OpenAI's GPT-6 Astra, the company's newest and most capable model, is now generally available on Amazon Bedrock, according to posts published by both OpenAI and Amazon Web Services (AWS).

The model can be called directly through Bedrock's APIs, or accessed through ChatGPT Work and Codex, OpenAI's coding agent, configured to run on AWS infrastructure. According to AWS, Astra also accepts up to 1 million input tokens in a single request — enough, the company says, to review hundreds of pages of a contract at once and flag the highest-risk provisions.

Pricing and capabilities

According to OpenAI, Astra costs $10 per million input tokens and $50 per million output tokens. The company says the model was trained to finish tasks using fewer tokens and fewer retries, which it says cuts down on rework and cost per task. OpenAI says Astra occupies much of the cost-efficiency frontier on coding and professional-work benchmarks, including Terminal Bench 4.0.

Within Codex, the model can investigate issues across large, unfamiliar codebases, trace dependencies between files, and carry a fix from diagnosis all the way through testing, according to AWS. Within ChatGPT Work, it can gather information across applications and files, browse the web, and produce spreadsheets, slide decks, documents and sites, per OpenAI.

Security and a new risk classification

According to OpenAI, Astra is the first of its models to reach the "Critical" cybersecurity capability threshold under the company's Preparedness Framework, its internal system for assessing frontier-model risk. Because of that, OpenAI says it strengthened automated safeguards that monitor misuse in real time and can pause or stop activity that crosses defined boundaries, alongside training meant to make Astra more resistant to attempts at bypassing those safeguards.

On the infrastructure side, AWS says it enforces what it calls "zero-operator access": not even Amazon's own employees can view the prompts sent or the responses generated during inference. The company says data is encrypted in transit and at rest, access is governed by identity policies (IAM), and every model call is logged through AWS CloudTrail. AWS also says customer data is not used to train OpenAI's models, and that using Astra does not require sharing data with OpenAI.

Alongside general availability, OpenAI is rolling out new enterprise plugins for ChatGPT Work. According to AWS, the first plugins cover tools such as Workday and Navan; according to OpenAI itself, the list also includes Oracle Analytics, Power BI and Avalara. Both companies agree the plugins extend Astra's browser-use abilities to data analytics, operations and finance tasks, within the permissions each customer's administrators already have in place, so the plugins do not grant Astra any additional access on their own.

According to AWS, Bedrock also offers prompt caching for Astra, aimed at workflows that reuse the same context across repeated requests, such as recurring document review or ongoing analysis of a codebase. With manually set cache breakpoints, reusing that context in later calls is meant to cut down on repeated processing, cost and latency, the company says.

Both AWS and OpenAI say customer inference data is not used to train the models. AWS adds that traffic flagged by its automated abuse classifiers is retained for up to 30 days for programmatic review, and that customers can request zero data retention through their own AWS account team. OpenAI says the same zero-retention option is available to eligible customers using Astra directly through its API, subject to approval.

OpenAI says Astra had already been introduced publicly the week before its Bedrock launch, and that enterprise access to the model is off by default until an organization chooses to turn it on for its own workforce.