Then in LinkedIn: Write article → click into the body → paste (Ctrl+V). Headings, links and images come with it. The title usually pastes as the first line — cut it into LinkedIn's title field. back to the article

Astra's Own Numbers Show Its Cyber Ceiling Never Moves — the Real One Sits on a Different Model

OpenAI's System Card shows Astra's advanced-cyber completion rate at 3.5% with or without trusted access — a flat line OpenAI calls deliberate. The 95% everyone attributes to "gated access" belongs to a different model shipped three weeks earlier.

Two monitors on a shared access-control terminal desk, one showing a toggle control caught mid-flip and the other showing a verification ring caught partway filled

Two labs reached the same week's decision — narrow the newest capability to a smaller trusted circle — through two differently shaped gates, and OpenAI's own published chart shows exactly where its gate actually sits [@openai-astra-system-card]. — Image prompt and art direction by Brecht Corbeel; generation pending.

Abstract

This article stays on one object: Table 21 of OpenAI's own GPT-6 Astra System Card, the five-column completion-rate chart behind the "Daybreak Blue and Enabling Cyber Defense" section, and the separately branded, separately trained model — GPT-5.6-Cyber, gated behind a different tier called Daybreak Red — whose own number is the one tier-1 coverage keeps attaching to Astra's name this week without naming it. It traces one flat table cell to the model that actually moves it, sets that against how Anthropic structured the equivalent choice for Claude Fable 5.1 and Claude Mythos 5.1 in the same week, and asks what a reader evaluating either company's newest "vetted access" tier could actually have verified from the primary documents alone. It does not re-derive OpenAI's Critical threshold test, does not re-explain the Cyber Verification Program or Life Sciences Verification Program mechanics, does not compare the two companies' chain-of-thought monitorability findings, and does not audit either company's cross-vendor footnotes or cost claims — each is a separate piece in this series.

Two Cells in the Same Row Refuse to Move

Section 10.2.2.2.1 of OpenAI’s own GPT-6 Astra System Card carries a chart the page itself calls Table 21, and the chart has a problem its surrounding prose explains rather than hides. Five columns compare three models — GPT-5.6 Sol, a model called GPT-5.6-Cyber, and GPT-6 Astra — with and without a new vetted-access tier called Daybreak Blue, across categories of authorized cyber-defense work. Read the row OpenAI labels “Advanced Cybersecurity Completion Rate” and Astra’s own two numbers are identical: 3.5% without trusted access, 3.5% with it [1]. Whatever Daybreak Blue is buying an enterprise this month, on OpenAI’s own broadest cyber-completion metric, it is not buying Astra anything.

That would be a strange thing to publish quietly in a document meant to certify Astra safe for release under the very framework that gave the model its headline distinction this week: Astra is, in OpenAI’s own words, “our first model to reach the Critical level of cybersecurity capability under our Preparedness Framework” [1] — the company’s internal classification for models capable of opening genuinely new pathways to severe harm. Tier-1 coverage of that designation ran everywhere in the first days of September. CNBC’s own report states plainly that Astra “is the first offering that crosses its ‘Critical’ cybersecurity capability threshold” [6]. TechCrunch called the same release “powerful (and controversial)” the day general rollout began [7]. Axios folded it into a wider story about both frontier labs steadying their safety optics ahead of expected public offerings, noting only that Astra’s “most powerful capabilities in that area will be initially limited to trusted testers” [8]. None of the three pieces mentions that the specific number describing the unlocked capability — the number a Critical designation is nominally about — does not move for the model actually carrying the designation.

It is not an oversight on OpenAI’s part. It is stated, plainly, two sentences after the chart.

Everything Else in the Row Jumps; This One Line Doesn’t

Table 21 is not evidence that Daybreak Blue does nothing for Astra. Read the whole row rather than one cell and the opposite is closer to true.

Figures per [1].

Grant Astra Daybreak Blue access and its completion rate on vulnerability discovery and analysis climbs to 100%, matching Sol exactly. Proof-of-concept exploit creation — arguably the more dual-use of the four named categories, since a working proof of concept is most of the way to a working exploit — goes from 2.4% to 92%, ahead of even Sol’s own jump from 5% to 90%. Cyber red-teaming goes from 7.4% to 76.9%. On three of the four named categories, Daybreak Blue is doing precisely the job its name implies: moving Astra from barely functional to broadly capable at defensive work OpenAI is willing to authorize.

