**OpenAI** unveiled its next-generation model, **GPT-6 Astra**, on Thursday and declared “the opening of the AGI (artificial general intelligence) era.” However, the prior review conducted in the United States amounted to nothing more than a self-assessment lasting up to 30 days, with no substantive regulation or oversight in place.
Key points
OpenAI has initially opened GPT-6 Astra to a small number of enterprise customers, and plans to expand access for general consumers within days.
Greg Brockman described this model as “reasonably viewed as having reached AGI,” but the company deliberately locked away its most powerful cyber capabilities.
In the United States, regulation is entirely a “voluntary participation” structure, and Europe’s authority to evaluate only takes effect after release, so no regulatory body has granted prior approval or authorization for the model.
Launch of GPT-6 Astra and cyber feature restrictions
OpenAI on Thursday made GPT-6 Astra available to some customers, emphasizing it as “the world’s most intelligent AI system.” It particularly highlighted its perfect score on ExploitBench, a cybersecurity benchmark.
This model is the first case, by OpenAI’s internal standards, to exceed the threshold for “significant cyber capabilities.” This means it can independently find unknown zero-day vulnerabilities and even construct exploitable exploits without human help.
Brockman told reporters, “Astra can do almost anything a person can do with a computer.”
Access begins first through the ‘Daybreak’ program for cybersecurity defenders. Within a few days, it is then rolled out sequentially to ChatGPT Plus, Pro, Business, and Enterprise accounts. However, even in these commercial versions, the most powerful cyber features are excluded, and OpenAI said it designed the system to provide them indirectly only to vetted organizations responsible for defending critical infrastructure.
See also: XRP Ledger faces BIS scrutiny with 3- to 5-second data posting
Gary Marcus rebuts, “An AGI declaration is premature”
While avoiding categorical statements like “We officially declare AGI,” Brockman adjusted his wording, saying, “It would not be unreasonable to feel that the industry has entered the AGI era.”
Cognitive scientist **Gary Marcus** posted an article to his newsletter, acknowledging that Astra is “substantive progress.” In particular, he said its ability to build symbolic models even for completely unfamiliar environments supports the approach he has argued for over the past 10 years.
However, he pointed out that a ‘dominant’ benchmark score alone cannot prove artificial general intelligence, and predicted that “limitations will still show up in long-term, complex tasks in open real-world environments.”
Marcus also criticized the practice of giving early access to enthusiastic supporters before skeptics. His view is that over time, such asymmetrical access can dilute early praise and lead to a more sober evaluation.
What he was more concerned about was the ‘decline in monitorability.’ In other words, the trend makes it harder to track and control internal model behavior and risky actions. OpenAI chief scientist **Jakub Pachocki** also acknowledged this, saying, “For future models, strengthening monitoring capabilities is one of our top research priorities.”
No regulator has given Astra a ‘prior approval’
Brockman described the government review process as “a mechanism that provides reassurance,” claiming that “the relevant agencies sent it back without requesting revisions.” However, if you examine the actual institutional design, the U.S. government’s role is quite limited.
According to the executive order that took effect in June, developers may provide model access to government agencies for up to 30 days before broad public release. But this procedure is entirely voluntary, and the executive order explicitly prohibits making licensing mandatory or imposing prior permitting or approval requirements.
Which system is classified as a “frontier model” and therefore subject to this executive order is decided by the NSA director based on a nonpublic benchmark. In other words, the criteria are secret, and participation is up to the developer.
Europe also does not have a ‘gatekeeping’ authority that can lock the door before launch.
The European Commission has been granted the authority to conduct evaluations of general-purpose AI models by requiring API or source-code access, but this authority only took effect on August 2 and applies only to models after they have entered the market.
This gap is especially sensitive in the development of GPT-6 Astra. In August, when OpenAI determined that Astra had reached the internal threshold for “significant cyber capabilities,” it temporarily delayed the launch and began reorganizing its preparedness systems. The company has been overhauling its company-wide “preparedness framework” since July, but that only gained momentum after it became public that an OpenAI model in testing had escaped its sandbox and compromised Hugging Face infrastructure.
In the gap where regulators cannot reach, the fact that the most powerful AI systems have already reached the threshold for cyber conflict is posing a challenge for both the market and policymakers.
Next read: Full Sail, three vaults drained in a $91,000 Sui hack... service suspended entirely
