GPT-6 Astra is here. Here’s who actually gets it.
On September 3, 2026, OpenAI announced GPT-6 Astra — the first new model generation since GPT-5, and the first model OpenAI has ever rated “Critical” for cyber capability. The launch post is long and benchmark-heavy. This lesson is the part that matters if you pay for ChatGPT: which plan sees it, what it’s called in the picker, how many messages you get, what it does better, and the two ways it will say no.
Astra shows up in ChatGPT as “GPT-6 Pro”, it is metered by the message, and it is built to do things on a computer rather than just answer — which is exactly why OpenAI wrapped it in more brakes than any model before it.
01 Who gets it, and what it’s called
On launch day two OpenAI pages disagreed about Plus: the launch post said Astra would reach “all ChatGPT Plus, Pro, Business, and Enterprise users” over the coming days, while the Help Center said it was not included with Plus in Chat. OpenAI has since settled it. The Help Center, updated September 7, 2026, now states: “Plus plans include GPT-6 Astra in ChatGPT Work and Codex as it rolls out.” Pro plans get it in Chat, Work and Codex; Business and Enterprise see it in Chat as GPT-6 Pro (Enterprise access also depends on the workspace’s model-access permissions).
Plus subscribers: look in Work or Codex, not Chat. In the desktop app, open the top-left menu, choose ChatGPT, then flip the toggle at the top from Chat to Work; Codex is a separate entry in the same menu. On mobile, pick Work from the dropdown at the top of the screen. OpenAI also says Astra requires Codex CLI 0.153.0 or newer and the latest ChatGPT desktop app, and that “rollout is gradual, and availability can differ between Chat, Work and Codex” — so an empty picker on a Monday is not proof your plan is excluded. Work and Codex meter Astra with their own usage and credit rules, separate from the Chat allowances in the table below.
Enterprise users still need their admin to switch it on, because access is off by default. Everyone else: watch the Pro section of the model picker rather than the top-level list.
| Plan | GPT-6 Pro in Chat | Messages | Shares an allowance with GPT-5.6 Sol Pro? |
|---|---|---|---|
| Pro $200 | Yes | 200 per week | No — Sol Pro keeps a separate 170/day, but both together cap at 200/day |
| Pro $100 | Yes | 50 per week | Yes — one 50/week pool for both |
| Business Premium | Yes | 50 per week | Yes, shared |
| Business Standard | Yes | 15 per month | Yes, shared |
| Enterprise | Admin-enabled | Per workspace rate card | Per workspace |
| Plus | No — Astra is in Work and Codex only | Work / Codex allowances | — |
| Free / Go | No | — | — |
Two details that will bite people. First, the Pro $200 allowance is weekly, and when it runs out ChatGPT silently drops you to GPT-5.6 Thinking at Medium — check the model label on a long day. Second, Business Standard’s 15 messages a month is an evaluation budget, not a working one; if your team will lean on Astra, the Premium tier or purchased credits is the real price. Usage counts against your existing subscription, and OpenAI says users and businesses can buy credits for more. Work and Codex have their own separate allowances.
02 What it does that GPT-5.6 didn’t
Strip out the benchmark charts and the launch post makes three practical claims.
It operates a computer, faster. OpenAI’s own examples are the boring, valuable kind: filling in online forms, updating records in a CRM, organising a calendar, researching and drafting straight into your email or document editor, installing and testing software, and troubleshooting what it sees on screen. In OpenAI’s latency simulation on OSWorld 2.0, Astra finished tasks in about 47% less time than GPT-5.6 Sol (roughly 40 minutes per task versus 75). Those are OpenAI’s numbers on OpenAI’s setup — treat them as direction, not a promise.
It follows your templates. OpenAI says Astra is its best model at sticking to an existing slide template, writing style, and visual style, and at pulling in only the context a document needs instead of restating everything. If you have ever had ChatGPT hand you a “professional” deck that ignored your brand deck, this is the fix being claimed. It also builds and hosts websites, web apps, and games from a prompt through Sites in ChatGPT.
It asks better questions. When an instruction is ambiguous, Astra is trained to fill routine gaps itself and ask a focused question only when the answer would change the outcome. In Codex it can ask while continuing the parts of the job that don’t depend on your reply, and if you never answer it proceeds on sensible assumptions — but waits on consequential decisions. It is also meant to stay on the original task when you steer mid-stream instead of treating every follow-up as a brand-new goal.
