The Intake
The Intake — Thursday, September 4, 2026
On the substrate
GPT-6 Astra is first OpenAI model rated Critical for cybersecurity
OpenAI The Hacker News Simon Willison
If you've been running model-assisted security work and directing each exploitation step yourself, GPT-6 Astra marks a shift in what the model handles autonomously. OpenAI released Astra on September 3, 2026.
The model carries OpenAI's Critical cybersecurity rating under their Preparedness Framework — the highest tier that framework defines. That designation means the model can identify and exploit vulnerabilities in hardened systems without step-by-step human direction. During pre-release evaluation, Astra independently discovered two previously unknown zero-day vulnerabilities. OpenAI is coordinating disclosure to the affected software maintainers.
OpenAI reports Astra scored 100% on ExploitBench, a benchmark measuring the conversion of known software vulnerabilities into working exploits. GPT-5.6 Sol scored 78.5% on the same benchmark. Jailbreak refusal rate is 91.5%. GPT-5.6 Sol's was 59%. The context window is 1,050,000 tokens with an April 2026 knowledge cutoff. Input pricing is $10 per million tokens. Output pricing is $50 per million tokens — matching Claude Fable 5.1's rate. The API identifier is gpt-6-astra.
If you're running authorized vulnerability research or red-team exercises via API, the model can now identify and exploit vulnerabilities without step-by-step direction from you.
---
For operators
OpenAI subsidizes frontier security model access for critical infrastructure and open-source defenders
OpenAI The Register Help Net Security
If AI-powered security tooling has been out of reach on budget — you operate water systems, maintain open-source infrastructure, or run a public-sector service — OpenAI opened an application path today. Daybreak for Frontline Defenders launched September 4, 2026. OpenAI is committing $1 billion in subsidized access, training, and technical support.
Eligible organizations include operators of water and wastewater systems, electric grid operators, state and local governments, community and regional banks, nonprofits, and open-source maintainers. Applicants choose between two tiers. Daybreak Blue covers defensive cybersecurity workflows only. Daybreak Red covers authorized offensive security testing. The tier determines both what access the organization receives and what the model will execute on their behalf.
OpenAI expects credits to be used within six months. The program launches with a pilot through the MS-ISAC. Initial cohort: water-system and public-sector defenders. Eligible organizations apply through OpenAI's website.
If you're running an open-source project or critical service that qualifies, the application decision is live: which tier's scope — defensive-only or authorized offensive access — matches what you'd actually use it for.
---