The fifth category behaves differently in kind, not merely in degree. “Advanced Cybersecurity Completion Rate” is not one task type; VentureBeat’s reporting on the eval, sourced to OpenAI’s own launch materials for the metric, describes it as covering “exploit-chain development, authentication bypass, privilege escalation, and other advanced cybersecurity scenarios” [4] — the broad, arbitrary-request ceiling, not a bounded defensive workflow. On that one axis, Astra with Daybreak Blue reaches exactly the same 3.5% it reaches without it. OpenAI states the reason directly, in the sentence immediately following the table: “This is consistent with the goal of expanding access to authorized defensive work while maintaining safeguards against activity outside Daybreak Blue’s intended scope” [1]. Read plainly, that sentence says the flat line is not a limitation Daybreak Blue failed to lift. It is a boundary OpenAI built the tier not to cross. Daybreak Blue was never designed to unlock the broad category; it was designed to unlock four narrower ones, and on OpenAI’s own numbers, it does exactly that.

The reason those three categories matter enough to headline a chart is that each sits close to the line between defense and offense. Vulnerability patching is unambiguously defensive; proof-of-concept exploit creation is not — a working proof of concept is most of the distance to a working exploit, which is exactly why OpenAI’s standard safeguards refuse most such requests by default and why Daybreak Blue’s jump from 2.4% to 92% on that one category is the largest single move in the table. Cyber red-teaming sits in between: authorized adversarial testing that, run against the wrong target or without authorization, is indistinguishable from an attack. OpenAI’s own framing treats moving these three categories as the entire point of Daybreak Blue — proof that a vetted-access tier can hand a defender real capability on genuinely dual-use tasks without also handing them the broadest possible completion rate on arbitrary requests. Whether that’s the right place to draw the line is a judgment call; that OpenAI drew it there on purpose, rather than simply running out of runway, is the part its own text confirms.

Which raises the obvious next question — and Table 21 answers it in its own third column, sitting quietly between the two Sol columns and the two Astra columns.

The Number That Actually Moves Belongs to a Different Model

The middle column of Table 21 is labeled “gpt-5.6-Cyber with Daybreak Red.” On the exact same Advanced Cybersecurity Completion Rate metric where Astra tops out at 3.5%, that model scores 95% [1].

GPT-5.6-Cyber does not appear anywhere else in Astra’s own System Card. It is a separate model OpenAI shipped on August 10, 2026 — roughly three weeks before Astra’s own Critical designation made headlines — under a new tier called Daybreak Red, introduced alongside a restructured Daybreak Blue in the same announcement [3] [5]. VentureBeat’s coverage of the launch describes the model precisely: “a fine-tuned version of OpenAI’s most advanced general model, GPT-5.6 Sol… but trained specifically to improve performance on advanced cybersecurity tasks, including finding zero-day vulnerabilities and developing exploit chains” [4]. TechCrunch’s own launch-day reporting is consistent: Daybreak Red grants access to “purpose-trained cybersecurity models,” and “with Red also comes the new model, GPT-5.6 Cyber, which is only available at that tier” [3].

The honest description sits between two extremes worth naming explicitly, since the accuracy of the rest of this piece depends on getting this one distinction right. GPT-5.6-Cyber is not Sol with a permission flag switched on; it carries its own separately fine-tuned weights, trained specifically toward the tasks the Advanced Cybersecurity Completion Rate measures. It is also not an independent foundation model built from scratch — VentureBeat and TechCrunch both describe it as “built off of” or “built on” Sol [4] [3]. Call it what the coverage calls it: a purpose-trained variant derived from Sol’s own base, not a toggle layered onto Sol or Astra’s existing weights.

OpenAI also priced it as its own product rather than as an add-on to an existing plan. VentureBeat reports GPT-5.6-Cyber listed at $12.50 per million input tokens and $75 per million output tokens, against Sol’s own Daybreak short-context pricing of $5 per million input and $30 per million output in the same table [4] — a distinctly SKU’d, separately billed model, not a checkbox on an existing account. And the capability curve behind it did not begin with GPT-5.6-Cyber, either: the same VentureBeat report puts the model’s 95% against “just 57.3% from its immediate predecessor model GPT-5.5-Cyber” [4], meaning a lineage of purpose-trained cyber models had already been climbing toward this ceiling before GPT-5.6-Cyber shipped, let alone before Astra did. An OpenAI researcher, Eric Wallace, described the new model in a post the same coverage cites as the company’s “first large-scale attempt at directly improving capabilities for advanced cybersecurity tasks such as exploit development” [4] — an accurate description of a separate program, not of Astra’s own Daybreak Blue tier, which the same week’s Table 21 shows tops out at 3.5% on precisely this measure.

