← All postsSeptember 7, 2026

OpenAI's GPT-6 Astra and the 'AGI Era' Claim: What Actually Changed

OpenAI rolled out its newest model, GPT-6 Astra, on September 3, starting with a limited preview before opening up to ChatGPT Plus, Pro, Business, and Enterprise users and through the API. Alongside the release, OpenAI president Greg Brockman told reporters it's "not unreasonable" to think this model marks the start of what he called the AGI era, closing the briefing with "welcome to the AGI era." That line got most of the headlines. It's not the part I'd pay attention to.

Skip the AGI debate

"Is this AGI" is a marketing framing dressed up as a milestone, and it's happened before — plenty of past releases were called a leap toward general intelligence, and the definition conveniently moves each time. I'm not saying Astra isn't a real capability jump; independent early benchmarks back that up. I'm saying the AGI label doesn't change anything about how you'd use the tool day to day, so it's not worth spending your attention on.

The part that's actually new

Buried under that headline is a more concrete fact: according to OpenAI's own published safety documentation, Astra is the first model the company has ever rated "Critical" for cybersecurity under its internal risk framework. In plain terms, OpenAI says the model can find previously unknown flaws in hardened systems and build working exploits for them largely without a person walking it through each step — and in pre-release testing, it reportedly did find real, previously unknown vulnerabilities this way. OpenAI says it added extra restrictions on cyber-related requests in the version it shipped to the public.

That's the signal worth reacting to, not the AGI branding. It doesn't mean panic — most small businesses were never the target of custom, human-driven exploit development anyway. But it's one more data point that the tools available to attackers (and to the researchers finding flaws before attackers do) are getting more capable, faster than most patch-management habits are built for. The practical response hasn't changed, it's just gotten more urgent:

  • Keep software, plugins, and themes on auto-update where you can, and check the rest on a regular schedule
  • Turn on MFA everywhere it's offered, especially for anything with admin access
  • Don't treat "nobody would bother targeting us" as a security plan — increasingly, "bother" is cheap

None of this requires a new tool or a new vendor. It's the same basic hygiene that's always mattered, just with a little more reason not to put it off.

Sources: