Answer engine optimization · News
OpenAI's Astra: what actually changes for local business AI visibility
OpenAI dropped a new model today and called it a possible arrival of AGI. GPT-6, codenamed Astra internally, went out to a limited group first, with wider access for ChatGPT Plus, Pro, Business, and Enterprise plans coming in the next few days. President Greg Brockman described it as a generational leap. It's also the first OpenAI model to hit the company's own Critical threshold for cybersecurity capability under their safety framework, which is why the initial rollout comes with tighter restrictions than any release before it.
I read through the announcement and the coverage the same way I read anything touching how ChatGPT works, because that's the engine deciding whether a client's business gets named when someone asks for a recommendation. A local business owner scrolling past this headline could reasonably wonder if it changes anything for them. So here's what I actually found, and what I'm doing about it.
What OpenAI is claiming
The headline feature isn't reasoning or writing. OpenAI is pitching Astra as a new frontier in computer and browser use, meaning the model can operate a browser and a desktop the way a person does, clicking through pages and completing multi-step tasks instead of answering from a static index. That capability is also why it tripped the cybersecurity threshold: a model that can competently drive a browser can also probe for and exploit weaknesses in one, and OpenAI treats that as serious enough to gate the release.
That's about the model acting as an agent inside a browser. Deciding which sources to trust when it answers a plain question is a separate job, running on separate logic, and today's announcement is squarely about the first one.
Why I'm not changing anything about how we test visibility
Our own audits run through the actual ChatGPT interface a real customer opens, separate from the API, because the two behave differently when it comes to what gets cited. We proved that gap ourselves back in July: the same query returned Yelp as a source 53% of the time through the interface against 44% through the API. If Astra changes how citations get selected, that's a genuine shift worth testing for, and we will test for it the moment it's broadly available rather than take OpenAI's word on it.
What Astra's own materials describe is agentic browsing. OpenAI hasn't said a word about the citation engine changing, about pulling from a different set of sources when someone asks "best day spa near me," or about weighing a business's own website any differently than it did yesterday. Until there's a reason to think the citation mechanism moved, the fixes that get a local business named stay the fixes that get a local business named: pages built around the specific question a customer actually asks, the kind that beats a general homepage trying to catch everything at once.
The safety headline, in plain terms
The Critical cybersecurity threshold sounds alarming out of context, so it's worth being precise about what it actually flags. It's an internal OpenAI benchmark measuring how well a model could exploit security weaknesses in software if someone pointed it at that task on purpose. It has nothing to do with whether the model is safe to search with or safe to book an appointment through, and nothing about it makes ChatGPT less trustworthy for a customer typing in a question about your business. The restriction is on what a bad actor could try to do with the model's coding and browsing skill, and OpenAI is gating access accordingly. Your customers using ChatGPT to find a med spa or a salon aren't the population this threshold is about.
The part that might matter down the line
Where this could eventually touch our world is booking. An agent that can operate a browser end to end could, in theory, go from "find me a med spa" straight through to placing the appointment, no human clicking a link in between. That would raise the stakes on a business's booking page working cleanly for an automated visitor the same way it needs to work cleanly for a human one, right down to whether the date picker and the confirmation step are readable by something other than a person's eyes. That's a real possibility, and it's also a year or two out from being how most people actually search, and agentic features have moved slowly from announcement to daily use so far. I'm not building anything around it yet, and I'd tell a client the same thing.
What I'd actually do this week
Ignore the AGI framing. That's a marketing choice sitting on top of a technical spec, and it changes nothing about whether your business shows up when someone asks ChatGPT a real question tonight. If you want to know where you stand today, our free 60-second check runs your business against ChatGPT's actual interface and shows you the sources it's currently pulling from. That number is worth having. What Astra means for any of this is worth revisiting once it's out of limited access and we can put real queries through it ourselves and see what actually changed.