Getting to that 95% is also not a matter of flipping a setting on an existing ChatGPT or API account. VentureBeat’s own reporting on the August launch describes an application process, Daybreak Access, through which “enterprises that want access have to apply,” identifying “who they are, what kind of security work they plan to do, where they will use the models, and which OpenAI products or surfaces they expect to use,” with applicants required to “confirm that their work is lawful, defensive and authorized” [4]. That is a heavier gate than the Advanced Account Security requirement OpenAI’s own System Card describes for individual Daybreak Blue users [1] — one more piece of evidence that Daybreak Red and GPT-5.6-Cyber were built as their own product, with their own vetting funnel, rather than as a capability flag inside Astra’s existing access tier.

A row of five vertical slider controls on an access-control panel, four sliders caught rising toward their filled end and one slider stalled near its empty end

Figure 1. Four of Table 21's five categories move the moment Daybreak Blue is granted; the broadest one, the Advanced Cybersecurity Completion Rate, does not move at all [@openai-astra-system-card]. — Image prompt and art direction by Brecht Corbeel; generation pending.

A Ceiling Mismatch, Named

Here is the discriminator worth stating precisely, because “gated behind Daybreak” — the phrase every outlet checked for this piece uses, in one form or another — collapses two different things into one word. Call the gap a ceiling mismatch: the model carrying this week’s headline capability designation is not the model whose own gated tier actually reaches the number that designation describes.

Astra carries the Critical designation. Astra’s own gated tier, Daybreak Blue, does not reach the completion rate that made cybersecurity capability the story this week — by OpenAI’s own design, per the sentence quoted above. The model that does reach it, GPT-5.6-Cyber, carries no Critical designation of its own in anything published this session, sits behind a separate tier, Daybreak Red, and shipped three weeks before Astra existed publicly. A reader who wants to know “what does OpenAI’s newest vetted cyber tier actually unlock” gets two different, non-interchangeable answers depending on which model and which tier is meant, and the week’s coverage does not distinguish between them.

This is not a claim that OpenAI hid anything. Table 21 is published, on OpenAI’s own site, with GPT-5.6-Cyber’s column sitting directly beside Astra’s own two columns, unhidden [1]. The gap is not in what OpenAI disclosed. It is in what got repeated.

Five Names Cover Two Programs and Three Models

Part of why the mismatch is easy to miss is that the vocabulary does not sort itself for a reader on first pass. Lay it out plainly, once, because the rest of this piece depends on the reader holding all five names apart. Daybreak is OpenAI’s cybersecurity access program, existing before this week [5]. Within it sit two tiers: Daybreak Blue, which relaxes safeguards on OpenAI’s general-purpose models — GPT-5.6 Sol and, as of this week, GPT-6 Astra — for four bounded categories of defensive work; and Daybreak Red, a separate, more restricted tier that grants access to purpose-trained cybersecurity models specifically [3]. Two of those general-purpose models, Sol and Astra, are the ones that made this week’s news. The third, GPT-5.6-Cyber, is the one that actually reaches 95% on the metric everyone is discussing, and it is reachable only through Daybreak Red, not Daybreak Blue. A headline that says Astra’s advanced cyber capability is “gated behind Daybreak” is true of all five names at once and specific to none of them — which is exactly the condition under which a reader can walk away believing Astra’s own gated tier reaches a number that, on OpenAI’s own chart, belongs to a different model entirely.

What Would Actually Resolve This

State the condition under which “ceiling mismatch” stops being the right description, because a discriminator that cannot be wrong is not a discriminator. If a future Daybreak Blue update raises Astra’s own Advanced Cybersecurity Completion Rate materially above 3.5% — closing the distance to GPT-5.6-Cyber’s 95%, or even to a meaningful fraction of it — the mismatch collapses into an early-stage number that simply had not caught up yet, and this piece’s framing should be read as a snapshot of a transitional month, not a structural feature of how OpenAI splits access. Nothing published as of this week commits to that outcome on any timeline. The System Card’s own language about Daybreak’s future is a statement of direction, not a number: “through Daybreak, we plan to broaden access to these capabilities iteratively,” beginning “with a limited set of organizations and full production cyber safeguards,” with the goal, over time, to “enable more advanced, authorized defensive work through more precise safeguards, supported by stronger verification and accountability” [1]. That commits OpenAI to expanding who gets access and to refining the safeguards around it. It does not commit OpenAI to raising the specific number this piece is built on.

What Three Outlets Told Readers This Week

Check the actual sentences, not the general shape of the coverage. CNBC’s September 1 report states: “Astra’s advanced cyber capabilities will be available to a select group of organizations that are part of its cybersecurity coalition called Daybreak” [6] — one program name, no tier, no model. TechCrunch’s September 3 report, published the day general rollout began, states: “The model is being made available Thursday to OpenAI customers that use Daybreak, its cybersecurity program” [7] — the same pattern. Axios’s September 2 framing of both labs’ safety posture ahead of expected public offerings says only that Astra’s advanced capabilities “will be initially limited to trusted testers” [8] — trusted testers, unnamed, untiered.

