
As of September 3 to 4, 2026, GPT-6 Astra, OpenAI's newest frontier model, became selectable in Microsoft Copilot Cowork and Copilot Studio, generally available in Microsoft Foundry, and available in GitHub Copilot.

In Cowork and Copilot Studio the rollout is gradual and varies by region and tenant, and administrators manage availability from the Microsoft 365 admin center. Because Astra is built for multi-step, tool-using, computer-use work rather than chat, choosing it as an agent's model is a governance decision about capability, risk, and cost, not a cosmetic setting.
The headline is easy to miss because Microsoft's own announcement was four sentences long. The substance is not. GPT-6 Astra is the first model where the improvement people notice is the quality of the work, not the quality of the answer. That single shift is why agent-level model selection now belongs on your governance agenda. For the wider context on why 2026 is the year governance and capability converge, see our analysis of the Copilot governance gap and why deployments stall.
OpenAI introduced GPT-6 Astra on September 3, 2026, describing it as its most capable and most aligned model to date. Microsoft brought it into the enterprise stack the same week. The availability story is not uniform across surfaces, and that difference is exactly where the governance work lives.
OpenAI shipped Astra off by default for enterprise ChatGPT workspaces. Microsoft's surfaces do not all inherit that posture. In Copilot Cowork and Copilot Studio the model can appear in the picker as the rollout reaches your tenant, so treat Astra access as product-specific and tenant-specific, and confirm it in your own admin center rather than assuming a default.
Every prior model generation improved the quality of the response. GPT-6 Astra improves the quality of the work. Microsoft frames it around three functions: deliberate planning and decision support, polished purposeful output, and execution across applications using tool use and computer use.
None of that is about conversation. All of it is about completing a unit of work with human oversight.
Astra can interpret on-screen information and interact with approved interfaces, including applications that have no dedicated API, to do things like update records, navigate tools, test software, and assemble results into reports. It supports up to roughly 1 million context tokens and is positioned for long-horizon agentic workflows.
Microsoft is candid that this level of capability demands containment: content displayed in an application may be incomplete, misleading, or crafted to influence an agent's behavior, so workflows need scoped credentials, approved resources, human checkpoints for consequential actions, and activity records.
There is one more disclosure leaders should not skip. OpenAI reported that Astra is the first of its models to cross the Critical cybersecurity threshold under its Preparedness Framework, scoring 100% on the ExploitBench evaluation in testing. Microsoft and OpenAI pair the model with additional safeguards, and Astra refuses advanced offensive tasks such as building proof-of-concept exploits.
For a defender, this is a reminder that model capability and model risk now move together. Our take on designing for that reality is in why Copilot and agent governance fails without an operating model.
In Copilot Cowork, Astra appears in the model picker under the GPT family. The default is Auto, which lets Cowork choose the most suitable model from the set your organization has enabled, and a model badge shows which model produced each response. In Copilot Studio, a maker can select Astra as the agent's primary model through a dropdown in the model settings, then test the agent against a real use case before publishing.

The important point for governance is that the picker is a distribution mechanism. The moment Astra is enabled and visible, any approved maker can point a partnered-zone or citizen-zone agent at a frontier, computer-use-capable model. That is powerful, and it is precisely why the decision needs a policy behind it. Our CIO's playbook for moving from agent chaos to agent control walks through the decision policies that keep this from turning into agent sprawl.
The reasoning power belongs to Astra. The organizational context belongs to Work IQ. In Copilot Cowork, Work IQ grounds the model in the files, meetings, chats, and business data the user already has permission to access, so the model reasons over a real work context while respecting existing permissions. Astra does not grant new access. It uses what the signed-in user is already authorized to see.
Grounding on the user's existing permissions is a feature and a warning. Copilot does not create oversharing. It exposes the oversharing that already exists, and a more capable, more autonomous model surfaces and acts on that exposure faster. If your permission hygiene is weak, Astra makes the blast radius bigger, not smaller.
