From Limited Access to GA in 72 Hours: GPT-6 Astra Lands on Microsoft Foundry
OpenAI's Critical-rated frontier model is now generally available in Microsoft Foundry at $10/$50 per million tokens — with PTU capacity, a 272K long-context cliff, no EU Data Zone, and an enterprise control stack built for computer use.
Three days after OpenAI launched GPT-6 Astra to a limited set of organizations, the model has cleared its enterprise gate. Microsoft’s Foundry team announced on September 3 that Astra — the first OpenAI model rated Critical for cybersecurity capability under the company’s own Preparedness Framework — is now generally available to all customers in Microsoft Foundry, with both pay-as-you-go Standard and Provisioned Throughput deployment options, in Global and US Data Zone geographies.
For enterprise buyers, this is the moment the Astra story stops being a ChatGPT headline and starts being a procurement decision. And the details buried in the pricing table and the system card deserve more attention than the launch-day benchmarks got.
What actually shipped
Astra arrived in Foundry at $10 per million input tokens and $50 per million output tokens on Global Standard (short context) — exactly matching the list price of Anthropic’s Claude Fable 5.1 published two days earlier, and 2.5x the promotional rate Microsoft is currently charging for GPT-5.6 Sol ($4/$20 through at least November 30).
The full price sheet:
| Deployment | Context | Input | Cached input | Cache writes | Output |
|---|---|---|---|---|---|
| Standard Global | Short | $10.00 | $1.00 | $12.50 | $50.00 |
| Standard Global | Long | $20.00 | $2.00 | $25.00 | $75.00 |
| Standard Data Zone (US) | Short | $11.00 | $1.10 | $13.75 | $55.00 |
| Standard Data Zone (US) | Long | $22.00 | $2.20 | $27.50 | $82.50 |
Notably absent: an EU Data Zone. Astra launches with Global and US-only residency options, which means no EU processing guarantee — a dealbreaker for European workloads with data-residency requirements, at least until the EU zone arrives. And when it does, it will be expensive: from September 1 Microsoft doubled the EU Data Zone premium from 10% to 20% for models launched after that date, making Astra the first frontier OpenAI model to carry the higher premium from day one.
The shift from Limited Access to general availability within roughly 72 hours is itself notable. Microsoft’s initial announcement said Astra would “begin rolling out through the Microsoft Foundry Limited Access Program, with availability expanding to participating customers over the coming days” — a gated process restricted to Microsoft-managed accounts with use-case reviews that take 5 to 10 business days. The current page reads simply: “now generally available for all customers.” Whatever internal review happened, it happened fast.
The 272K cliff
The most dangerous line in the documentation is the long-context threshold. Prompts above 272,000 input tokens are billed at doubled input and cache rates and 1.5x output rates — for the entire request, not just the tokens past the line.
Run the math: a single call with 300,000 input tokens and 8,000 output tokens costs $6.60 on Global long-context pricing. Trim the same call to 270,000 tokens and it costs $3.10. Thirty thousand fewer tokens halves the bill. Any document pipeline that routinely lands between 272K and 400K tokens needs to chunk or summarize before the call, not after the invoice.
Astra’s context window itself is enormous — OpenAI’s model page lists 1,050,000 tokens total context, 922,000 maximum input, 128,000 maximum output — with text and image input, a knowledge cutoff of April 30, 2026, and a new max reasoning-effort level sitting above xhigh.
Why Critical for cyber matters
The system card is unusually direct: “GPT-6 Astra is a significant step up in cyber capabilities and meets our Critical threshold.” Under OpenAI’s definitions, that means a model that — with the right tools and access — can find previously unknown vulnerabilities and develop exploits across well-protected systems without a person guiding each step. No earlier OpenAI model carried that rating, and OpenAI says it delayed parts of the release by weeks specifically to harden against cyber misuse and out-of-scope behavior.