One caveat belongs here, in fairness to CNBC specifically. Its September 1 Astra story links, in the very sentence naming Daybreak, back to CNBC’s own August 10 coverage of the Daybreak Blue/Red split — the same story that names GPT-5.6-Cyber directly and quotes OpenAI describing Daybreak Red as granting access to “purpose-trained cybersecurity models” [5]. A reader who followed that link on September 1 could, in principle, have reconstructed the ceiling mismatch three weeks before this article did. Neither of the other two pieces checked here does the same; nothing in TechCrunch’s September 3 report or Axios’s September 2 report links back to the August 10 launch at all. The information was public well before this week. It was not, in the coverage actually read for this piece, assembled.

A badge-reader terminal with two credential slots, a badge partway inserted into a slot with a still-cycling status ring beside an adjacent slot already lit steady

Figure 2. Daybreak Red is a separate credential from Daybreak Blue, granting access to a separately trained model, GPT-5.6-Cyber, that OpenAI shipped three weeks before Astra existed publicly [@techcrunch-gpt-5-6-cyber-launch]. — Image prompt and art direction by Brecht Corbeel; generation pending.

Anthropic Kept Its Ceiling on the Model It Announced

Set this next to how Anthropic structured the equivalent choice in the same week, because the contrast is the point, not an aside.

Anthropic’s own launch page for Claude Fable 5.1 and Claude Mythos 5.1 states plainly: “Claude Fable 5.1 and Claude Mythos 5.1 are the same model, but with different levels of safeguards” [2]. Fable 5.1 shipped generally available on September 1, 2026; Mythos 5.1, the safeguards-relaxed sibling, shipped the same day, described on the same page as available “only through our trusted access programs” [2]. The two named programs are not equally live on that date, and the same page says so: the Life Sciences Verification Program already carries Mythos 5.1, with Anthropic reporting it has “enrolled our first participants,” while the Cyber Verification Program’s own description states that it “currently provides access to certain Opus- and Sonnet-class models” and that Mythos-class access through that program specifically is coming only “in the near future” [2]. Whatever a reader makes of the identity-verification mechanics behind that split, or of how narrowly Mythos 5.1’s access is currently drawn — separate questions this series takes up elsewhere — the model itself is not in dispute. Fable 5.1 and Mythos 5.1 are one set of weights, one release date, two safeguard configurations of the same underlying model; it is specifically the cyber-side trusted-access program, not the model or its release date, that has its own not-yet-live component.

OpenAI’s own structure, on Table 21’s own evidence, is not that. Astra and GPT-5.6-Cyber are two different models, trained separately, shipped three weeks apart, sitting behind two differently named tiers of the same access program. A customer asking “what is this company’s newest vetted-access tier for cyber work” gets a same-model, same-day answer from Anthropic and a different-model, three-weeks-earlier answer from OpenAI — and this week’s coverage, built almost entirely around Astra’s own Critical designation, has treated both as equivalent instances of “gated access to the new model.” They are not describing the same kind of gate, and a reader relying on either company’s own primary document, rather than on the week’s press summary of it, would have been able to tell the difference in under a page.

Two identical badge-reader terminals side by side on the same desk edge, both status rings rising to full brightness at the same moment

Figure 3. Anthropic's equivalent split — Claude Fable 5.1 and Claude Mythos 5.1 — is one model, one release date, two safeguard settings; both readers here settle in the same instant rather than three weeks apart [@anthropic-fable-mythos-5-1-launch]. — Image prompt and art direction by Brecht Corbeel; generation pending.

The Counter-Case: An Early Ship, Not a Split Strategy

The fair objection to all of this is that OpenAI never claimed otherwise, and might reasonably argue the mismatch is a shipping-schedule artifact rather than a considered strategy. GPT-5.6-Cyber, on this reading, is Astra-class cyber capability that reached production early because a purpose-trained variant is faster to fine-tune and ship than a full frontier model — not evidence that OpenAI intends to keep Astra’s own Daybreak Blue ceiling permanently capped at 3.5%. VentureBeat’s own coverage supports part of this reading indirectly: OpenAI had already built toward this specific capability through an earlier, narrower identity-and-trust framework, introduced in February 2026 and reported as Trusted Access for Cyber, before Daybreak Red or GPT-5.6-Cyber existed under those names [4] — a sign the vetting machinery was maturing in stages rather than arriving, fully formed, as a deliberate two-tier strategy timed to this week.

