Share

FIRSTonline Banner

OpenAI launches Astra, the AI ​​that works alone on computers: what it is and why it could be dangerous

The new model can use browsers and applications, develop software, and tackle complex professional tasks. OpenAI calls it the most powerful and reliable ever made, but acknowledges its "critical" computing capabilities. Its launch comes just three days after a stark warning about the risks.

OpenAI launches Astra, the AI ​​that works alone on computers: what it is and why it could be dangerous

OpenAI has launched GPT-6 Astra, Its most advanced artificial intelligence model, capable not only of answering questions, but also of use computers independently, browsers, and programs to complete complex tasks. It can fill out online forms, update company records, organize a calendar, conduct research, prepare documents and presentations, analyze scientific data, create websites, and develop software. Sam Altman's company presented Astra as its "smartest and most aligned" system, the result of years of research into model training and security. The debut, however, was accompanied by unusual precautions. OpenAI has acknowledged that its cybersecurity capabilities have reached the “Critical” level, the highest ever awarded by the company to one of its models.

The distribution will start from a limited number of organizationsIn the coming days, Astra will be available to ChatGPT Plus, Pro, Business, and Enterprise users, as well as developers via the OpenAI, Microsoft Azure, and Amazon Bedrock APIs. Access for enterprises will initially be disabled and will need to be authorized by administrators.

Astra: from digital assistant to agent capable of working

Astra represents OpenAI's attempt to transform ChatGPT from a digital interlocutor into a real operational agentThe model can receive a goal, break it down into multiple steps, and continue working even when the task requires the use of different programs. Therefore, it doesn't just explain how to complete a task. You can intervene directly within IT tools, open web pages, edit documents, analyze files, and verify the final result. In the tests cited by OpenAI, it was also used to design electronic circuits, develop three-dimensional models and check the functioning of websites and applications.

The most significant improvement concerns the ability to stay focused during long tasks. Previous models could lose some details when a conversation became very long or interpret a new request as a complete change of objective. Astra, according to the company, is able to retain requirements, results, and previous attempts, correcting its path without forgetting the work already done.

OpenAI also claims that the new model is better able to assess when to proceed autonomously and when to ask for clarification. If secondary information is missing, it can make a reasonable guess; if the decision risks significantly changing the outcome, it should stop and ask the user.

What Astra promises, between work, science and hypotheses Agi

Le ambitions OpenAI's capabilities range from office work to programming to scientific research. Astra has been trained to produce documents, spreadsheets, and presentations that are already close to the standards required by companies, respecting graphic templates and writing styles provided by users. It can also work within specialized software to examine data, run simulations, and help researchers pinpoint the most important insights.

In the results released by the company, Astra scores 98% on FrontierMath Tier 4, dedicated to particularly complex mathematical problems, and reaches 99,9% on Arc-Agi-3, a test designed to assess the ability to navigate unfamiliar environments and learn their rules. It also outperforms previous models in tests on professional activities and computer use, completing some tasks in significantly shorter times. The numbers, however, require cautionPerformance can vary depending on the infrastructure, memory, and the amount of resources made available to the model. In a standardized configuration, Astra's score on Arc-AGI-3 drops to around 63%. Furthermore, beating a benchmark doesn't automatically demonstrate human-like general intelligence.

OpenAI President and Co-Founder, Greg Brockman, however, has chosen a formula destined to fuel the debate. "Welcome to the Age of Agi“, he declared during the presentation. Agi, or general artificial intelligence, is OpenAI's historical goal and indicates a highly autonomous system, capable of surpassing humans in most economically relevant tasks. Astra doesn't settle the discussion, but it does demonstrate how the line between chatbot and autonomous agent is becoming increasingly blurred.

Cybersecurity risk and the flaws discovered by the model

The same autonomy that makes Astra more useful can transform it into a dangerous instrumentThe model is able to identify unknown computer vulnerabilities and develop methods to exploit them, without requiring one person to lead every single step.

In the ExploitBench benchmark, which measures the ability to build attacks based on known vulnerabilities, Astra scored 100%, compared to 78,5% for GPT-5.6 Sol. OpenAI then subjected it to an evaluation based on vulnerabilities disclosed between June and August 2026. During these tests, the system discovered and exploited two zero-day vulnerabilities, i.e., security issues not yet known and with no available fix. The company disclosed the vulnerabilities to the developers of the affected software.

In controlled environments, Astra was also able to compromise hardened browsers and operating systems, executing commands on the computer and gaining administrative privileges. These capabilities can help network and infrastructure defenders find and fix vulnerabilities more quickly, but they could also offer a huge advantage to criminal groups or hostile entities.

There is a second concern. OpenAI has found that Astra's written reasoning is more difficult to monitor than that of GPT-5.6 Sol. The model appears capable of solving some problems with fewer explicit steps, and in tests designed to test it, it was better at hiding some of its intentions from control systems. The company claims it hasn't observed any spontaneous use of sophisticated obfuscation techniques, but still considers the deterioration in monitorability a serious problem.

The launch follows the warning and protections introduced by OpenAI

The timing makes the debut even more delicate. On September 1st, just three days before the presentation, OpenAI had published an update in which it admitted that Astra had achieved “critical” computing capabilitiesThe company explained that it had postponed some phases of development and release to strengthen defenses against abuse and unauthorized actions.

The decision also came after the accident involving the Hugging Face open source platform, (society just bought by Nvidia) where OpenAI agents had compromised external systems and attempted to erase traces of their actions. Astra was not involved, but the episode prompted the company to temporarily suspend some training and introduce stricter controls.

OpenAI claims to now have reached a sufficient level of security to proceedAstra was trained to reject malicious requests more frequently, and in tests of attempts to bypass protections, it rejected 91,5 percent of disallowed instructions, compared to 59 percent for GPT-5.6 Sol. In another evaluation, it never attempted to bypass a block imposed by automatic review.

The version available to the public It will also not be able to create demonstration exploits for more advanced vulnerabilitiesThe most sensitive capabilities will initially be reserved for a select group of verified users and subsequently expanded through the Daybreak program, aimed primarily at defensive applications.

But meanwhile, on the cybersecurity front, OpenAI has announced a billion dollar investment facilitated access to tools, training, and support for organizations protecting essential services such as power grids, water systems, local governments, community banks, and nonprofits. This is the response to a risk that the company itself considers imminent. In the coming months, OpenAI warned, AI-powered cyber attacks will become “much more widespread and sophisticated.”

Astra is therefore born within a contradiction that will increasingly accompany cutting-edge models. The capabilities that can make software and infrastructure more secure are the same ones that could facilitate attacks. OpenAI has chosen not to halt the launch, relying on a gradual deployment, automatic controls, and stricter limitations. It remains to be seen whether the protections will be able to grow at the same rate as the model's power.

comments