tutoriales · 4 min read
GPT-6 Astra: OpenAI's highest-risk model reaches business
OpenAI has launched GPT-6 Astra, its first model rated at the top of its own risk scale, able to act on your systems on its own. What to check before giving it access.
On September 3, 2026, OpenAI launched GPT-6 Astra, a model able to operate a computer and finish tasks end to end — from writing code to filing a tax return or formatting a contract — without a person stepping in at every stage (Infobae; CNBC). What stands out isn’t only what it can do, but how its own maker classifies it: it’s the first model OpenAI has placed at the highest risk level in its own internal safety framework. At Evicron, an AI and custom software studio based in Barcelona, that raises a question we’re already hearing from the companies we advise: if an AI can act on its own across your systems, what do you need to check before letting it in?
What OpenAI shipped, and why experts are worried
GPT-6 Astra first reached enterprise users enrolled in Daybreak, OpenAI’s restricted-access program for authorized evaluators, then rolled out over the following days to ChatGPT Plus, Pro, Business and Enterprise plans, plus the API, Microsoft Azure and AWS Bedrock, priced at $10 per million input tokens and $50 per million output tokens on the standard API (Infobae). OpenAI itself has acknowledged this is the first of its models to reach the top tier of its internal evaluation scale, with demonstrated ability to identify software vulnerabilities and work out ways to attack well-defended systems without human oversight (CNBC). Don’t confuse this scale with the EU AI Act’s risk tiers: they measure two different things — OpenAI’s framework rates the risk of the model itself before release, while the EU regulation classifies how each business actually uses it.
Why this isn’t just a tech headline
It’s tempting to assume a model with autonomous cyberattack capability only matters to AI labs or big tech firms. It doesn’t. The moment any business — an accounting firm, a law office, any SME — connects an agent like this to its inbox, its document management system, or its credentials to automate admin work, it’s giving an autonomous system access to sensitive information and the ability to act on it without anyone reviewing each step. The productivity gains are real, and the pressure to adopt it will arrive the same way ChatGPT’s did; the question that actually matters isn’t whether to use it, but under what limits.
The checklist before granting an autonomous agent access
- What can it actually touch? Scope its permissions before connecting it: read-only access wherever possible, and credentials kept separate from the ones your team uses — never shared.
- Is there human review before irreversible actions? Sending a payment, signing a document, replying to a client, or deleting a file are things an agent can propose, but a person should approve before they happen.
- Is there a record of what it does? Every action the agent takes — what it opened, changed, or sent — should be traceable the same way an employee’s work would be, not buried in a technical log nobody checks.
- What does the vendor’s contract say about liability? If the agent makes a mistake with legal or financial consequences, you need to know who’s responsible before it happens, not after the incident.
- Can access be revoked instantly? A serious deployment of an autonomous agent needs a real kill switch, not a support ticket to the vendor.
What EU regulation already says about this
The EU AI Act requires companies to know at all times what a system decides or influences, and an agent acting unsupervised on admin tasks can land in a higher risk tier than a business assumes by default — as we explain in our guide to the four risk tiers. Spain’s AI supervisory authority has already updated its compliance guides to cover cases like this; it isn’t a legal grey area you can put off while you decide whether the tool is worth adopting.
How we approach this at Evicron
We don’t recommend slowing down adoption of autonomous agents — the competitive edge for those who use them well is real — but we do recommend not connecting one to production systems until the five safeguards above are in place. In our AI consulting for businesses we audit which agents your team is already testing and what controls they’re missing; when the answer is deploying a specific agent with scoped access to your own data, we build it with applied AI designed so access, logging and rollback are solved from day one, not bolted on after a scare.
Bottom line
GPT-6 Astra confirms the next generation of AI doesn’t just answer questions — it acts on real systems by itself, and its own maker admits that puts it at the top of its risk scale. Before giving an agent like this access at your company, work through the five questions above; the cost of answering them now is nothing compared to finding out the hard way after an incident.
Want to know which AI agents your business could safely use, and under what actual guarantees? Get in touch: the first discovery session is free and we reply within 24 hours.