Two questions stay open for the same reason, and this piece does not have the sourcing to close either one. First, whether Daybreak Red’s enrolled organizations are simply a subset of Daybreak Blue’s own existing vetted accounts — the same customers, granted one additional model — or a materially separate population vetted through a different process. TechCrunch’s August coverage names early Daybreak Red participants “including, reportedly, Accenture, IBM, CrowdStrike, Cloudflare, and others” [3], but names no overlap or lack of overlap with Daybreak Blue’s own roster. If the populations substantially overlap, the ceiling mismatch described above still holds exactly as stated: two models, two numbers, one designation attached to the wrong one. If they are materially distinct, the mismatch runs slightly deeper than a labeling gap — it would mean OpenAI operates two separate trust relationships under one program name, a claim this piece is not in a position to make either way. Second, whether OpenAI’s own roadmap language — “broaden access… iteratively,” “more advanced, authorized defensive work through more precise safeguards” [1] — will, on some future timeline, fold GPT-5.6-Cyber-equivalent capability into Astra’s own Daybreak Blue number specifically, which would retire this entire piece’s premise. As of this week, nothing OpenAI has published commits to that outcome.

The Designation Traveled Further Than the Number It Describes

None of this makes Astra’s Critical designation false. OpenAI’s evidence for that designation — its ExploitBench and SRE-Bench results, the internally discovered zero-day vulnerabilities in real-world software, the red-team-built exploit chains against hardened targets — sits in a different part of the System Card from Table 21 and is not what this piece is auditing. What Table 21 shows, in OpenAI’s own published numbers, is narrower and more checkable: the specific capability jump every outlet attached to Astra’s name this week — the one that supposedly justifies calling the model’s cyber capability “gated behind trusted access” — belongs, on the company’s own chart, to a different model that most of that coverage never named.

A reader evaluating either company’s newest “vetted access” tier this week could, in principle, have checked which model’s own number actually moves. Anthropic’s own page made that check trivial: one model, one date, two safeguard settings, stated in a single sentence. OpenAI’s own page made the same check possible but not easy: the answer sits in the fifth column of a table three sections into a document long enough that skimming it, rather than reading straight through, is the only realistic way most readers will ever meet it. Astra’s flat 3.5% is not evidence of anything OpenAI concealed. It is evidence that, this week, one company’s disclosure required a reader to do the reconciliation the other company’s page did for them in a single line.

The practical consequence is narrower than “OpenAI’s disclosure is worse than Anthropic’s,” and worth stating at that narrower scale rather than a broader one this piece cannot support. It is this: a “Critical” designation, a “gated behind trusted access” headline, and a specific completion-rate number are three separate claims, and this week showed they do not automatically travel together even inside one company’s own document. The designation belongs to Astra. The gating language belongs, loosely, to a program with two tiers and three models sitting behind it. The number belongs to GPT-5.6-Cyber alone. A reader, an enterprise buyer, or a journalist who treats those three as interchangeable — who reads “Astra crossed a Critical cyber threshold” and “Astra’s advanced cyber capability is gated behind Daybreak” and concludes that Astra’s own gated tier reaches whatever number made the threshold newsworthy — has made an inference OpenAI’s own chart does not support. The fix is not a longer footnote. It is checking, before repeating a vendor’s capability number, which of the vendor’s own models that number actually describes.

Sources

  1. OpenAI. GPT-6 Astra System Card. OpenAI Deployment Safety Hub (2026).
  2. Anthropic. Claude Fable 5.1 and Claude Mythos 5.1. Anthropic (2026).
  3. Lucas Ropek. As AI-Led Attacks Multiply, OpenAI Launches a New Cyber Model. TechCrunch (2026).
  4. VentureBeat. OpenAI Launches GPT-5.6-Cyber With Reduced Refusals, 95% Completion on Advanced Cybersecurity Tasks. VentureBeat (2026).
  5. CNBC. OpenAI Expands Daybreak Cybersecurity Initiative as AI Agent Threats Evolve. CNBC (2026).
  6. CNBC. OpenAI Says Astra AI Model Is Its First That Crosses 'Critical' Cybersecurity Capability. CNBC (2026).
  7. Lucas Ropek. OpenAI Launches Astra, Its Powerful (and Controversial) New Model. TechCrunch (2026).
  8. Axios. OpenAI Gets Cautious as Anthropic Courts Customers Ahead of IPOs. Axios (2026).

Originally published at https://absolutedigitalpublishers.com/articles/astras-cyber-ceiling-belongs-to-a-different-model.