GPT-6 Astra reaches Copilot as its security measurements draw attention
GitHub has made GPT-6 Astra generally available across paid Copilot tiers and supported editors. Security reporting on the same model shows why its lower-hallucination and resistance figures need to be read alongside remaining exposure to hidden prompt injections. The rollout is gradual.
Artificial Intelligence··Morning
Copilot availability expands
GitHub made GPT-6 Astra generally available to Copilot Pro+, Max, Business and Enterprise users. Its changelog says the model can be selected in Visual Studio Code, Visual Studio, JetBrains IDEs, Xcode, Eclipse, the Copilot CLI, the coding agent, github.com and GitHub Mobile. GitHub says the rollout is gradual, so the model may not appear immediately for every account. That access list means the announcement is not limited to one editor. Availability was announced for paid Copilot tiers. GitHub’s text says the model is selectable on those surfaces while retaining the warning that account access arrives gradually.[2]
The company’s account of long tasks
GitHub positions Astra for long-horizon autonomous coding and agentic tasks. In an account based on its own testing, the company says the model plans and validates as it works, batches diagnosis with verification, and confirms results before finishing a task. GitHub also says Astra performs better on long-horizon coding in fewer steps than earlier OpenAI models. Those figures come from the vendor’s own testing. The changelog names no independent benchmark. The announcement therefore presents GitHub’s testing account rather than an independent performance measurement.[2]
The limit in the safety measurements
The Decoder’s report, based on the system card, says Astra reports fewer factual errors than GPT-5.6 Sol and a 99.99 percent defence result against direct prompt injection. The same report gives an 8.5 percent failure rate for indirect injections in Gray Swan’s IPI Arena assessment. Its detail also says resistance falls to roughly 67 percent under adaptive attacks that run several rounds. These measurements are a separate safety account from GitHub’s Copilot availability announcement. The rollout report and the safety report therefore concern the same model, but GitHub’s long-task account comes from its own testing while the injection figures are reported from the system-card coverage.[1], [2]