For deployers, the practical consequence is a model that refuses more, deliberately. Astra refused 91.5% of prohibited cyber requests where GPT-5.6 Sol refused 59%. Offensive-security work — writing working exploits for known CVEs — is routed through OpenAI’s separate Trusted Access for Cyber programme, not the general API. Ordinary defensive use (vulnerability triage, code review, hardening advice) stays inside the standard envelope.
The safety deltas elsewhere are substantial: OpenAI reports an indirect prompt-injection attack success rate of 8.5% for Astra against 27.0% for Sol, and The Register cites a hallucination rate of 2% versus 9.4%. For an enterprise agent touching untrusted documents, an attacker-resistant model that hallucinates five times less is cheaper to supervise even at 2.5x the per-token price.
Computer use, contained
Microsoft’s pitch centers on “execution across applications”: Astra interpreting on-screen information, interacting with approved interfaces, updating records, navigating development tools, testing software, and assembling reports — including in workflows without dedicated APIs. OpenAI’s own benchmark there is OSWorld 2.0, where it reports 72.6% on the offline subset at roughly 40 minutes per task. Forty minutes of a $10/$50 model driving a desktop is a real cost line.
Microsoft’s own language is telling: “Capability this direct demands containment.” The blog acknowledges that content displayed in an application “may be incomplete, misleading, or designed to influence an agent’s behavior” — a candid description of the prompt-injection surface that computer-use agents inherit. Foundry’s answer is scoped credentials, approved-resource allowlists, human checkpoints for consequential actions, Entra ID identity, private networking, and activity records aligned to organizational risk requirements.
The enterprise-voice section is also unusually concrete: Replit’s CTO Luis Hector Chavez frames Astra as going “beyond code generation to active software creation,” and Albertsons’ VP of Data and AI describes using Foundry to balance evaluation speed against “consistent security, governance and operational controls.”
Worth 2.5x Sol?
Independent numbers suggest the answer is workload-dependent. Artificial Analysis scores Astra at 61 on its Intelligence Index at max effort against 66 for Claude Fable 5.1 — but reports a cost per Coding Agent Index task of $4.72 for Astra versus $9.18 for Fable, a striking efficiency gap that tips agent workloads back toward OpenAI. On cache-heavy loops, the picture flips: Anthropic cut Fable 5.1 cache reads to $0.25 per million while OpenAI’s cached input sits at $1.00, making Fable roughly 39% cheaper on a 60-turn agent session that re-reads a stable prefix.
The decision framework the data supports: single-shot document jobs tie between the two $10/$50 models; cache-dominated agent loops favor Anthropic; cost-per-completed-task favors Astra; and until November 30, GPT-5.6 Sol at promo pricing remains 2.5x cheaper for everything that doesn’t need frontier reasoning. Foundry’s addition of Provisioned Throughput — with US Data Zone PTU at a 10% premium to Global PTU — also answers the biggest early criticism of the launch, since capacity-constrained computer-use agents that must run on schedule can now reserve dedicated throughput rather than compete in the shared Standard pool.
The bigger picture: Astra’s Foundry GA closes the loop on OpenAI’s multi-cloud enterprise strategy — first-party ChatGPT plans, the OpenAI API, AWS Bedrock, and Azure Foundry all shipping the same frontier model within days of each other. The battleground has decisively shifted from model access to the management plane around it: identity, containment, evaluation, and cost controls. That is precisely the ground Microsoft built Foundry to hold, and precisely where a Critical-rated, computer-capable model either earns its premium or doesn’t.
Sources
- [1] https://azure.microsoft.com/en-us/blog/gpt-6-astra-frontier-intelligence-for-work-now-available-in-microsoft-foundry/
- [2] https://openai.com/index/gpt-6-astra/
- [3] https://technspire.com/en/blog/gpt-6-astra-foundry-price-gate-eu-gap
- [4] https://www.cnbc.com/2026/09/03/open-ai-astra-gpt-6-cyber.html
- [5] https://artificialanalysis.ai/articles/benchmarking-gpt-6-astra