Trusted Access and a “limited set of organizations” are not every Sherwood Park shop. A $10 / $50 card is not Alberta residency. OpenAI’s first Critical cybersecurity designation means keep client networks, tenders, and credentials off Astra — put sensitive work on a private AI security path, and treat the rest as AI consulting Alberta work, not a public paste. OpenAI’s September 3 launch post and the latest-model guide both matter: limited orgs / Trusted Access today, broader plans and API surfaces in the coming days. The models listing prices the flagship at $10 per million input tokens and $50 per million output tokens. Those figures are USD as published. CAD is on the invoice. This desk is not inventing a Canadian list price.
What OpenAI launched
On September 3, 2026, OpenAI’s product launch post introduced GPT-6 Astra as its most intelligent and aligned model yet for computer use, browsing, software engineering, cybersecurity, science, and professional work. Set model to gpt-6-astra in a Responses API request. Tool calling requires the Responses API. Reasoning effort runs low through max — there is no none.
“GPT‑6 Astra is rolling out today to a limited set of organizations and over the coming days will become available to all ChatGPT Plus, Pro, Business, and Enterprise users, as well as through the OpenAI API, Microsoft Azure, and AWS Bedrock.”OpenAI, GPT-6 Astra launch post, September 3, 2026
Read that with the docs, not instead of them. The latest-model guide also says Astra is rolling out today for enterprises in the Trusted Access Program, with API access and Plus, Pro, Business, and Enterprise plans coming in the coming days. Launch framing adds Microsoft Azure and AWS Bedrock to the coming-days surface. Both notes are true at once: limited / Trusted Access now; broader paid plans and cloud surfaces next.
OpenAI’s published claims, labeled as such: ARC-AGI-3 at 99.9%; FrontierMath Tier 4 at 98%; ExploitBench at 100% (versus GPT-5.6 Sol at 78.5% on ExploitBench without production safeguards). On an OSWorld 2.0 latency simulation, OpenAI claims Astra at 72.6% in roughly 40 minutes per task versus Sol at 65.7% in roughly 75 minutes — about 47% less time. Those are OpenAI’s numbers, not this desk’s harness. Do not invent ARC harness claims beyond what OpenAI published.
OpenAI also says Astra can deliver a lower estimated API cost per task than earlier models despite higher per-token pricing, because it uses fewer output tokens in several evaluations. That is OpenAI’s estimate. Fast mode is unavailable with EU data residency; this briefing does not invent a Fast-mode 2x Astra list price off the models page.
What it costs
These are OpenAI’s published USD API rates from the models page and the gpt-6-astra model page. Do not quote them as CAD. CAD is on the invoice. The model page also lists cached input at $1.00 and cache writes at $12.50 per million; prompts over 272K input tokens are priced at 2x input/cache and 1.5x output for the full request; Fast mode is 2x the applicable rates. Astra lists the same $10 / $50 as Claude Fable 5.1 — pick on data path and Cursor failover, not a fake price war. For Alberta operator knobs (effort pins, Enterprise off-by-default, monitor pauses), see the Alberta cheat codes companion.
| Model | Input / 1M | Output / 1M | Notes |
|---|---|---|---|
| GPT-6 Astra | $10 | $50 | Flagship. gpt-6-astra. 1.05M context. |
| GPT-5.6 Sol | $4 | $20 | gpt-5.6-sol / gpt-5.6. Same context. |
| GPT-5.6 Terra | $2 | $12 | Balance of intelligence and cost. |
| GPT-5.6 Luna | $0.20 | $1.20 | Cost-sensitive, high-volume. |
Reasoning efforts listed for Astra are low, medium, high, xhigh, and max. Knowledge cutoff is Apr 30, 2026. Max output is 128K tokens. Context window is 1.05M on the same page for Astra, Sol, Terra, and Luna.
Critical cyber and limited access
On September 1, 2026, OpenAI’s Path to Astra note said the company believes Astra meets the Critical cybersecurity capability threshold under its Preparedness Framework: with the right tools and access, it can find previously unknown security flaws and develop ways to exploit them across many well-protected systems without a person guiding each step. OpenAI says it is the first model they designate at this level. Advanced cybersecurity access is more limited, with Daybreak used for defensive expansion. The September 3 safety overview says OpenAI is deploying misalignment monitoring on tool-using external Astra inference, and that Astra is significantly more robust to jailbreaks than GPT-5.6 Sol. This briefing stops at the designation, the limited-access rule, and those high-level safety notes. It does not recap exploit methods.
What Alberta operators should do
Alberta work here means AI consulting Alberta, AI automation Alberta, and private AI security. Trusted Access / limited organizations is not every Sherwood Park shop today. Price is not permission and price is not residency — a $10 / $50 USD card does not put inference in Alberta. Default remains US/cloud unless you have a private path.
The Critical cyber designation is the operator line: do not point Astra at client networks, tenders, or credentials. Keep that traffic on a private AI security path. If the workflow has to stay on the desk, that is AI consulting work, not a public paste. Use Sol, Terra, or Luna when the job does not need the flagship.
Same $10 / $50 as Claude Fable 5.1 — pick on data path and Cursor failover, not a fake price war. November 12 Cursor wind-down is still proposed. OpenAI’s decision on Cursor said it will not provide future models to Cursor after the SpaceX acquisition. That is why Astra-in-Cursor is not the Alberta failover. See the existing Cursor wind-down briefing for the house note. Operator knobs live in the Alberta cheat codes companion.