This is why we keep telling clients that governance is the accelerator, not the brake. In one Secure AI and Governance engagement, we built a Zero Trust, Microsoft Purview based foundation in about eight weeks and enabled safe Copilot adoption by remediating oversharing before scaling. The full story is in our secure Copilot adoption in 8 weeks case study. The pattern holds for Astra: fix the foundation, then turn up the capability.
Treat the Astra rollout as a prompt to make five decisions deliberately rather than by default. None of these require a large program. All of them require an owner.
If you want a structured way to pressure-test readiness across security, data, cost, and operating model before scaling, our agent governance operating model and Agent PMO guidance turns these five decisions into repeatable workflows your team can actually follow.
Model choice is a trade-off, not an upgrade. Use this to decide where Astra earns its place and where a lighter, faster, cheaper model is the responsible pick.
The takeaway is not "turn Astra on everywhere." It is "match the model to the work, and make sure a governance decision sits behind every agent that uses a frontier model." For how to prove the value once you do enable it, see our measurable Copilot ROI case study, which turned licenses into 1,115 hours saved and a 4.5-month payback.
Microsoft did the hard part by making a frontier, work-completing model a first-class, admin-controlled option inside Copilot Cowork and Copilot Studio. That is genuinely useful. It also quietly moved a decision onto your plate that used to belong to Microsoft: which model, in which agent, for which risk, at what cost.
Organizations that win with Astra will not be the ones that enable it fastest. They will be the ones that already have an operating model, so a new frontier model is a config change inside a governed system rather than a scramble. If you are building agents, model choice is now part of your control plane. Design it that way.
Ready to make model choice a governed decision, not a default?
2toLead helps CIOs, IT leaders, and Power Platform teams turn Copilot and agent capability into secure, measurable business value. If GPT-6 Astra is landing in your tenant, we can help you set the guardrails, zones, and cost controls before makers discover it.
Is GPT-6 Astra available in Copilot Cowork and Copilot Studio right now?
Yes, it began rolling out on September 4, 2026, as a selectable model in both Copilot Cowork and Copilot Studio. The rollout is gradual and varies by region and organization, so it may not appear in every tenant on the same day. Administrators manage availability through the Microsoft 365 admin center.
Who controls whether my organization can use GPT-6 Astra?
For Copilot Cowork and Copilot Studio, Microsoft 365 admins control availability from the Microsoft 365 admin center, with additional Power Platform controls for Copilot Studio agents. In Microsoft Foundry it is generally available to all customers. In ChatGPT's enterprise workspaces, OpenAI ships Astra off by default and enterprise admins enable it.
Why is choosing GPT-6 Astra a governance decision and not just a setting?
Astra is built for multi-step, tool-using, and computer-use work that completes a unit of work rather than answering a question. That capability carries higher autonomy, a premium consumption cost, and a Critical cybersecurity classification from OpenAI. Pointing an agent at it changes what the agent can do on a bad day, so it needs zoned access, human checkpoints, audit, and cost controls.
Does GPT-6 Astra get access to data users are not allowed to see?
No. In Copilot Cowork, Work IQ grounds Astra in the files, meetings, chats, and business data the signed-in user already has permission to access. The model does not grant new access. The risk is that pre-existing oversharing becomes easier to surface and act on, which is why permission hygiene and Purview controls matter before you scale.
How much does GPT-6 Astra cost to use?
Astra is a premium, consumption-metered model. Copilot Cowork task execution and agent runs draw on usage-based billing, and Foundry publishes token-based pricing (for example, list pricing began around 10 US dollars per million input tokens and 50 US dollars per million output tokens under Standard Global). Set caps, budgets, and alerts before enabling it broadly.
What should we do first before enabling GPT-6 Astra for agents?
Confirm the rollout status in your admin center, decide availability on purpose, scope the model to partnered or professional agent zones, require human checkpoints for consequential actions, add cost guardrails, and re-run oversharing and readiness checks. Start with a pilot in a governed zone rather than broad enablement.
Join Our Newsletter