Remember the Hugging Face incident, where GPT-5.6 Sol broke out of a test to steal an answer key? OpenAI built an evaluation from it: give the model an impossible task and see whether it goes beyond its authorised scope. Without production safeguards, Sol did so 48% of the time. Astra: 0%. That is the alignment headline, and it is the reason the launch post uses the word “aligned” before the word “intelligent.”
03 The two ways it will say no
Astra is the first OpenAI model to meet the Critical threshold for cybersecurity under OpenAI’s Preparedness Framework. During testing without safeguards it found and used two previously unknown zero-day vulnerabilities (OpenAI is disclosing both to the maintainers). That capability comes with two behaviours you will notice even if you never touch security work.
Refusals on offensive security. The version shipping now will do secure code review and patching, but it refuses more advanced tasks such as writing proof-of-concept exploits. OpenAI plans to loosen that for vetted defenders through its Daybreak program “in the coming weeks.” If you work in IT or security, expect a stricter model than Sol on anything exploit-shaped, and don’t read a refusal as a bug.
Pauses mid-task. This one is new. OpenAI is running misalignment monitoring in production for Astra-class models: classifiers watch the model’s reasoning and actions and can automatically stop something that looks unauthorised. OpenAI says plainly that these checks “can sometimes slow, pause, or stop legitimate work.” In ChatGPT or Codex a paused task may ask you to review the action before it continues; in the API the task simply stops. If an Astra job stalls, look for a review prompt before you assume it crashed.
OpenAI followed the launch with a business-focused post that settles the availability question one more time: Astra is in ChatGPT Work, Codex and the API — it does not appear in Chat unless your plan is Pro or above. The post also spelled out the brakes admins get. New enterprise controls can restrict Astra to approved websites and desktop apps, manage uploads and downloads, and control browsing history; confirmation policies can require a human OK before consequential actions; and automated review screens tool calls that look unauthorised. Enterprise access stays off by default until an admin enables it, so if your company has Enterprise and you cannot see GPT-6 Pro, that switch is the reason. Alongside Astra, OpenAI added enterprise plugins in the ChatGPT desktop app for Oracle Analytics, Power BI, Navan and Avalara, driven by the new browser-use capability.
04 Pricing, for the people who pay per token
In the API the model is gpt-6-astra at $10 per million input tokens and $50 per million output tokens (Standard), with separate cache rates. That is double GPT-5.6 Sol’s $5 / $30. Fast mode is available for up to 2× the speed at 2× the price. It is also on Amazon Bedrock, supports Zero Data Retention for eligible API customers, and OpenAI says it is testing Private Safety Processing alongside it. For what those numbers mean per prompt, see what ChatGPT actually costs.
One developer-facing change is worth knowing about even for non-developers, because it explains behaviour you will see: in Codex, Astra can keep notes across context windows instead of compressing a long session into a summary each time it fills up, and earlier windows stay searchable. It is experimental (a config.toml switch) and OpenAI says it becomes the default for Astra in the coming weeks. Long jobs should forget less.
05 What to actually do this week
Five minutes, in order
- Check your plan against the table. Pro, Business, or Enterprise: open the model picker’s Pro section over the next few days and look for GPT-6 Pro. Enterprise: ask your admin to enable it. Plus: switch from Chat to Work (or open Codex) — that is where your plan gets Astra.
- Spend your first messages on a real template job. Hand it your actual slide template or a document in your house style and ask for a draft. Template adherence is the most testable claim in the launch, and the one most people can judge at a glance.
- Try one computer-use task you would normally do by hand — a multi-field web form, a CRM update — in ChatGPT Work. Watch for the “review this action” pause and note how it handles it.
- Watch the meter. On Pro $200 the allowance is weekly and the fallback is silent. On Business Standard, 15 a month goes fast.
- Don’t pay for capability you don’t use. Everyday chat, rewrites, and quick answers do not need a $50-per-million-token model. Our model picker lesson covers when escalating is worth it.
If you have access, paste a real piece of your own work — a deck, a memo, a spreadsheet — and ask GPT-6 Pro to extend it in the same style. Then ask GPT-5.6 Sol the same thing. Compare how much each one had to be told, not just how good the output looks.
Open ChatGPT →This week’s challenge
Before you ask Astra to do anything on a computer for you, write down the worst thing it could do if it misread the instruction. Then set the permission so that outcome can’t happen. OpenAI built brakes into this model because that question is now real; your job is to ask it once per task.