The Pulse
Perplexity Trusts OpenAI’s GPT-6 Astra With Production Systems
Perplexity says OpenAI’s GPT-6 Astra can write communications, modify software, test applications and monitor production systems with less frequent human checking. The endorsement comes as OpenAI discloses that Astra can find unknown vulner

AI.info Team ·
Perplexity says it is giving OpenAI’s GPT-6 Astra access to work that extends beyond code suggestions, including software changes, production monitoring and end-to-end application testing. Johnny Ho, Perplexity’s cofounder and chief strategy officer, says the company checks Astra’s work less frequently than it checked earlier models.
The claim puts Perplexity’s operating practices alongside a warning in OpenAI’s separate Astra launch materials: when run without production safeguards, the model can identify previously unknown software vulnerabilities and develop exploit chains. OpenAI’s customer account presents Astra as a system Perplexity can trust; OpenAI’s safety documentation shows why that trust depends on controls around the model’s access and actions.
Perplexity Moves Astra Beyond Code Suggestions
Perplexity uses Astra to write communications, edit real-world systems and monitor production software, according to OpenAI’s account published September 14, 2026. Ho describes the change as an application of stronger coding and reasoning capabilities to the systems that support Perplexity’s search product.
“We can have the model craft communications, edit real-world systems, and monitor our production software in a way that previous generations were not able to.”
Johnny Ho, Cofounder and Chief Strategy Officer, Perplexity
Ho says improvements in code generation directly affect Perplexity’s search engine because the company can use better programs to search the web and internal information, then summarize results. The OpenAI post does not identify particular production services or describe the permissions Astra receives inside Perplexity’s infrastructure.
Testing Becomes Astra’s Main Assignment
One of Perplexity’s most useful applications involves software testing. Ho says he can ask Astra to build a small testing program around an application and generate realistic responses from services that application depends on, such as a language-model API or an external connector.
That approach lets the model test an application’s workflow from start to finish instead of stopping at an isolated function. The account describes Astra as generating simulated service responses and checking how the application behaves, but it does not provide test volumes, failure rates or a comparison with human-written tests.
“We’re actually able to trust it with full end-to-end systems and check in on it much less frequently than previous generations of models.”
Johnny Ho, Cofounder and Chief Strategy Officer, Perplexity
OpenAI’s Safety Record Raises the Stakes
OpenAI’s GPT-6 Astra launch post says the model is rolling out to a limited group of organizations before broader availability through ChatGPT, the API, Microsoft Azure and Amazon Bedrock. OpenAI reports that Astra scores 100% on ExploitBench, compared with 78.5% for GPT-5.6 Sol, and reaches a 42.4% success rate on ExploitGym, compared with 30.3% for its predecessor.
Those figures come from evaluations run without production safeguards. OpenAI says expert-led assessments found that Astra could use previously unknown vulnerabilities to achieve arbitrary code execution in hardened browsers and create privilege-escalation exploits against hardened operating systems. The company says the version launching publicly refuses more advanced cybersecurity tasks, while additional safeguards monitor model reasoning and actions for unauthorized behavior.
That distinction matters to Perplexity’s account. Ho is describing trust in a deployed system, not unrestricted access to an unguarded model. OpenAI’s Astra system card says tool-using inference receives security controls and universal monitoring for possible misalignment, with human intervention available to stop workloads when needed.
A Narrow Claim With Broad Implications
Perplexity’s endorsement does not establish that Astra independently operates production infrastructure or makes unsupervised changes without approval gates. OpenAI’s post supports a narrower claim: Perplexity uses the model for communications, software editing, monitoring and automated testing, and its executive says the company needs fewer check-ins than with earlier models.
The account also leaves out the operational details engineers would need to assess the arrangement, including which actions require confirmation, how changes are reviewed, what access boundaries exist and how often Astra’s work is rolled back. Those omissions do not negate Ho’s statement, but they limit what can be concluded about autonomy in Perplexity’s live systems.
For now, the clearest fact is the one Perplexity supplied directly: the company says GPT-6 Astra is trusted with full end-to-end systems and receives less frequent human attention than previous models.