OpenAI put a product on the table and a warning label on the same line. GPT-6 Astra, the lab’s new flagship, is the first model OpenAI has designated as meeting the Critical cybersecurity capability threshold under its Preparedness Framework. The Verge and NBC News both filed the rollout in the first days of September 2026. OpenAI’s own “Path to Astra” note is the primary for the threshold language. Models as products: who gets what, when, and under which door. Not a kit.

Here’s the cadence as published. Trusted defenders inside OpenAI’s Daybreak programme see Astra first. Wider ChatGPT access for Plus, Pro, Business, and Enterprise, plus the OpenAI API and AWS, follows in the days after. That’s the Verge/NBC/OpenAI triangle. The Critical mark is not a marketing star. It’s the company’s own framework saying the model’s cyber capability crossed a line that triggers harder deployment rules. Sunday 6 September 2026 is the product story of that line.

OpenAI’s Preparedness Framework is the house rule here, so say what Critical means in the company’s words, not in mine. Path to Astra says Astra meets the Critical cybersecurity capability threshold: with the right tools and access, it can find previously unknown security flaws and develop ways to exploit them across many well-protected systems without a person guiding each step. That’s the designation. It is the first OpenAI model the lab has put at that level. It also says stronger safeguards are required during development and before release. I’m repeating the framework sentence because the news is the classification, not a walkthrough of misuse. I’m not teaching that work.

Astra crossed the threshold
The Standard illustration

Daybreak is the first door. OpenAI has framed Daybreak as the track for vetted cybersecurity customers and trusted defenders. The Verge’s rollout note is clear that Astra lands with Daybreak cybersecurity customers first, then expands over the next several days to Plus, Pro, Business, and Enterprise users, and through the API and AWS. NBC’s 3 September filing matches the same shape: Daybreak defenders first, wider enterprise and consumer accounts in the coming days. CNBC’s same-day note repeats Plus, Pro, Business, Enterprise, API, and Amazon Web Services. I’m not inventing an Education SKU that isn’t on those wires. The product fact is a staggered ship: defenders’ programme first, paid tiers next.

What the public model will and will not do is also on the record. Coverage across OpenAI’s own notes and secondary wires says the broadly shipping Astra refuses advanced offensive asks such as generating proof-of-concept exploits, while OpenAI plans to loosen those restrictions for vetted defenders through Daybreak in the coming weeks for defensive workflows — vulnerability validation, malware analysis, detection engineering. Read that as access design, not as an invitation. I’m covering the existence of a defender gate. I’m not reprinting recipes or reproduction steps. If you came looking for a PoC, you’ve got the wrong outlet.

Agentic coding is the other half of the product pitch, and it’s why Astra isn’t only a cyber headline. OpenAI’s launch language, carried by The Verge and NBC, puts Astra as state-of-the-art on computer use, browsing, software engineering, cybersecurity, science, and professional work. The company is selling a model that stays on multi-step jobs, writes and reviews code, and operates tools. Treat those as vendor claims until independent benches you trust re-run them. My rule is the same as always: attribute the scoreboard, don’t launder it into a guarantee. Models as products means you get the ship date, the SKU list, and the safeguard story beside the capability adjectives.

The threshold timing matters for the paper trail. OpenAI’s Path to Astra note describes gathering more evidence after an earlier assessment that Critical capability could not be ruled out, then concluding the threshold was met. CSO Online’s 4 September write-up walks that chronology and quotes outside analysts arguing about whether the model changed or the testing did. I’m not going to settle a lab-methods fight from here. I’m going to say the company published a Critical designation, then started a gated rollout. That’s the product event.

Compare the doors without confusing them. Daybreak access is application-based and defensive by design. The ChatGPT Plus-through-Enterprise path is the consumer and business product path with tighter cyber refusals on the public surface. API and AWS are the integration path for builders who already live in those clouds. Three doors, one model name, different safeguard postures. If your org is a defender shop, you talk to Daybreak. If you’re a Plus subscriber waiting on the general ship, you’re on the “coming days” clock the wires described — and that clock has already been messy enough that The Verge filed a separate Altman apology note about staggered access. Staggered is still the design. Patience is not a patch.

Positive where it’s true: defenders get a named programme and a first look. The public product gets a model that OpenAI says is better at long software and professional work, with refusal boundaries meant to keep the hottest cyber capability off the open web. Transparency about a Critical mark is better than shipping the same capability under a silent label. None of that requires me to demonstrate a vulnerability chain. The craft here is filing the product.

Metric, because I run metric. Rollout window: about 3 to 4 September 2026 for the first Daybreak ship, with Plus/Pro/Business/Enterprise in the following days per Verge/NBC/OpenAI. Framework level: Critical, first for OpenAI under the Preparedness Framework. Surfaces named on the wires: ChatGPT paid tiers as listed, OpenAI API, AWS. Secondary coverage also mentions Azure/Bedrock in some follow-ups; stick to the primaries when you argue with a colleague. File date: Sunday 6 September 2026.

What I’m leaving out on purpose. I’m not reprinting ExploitBench percentages as a dare. I’m not walking “how Astra found a zero-day” as a tutorial. I’m not inventing a global price card for every token tier from a blog that isn’t OpenAI’s. I’m not putting an Education plan on the dek when the Verge/NBC/OpenAI cluster says Enterprise. I’m not naming a host who doesn’t exist. The sources are OpenAI’s Path to Astra, The Verge’s Astra release filing, and NBC News’ 3 September debut note. CSO Online is useful colour on the threshold debate. That’s the shelf.

Cadence for the AI tab: models arrive as products with doors. Astra’s door schedule is the story. Critical under the Preparedness Framework is the label. Daybreak is the defender-first lane. Plus, Pro, Business, and Enterprise are the days-after lane. Agentic coding and professional work are the capability pitch you should test, not worship. I’m not walking offensive how-tos. I’m not dropping a payload. I’m not saying “try this against a lab box.” Astra crossed the threshold. The product is shipping behind the gates OpenAI named. The rest is whether your org is on the defender list or on the waiting room clock — and whether the refusal boundary holds when the model is as useful as the company says it is.

One more pass for the notebook. Thursday-to-Friday ship window in early September. Critical is a framework word with consequences. Daybreak first. Paid ChatGPT next. API and AWS on the same wider wave. Defensive loosening later for vetted shops. Public refusals on advanced offensive asks at launch. Spoken plainly: OpenAI sold a faster, broader workhorse and admitted it also crosses a cyber line that forces a split product. That’s honest product journalism. It’s also why I stay on the catalogue and the calendar, not on the exploit bench. Sunday’s file stops here. Cite Verge. Cite NBC. Cite OpenAI. Leave the PoC culture to people who don’t work here.