You got Astra. You didn’t get Daybreak.

Critical cyber is a capability tier. Daybreak is who actually gets the keys.

Cream hallway with terracotta door ajar and iron keys on the wall
Critical is a tier. Daybreak is the door.

Critical.

That’s the word OpenAI put on GPT-6 Astra under its Preparedness Framework — the first model it has broadly deployed at that cyber tier. In OpenAI’s own words: with the right tools and access, Astra can find previously unknown security flaws and develop ways to exploit them across many well-protected systems without a person guiding each step (Path to Astra, Safety overview).

The keynote sells the capability. The product sells a gated stack.

Same shape as our last two posts: harness ≠ model (Astra asterisk). Open pledge ≠ control (HF town square). Here: Critical capability ≠ default access.

What you actually bought

Layer What it is Who gets it
ChatGPT / API Astra (default) Frontier model with stronger cyber refusals Plus / Pro / Business / Enterprise / API as it rolls out — Enterprise often off until an admin enables it (Astra launch)
Daybreak Blue Trusted Access for Cyber — general frontier models (e.g. GPT-5.6 Sol) with safeguards calibrated for authorized defensive work Approved individuals/orgs; identity checks, monitoring, attestations (Daybreak overview, Expanding Daybreak)
Daybreak Red Purpose-trained cyber models for narrower, higher-friction authorized work Separate approval on top of Daybreak — not automatic if you already have Blue or legacy cyber access

Intended Blue-style work (OpenAI’s list, paraphrased): vulnerability triage, secure code review, malware analysis, detection engineering, incident response, patch validation — on systems you own, operate, or are explicitly authorized to test.

Red is the narrower lane for advanced authorized research / red-team style work. Extra approval. Stronger controls. Not a ChatGPT Plus upgrade path.

The asterisk inside the asterisk

OpenAI has already written the quiet part:

  1. Daybreak Blue results ≠ default Astra. Path to Astra notes some cyber results reflect Daybreak Blue access, not the default production configuration. If you quote a cyber bench from the launch packet, ask which config.
  2. Daybreak Blue is mostly not “Astra with the safety dial turned down.” Reduced refusals aren’t on Astra for most Daybreak customers. Help Center: keep using Astra with standard safeguards, or switch to a model that supports Daybreak Blue. The Daybreak toggle in Codex doesn’t magically unlock “Astra + Blue.”
  3. Approval ≠ configuration. Getting into Daybreak does not set up your environment. Scope, least privilege, isolation, and human review for consequential actions are still on you (Developers blog).
  4. The admin switch. Enterprise Astra access is off by default at launch. The computer-use demo assumes someone with authority already flipped a switch and accepted the risk. Your CRM, email, and prod credentials don’t care about Brockman’s keynote.

What this means for your stack (defensive only)

  • If you’re a builder / SMB: ChatGPT Plus Astra is a better agent and a more refused cyber assistant. Don’t plan a security workflow on “the model that scored Critical.” Plan on what your seat actually allows.
  • If you’re IT / security: Map who can enable Astra in the workspace. Treat Daybreak as a separate procurement — verification, hardware keys for individuals (OpenAI’s Daybreak hardening includes security-key requirements), monitoring, legal attestations.
  • If you’re a vendor selling “AI security”: Your customers will confuse capability headlines with access. The honest pitch is governance + Daybreak eligibility + human-in-the-loop — not “we run Astra Critical on your perimeter.”
  • If you’re comparing labs: The same shape shows up elsewhere — frontier cyber gets a velvet rope. The rope is the product.

What to do Monday

  1. Read the access table out loud to whoever owns ChatGPT Enterprise / API spend. Capability ≠ entitlement.
  2. Check whether Astra is enabled in your workspace (and who can flip it).
  3. If you’re an authorized defender: apply / confirm Daybreak status at openai.com/daybreak — Blue first unless you have a documented need for Red.
  4. Write a one-page rule: which systems agents may touch; what requires human review; what never leaves an isolated env. Access approval won’t write this for you.
  5. Don’t chase exploit theater. Your edge this month is patch cadence, inventory, and permissions — the boring stuff Critical models make more urgent.

The series, so far

  1. Harness moved the score.
  2. Landlord bought the town square.
  3. Critical is a tier. Daybreak is the door.

Adults hold both: the capability is real and most seats don’t get the keys the marketing implied.

If you only remember one line: You got Astra. You didn’t get Daybreak. Measure the door.

Want the one-page “capability vs entitlement” checklist? Reply DOOR / join the waitlist.