SAN FRANCISCO — Greg Brockman had a declaration ready. OpenAI’s president, speaking at the company’s offices on Thursday after the launch of Astra, the company’s most capable model to date, said that in his view, OpenAI has crossed the threshold. “I do think we’re there,” he told reporters, referring to artificial general intelligence.
The model Brockman was describing began reaching subscribers that same morning. It can autonomously identify and develop zero-day software vulnerabilities, operate browsers and computer interfaces without human oversight, outperform every competitor OpenAI has named in software engineering tasks, and complete complex multi-step jobs using fewer computational resources than its predecessor. It also uses a reasoning technique that OpenAI’s own chief scientist said makes it harder to monitor than the model it replaces.
Astra is immediately available to participants in OpenAI’s Daybreak cybersecurity program, which launched in August to give vetted security researchers access to advanced offensive AI capabilities. Pro, Plus, Enterprise, and Business subscribers receive access within the week. Developers can also reach Astra through OpenAI’s API.
On the benchmarks OpenAI published Thursday, as TechCrunch reported, Astra ranks above Sol, the model OpenAI fielded earlier this year, and above Anthropic’s Fable, which had led several independent assessments since its June release. The comparative advantages are specific: bug-finding, terminal tasks, and codebase queries. Astra also operates more efficiently, completing complex multi-step operations using fewer language tokens, which reduces API costs for developers integrating the model into products.
Brockman described Astra as “a new frontier on computer and browser use.” That phrase maps directly to what the model was built for: agentic workflows in which the AI autonomously operates software interfaces, writes and tests code, and takes follow-on actions across connected systems. A model that can identify a zero-day vulnerability and then navigate a browser to file a disclosure, draft a remediation ticket, or trigger a downstream process is different in kind from a model that answers questions about code.
The monitoring concern is harder to set aside. Astra uses a technique OpenAI calls opaque recurrence, a reasoning approach that obscures the chain-of-thought process safety researchers rely on to audit how a model reaches its conclusions. In materials accompanying Thursday’s launch, OpenAI’s chief scientist acknowledged the trade-off without qualification: “As model capabilities are increasing, monitorability is getting more challenging.”

That statement landed alongside Brockman’s AGI declaration. Whether OpenAI intended the pairing as a disclosure, a warning, or simply a coincidence of timing is not clear from what the company published Thursday.
The AGI claim carries less contractual weight than it would have a year ago. OpenAI renegotiated its partnership agreement with Microsoft earlier in 2026, removing provisions that had tied specific contractual triggers, including licensing terms and liability thresholds, to an internal determination that OpenAI had crossed the AGI threshold. In Thursday’s briefing, Brockman addressed that context directly, arguing that AGI should be understood as “a mission concept or spiritual concept” rather than a contractual milestone. He has said consistently that any binary definition of AGI was always inadequate to what the technology actually does. The renegotiation restructured the Microsoft relationship significantly, shifting operational and commercial boundaries that had been in place since 2019.
Yesterday, Astra became the first AI model to register at the “Critical” threshold on the industry’s cybersecurity benchmarks, the level at which a system can autonomously develop exploits for software vulnerabilities that no public patch yet exists for. OpenAI shipped it then under that assessment. It is shipping Astra now with that same capability, broader access, and less monitoring transparency than it disclosed at the time.
For the organizations receiving Astra through standard subscriptions within the week, the risk profile differs meaningfully from the Daybreak deployment. The cybersecurity program’s participants are vetted, operating under specific usage agreements, within a controlled research context. A general subscriber rollout across Pro, Plus, Enterprise, and Business accounts extends a model with offensive cybersecurity capabilities and reduced chain-of-thought visibility to a far broader range of deployment environments simultaneously.
Three things OpenAI did not address Thursday. The Daybreak customers who have had access to Astra for several hours have not published any operational assessments. The full scope of the opaque recurrence limitation, whether it is a structural property of how the model was trained or an engineering constraint that future model versions could address, is not in the materials OpenAI released. And whether Brockman’s AGI declaration represents an internal consensus view at the company or a personal position is not clear from the available disclosures.
What Astra can do is substantial. The question the launch raises, and does not answer, is whether the decline in monitorability is a temporary engineering constraint or the beginning of a longer curve, and what OpenAI proposes to do about it.

