窗中開啟) and supporting research(在新視窗中開啟).

  11. 11

    We independently evaluated all Claude models following the intended HealthBench Professional procedure, using GPT‑5.4 grading and length-adjusted, unclipped scores. For Fable 5.1, we used Opus 5 fallback for provider refusals.

  12. 12

    Claude Fable 5 and 5.1 are not included in LifeSciBench Gold v1, GeneBench Pro v13, and MedChemBench because they refuse the majority of questions in these evaluations.

  13. 13

    On ExploitGym, we tested Astra and Sol without the 6-hour time limit, to better assess their full cyber capabilities. They are fast enough that it has little impact.

  14. 14

    ExploitBench (June–August 2026) contains 20 high-severity V8 vulnerabilities across 13 stable Chrome releases. The benchmark tests whether agents can achieve arbitrary code execution in V8 and official Chrome releases for Linux by exploiting each specified vulnerability. Some included vulnerabilities may not permit arbitrary code execution under the evaluation’s constraints, so a 100% success rate may not be achievable. Note: the 5.5% score of GPT-5.6 Sol is an artifact of the 300-turn limit in the benchmark, which is not a limit that real customers using max would have. The model at similar settings achieved an 11.5% score when hitting fewer limits.

  15. 15
  16. 16

    When we test across third-party models, we use a simpler research setup. Codex has a more complex production configuration, which can result in different raw-model error rates. Provider-side safeguards and computer-tool implementations still differ. Users do not experience the no-confirmation scenario in Codex, as it's an internal research configuration.

  17. 17

    For ScreenSpot-Pro and ExploitGym, the Fable scores we report come from Mythos, which is Fable with fewer safeguards.