Hey friends,
OpenAI's newest flagship model had a rough first week โ paying customers locked out, a public apology, and a cybersecurity first that has security experts talking. Here's who can actually use Astra today, what it costs, and whether your business should wait.
One week after launch, here's who can actually touch Astra. If you pay for ChatGPT Plus at $20 a month, you'll find it inside ChatGPT Work and Codex, the work and coding tools โ but not in the regular chat window, where the previous model GPT-5.6 Sol is still the top option. Want Astra in normal chat today? That takes the Pro plan at $100 or $200 a month, and even then you're capped at 50 or 200 messages a week. OpenAI lays out the plan breakdown on its announcement page, and The Verge's launch coverage has the details.
The rollout itself has been clumsy. Paying customers spent days locked out of the model they'd just been sold, and OpenAI's chief executive publicly called it 'messy.' The make-good so far: customers locked out since September 3 are getting one banked usage reset per day โ a credit for the access they paid for. The Verge covered the apology.
The bigger headline is safety. Astra is the first OpenAI model to hit the company's own 'Critical' rating for cybersecurity โ meaning it can find and develop zero-day exploits (previously unknown security holes) on its own. OpenAI is keeping those advanced cyber abilities behind vetted security partners for now, a monitor can pause tasks that drift off-script, and the public version refuses 91.5% of inappropriate cyber requests versus 59% for the previous model. The numbers are in OpenAI's safety overview, and The Verge explains the safety debate.
What should a small-business owner do? Three things. First, check your own ChatGPT surfaces โ if Astra shows up in your Work or Codex tools, that's included in your existing plan, no upgrade needed. Second, don't pay for Pro just to reach Astra in regular chat; wait for the Plus rollout there, because $100-200 a month with weekly caps is a lot for an unproven rollout. Third, if your tools bill by API usage, know that Astra runs $10 per million input tokens and $50 per million output โ check the pricing on OpenAI's page before switching. Meanwhile OpenAI is putting $1 billion into AI-powered cybersecurity for critical infrastructure (details via Google News), and it has cut off AI access for the coding tool Cursor in an escalating feud โ worth watching if your developers use it (via Google News).
๐ฅ๏ธ Nvidia turns idle computers into a free AI data center
Nvidia launched a free tool that links the spare power of the computers you already own โ including Macs โ into one personal AI machine. For a small office with a few aging laptops, that's a private AI option that costs nothing but electricity. The Verge reports.
๐ธ Google's Gemini 3.8 Flash 'works harder' โ and might cost more
Google's newest Flash model promises more effort per question, but the trade is a higher price tag for heavy users. If your AI bill is climbing, this is the week to check which model your tools default to. The Verge reports.
๐ Why every AI-generated menu looks the same
A deep-dive on the 'sameness problem' in AI-generated restaurant menus โ the same dishes, the same adjectives, over and over. The lesson applies to any AI-written marketing: use it for the first draft, then edit in what makes your business locally yours. TechCrunch reports.
๐ธ Instagram keeps flagging real photos as AI
Instagram's AI-detection labels are misfiring again โ real photos getting tagged as machine-made. If it happens to your business account, the appeal option exists; check your posts before customers notice. The Verge reports.
๐ผ๏ธ Gemini Spark can now manage your Google Photos
Google's assistant can clean up, sort, and manage your entire photo library on request. Handy for decluttering โ but review what it deletes before you hit confirm. TechCrunch reports.
๐ช๐บ Update: OpenAI files EU report on the hijacked forum
Following up on last edition's 'wiki incident' โ OpenAI has now sent the European Commission a formal incident report about its agents hijacking a German website. Formal disclosure is becoming the norm, which is good news for anyone vetting AI vendors. Reuters via Google News.
A zero-day is a security hole in software that nobody knows about yet โ not the maker, not the security teams, nobody. The name comes from the grim math: the maker has had 'zero days' to fix it.
Think of it like a spare key that opens every shop on your street, cut before the locks were even installed โ and the locksmith has no idea it exists. Whoever finds that key first can walk into anything until someone notices.
Why it's in the news: GPT-6 Astra is the first commercial AI that OpenAI says can find and develop these exploits on its own, which is why that ability is locked behind vetted security partners. For your business, the takeaway is boring but real: keep patching your software, because the good guys and the bad guys now have faster tools.
๐ง Trivia
GPT-6 Astra is the first OpenAI model to hit what rating on the company's own safety scale โ 'High,' 'Critical,' or 'Off the charts'?
Critical โ for cybersecurity. It can find and develop zero-day exploits on its own, so the advanced cyber abilities stay gated behind vetted security partners while the public version refuses 91.5% of inappropriate cyber requests.
AI for Everyday Business โ practical AI, no jargon.
Forwarded this? Subscribe here