
GPT-6 Can Now Write Its Own Cyberattacks. Here's What It Means for Your Small Business.
Last week OpenAI released GPT-6 Astra, its most powerful model yet, and did something no AI company has done before. It labelled its own product "Critical" for cybersecurity risk. Not a journalist, not a rival, not a worried researcher. OpenAI, about its own model.
For most business owners that headline slid straight past, buried under talk of parameters and benchmarks. It should not have. This is the AI news that actually touches your business, and it changes the maths on security for every small business in Australia.
Quick answer: GPT-6 Astra is the first AI its own maker has rated "Critical" for cybersecurity, meaning it can find unknown security flaws and build working attacks with little human help. For small businesses this means automated attacks are about to get faster and cheaper, so the practical response is faster patching, multi-factor authentication everywhere, and least-privilege access, starting now. You don't need to fear the technology. You need to close the easy doors before the cost of finding them drops to zero.
What actually happened, in plain English
Every serious AI lab now grades its models for how dangerous they could be. GPT-6 Astra is the first commercially released model that its own maker has classified as crossing the "Critical" threshold for cyber capability.
Here is what "Critical" means without the jargon. Given the right tools and access, the model can find security holes nobody knew existed and build working attacks to exploit them across well-protected systems, without a person guiding each step.
Put simply: the skill that used to take a trained specialist years to develop now sits inside a tool that anyone can rent by the month.
The one number that should get your attention
OpenAI ran its own test. On a set of 20 high-severity security flaws disclosed between June and August 2026, they measured how often the AI could turn a freshly announced flaw into a working attack on its own.
The previous model managed it 11.5% of the time. GPT-6 Astra managed it 39%. That is a 3.4 times jump in a single model generation.
| Previous model | GPT-6 Astra | |
|---|---|---|
| Turned a fresh flaw into a working attack | 11.5% | 39.0% |
Read that as a trend, not a one-off. The gap between a security flaw being announced and it being weaponised used to be measured in weeks, which gave you time to patch. That window is closing fast, and it is closing for everyone at once.
"But we're too small to be a target"
This is the belief that gets small businesses hurt, and it was always a little wrong. Now it is dangerously wrong.
Attackers never skipped small business because they weren't interested. They skipped it because, one by one, small businesses were not worth the manual effort. There was more money in going after big targets with the same hours of work.
Automation removes that maths entirely. When an AI can find and exploit weaknesses at scale, cheaply, the "not worth the effort" protection you never knew you had disappears. Small businesses stop being ignored and start being easy. And small businesses are easy precisely because most have never set the basics.
You are not too small to be a target. You were just too fiddly to bother with, and that just changed.
What to do this week (none of it is expensive)
The good news is that the fixes have not changed, only the urgency has. You do not need enterprise security. You need to close the easy doors, and most of it is decisions and settings, not spend.
- Turn on multi-factor authentication everywhere. Email, banking, your CRM, your Microsoft or Google accounts. This one step blocks the overwhelming majority of automated attacks on its own. If you do nothing else, do this.
- Patch faster. The old habit of "we'll update it next month" is now a real exposure. Turn on automatic updates for devices and key software, and treat anything facing the internet as urgent.
- Give people the least access they need. Not everyone needs admin rights or access to everything. The less each account can reach, the less any single breach can touch.
- Know what's exposed. Any system reachable from the internet, an old website login, a remote-access tool, a forgotten portal, is a door. You cannot protect what you have forgotten you own.
- Use business-grade tools, set up properly. Free consumer accounts and unmanaged devices are the soft underbelly. Your AI and your data are only ever as safe as the machine they are signed into.
None of this requires a security team. It requires someone to actually decide to do it, this month rather than next.
The other side of the coin: AI defends too
Here is the part the scary headlines leave out. The same leap that helps attackers helps defenders. Alongside the launch, OpenAI opened a program giving cyber defenders access to a less-restricted version for exactly this: validating vulnerabilities, analysing malware, and building better detection.
So this is not a story about doom. It is a story about an arms race that just sped up, where the businesses that quietly get their house in order pull away from the ones that assume they'll be fine.
The tools to defend are getting better at the same rate as the tools to attack. The question is simply which side of that race your business is actually on.
You don't need to be a security expert. You need one in your corner.
Here is where most advice fails a small business. The AI crowd will sell you a clever tool and go quiet when you ask how it could be turned against you. The traditional security crowd will hand you a fear-driven shopping list and no sense of what actually matters for a business your size.
You should not have to choose. The whole point is to use AI to grow, set up by someone whose instinct is to ask "and how could this be used against us?" before it becomes a headline with your name on it. Growth and safety are not opposites. Right now, getting the safety basics done is what lets you adopt AI with confidence instead of nerves.
Frequently asked questions
Is GPT-6 dangerous? The model itself is heavily restricted, off by default for businesses, and access to its most sensitive capabilities is gated. The real risk is not that you use GPT-6, it is that the general ability to automate attacks has taken a big step up, which raises the baseline threat for everyone. Treat it as a prompt to close the easy gaps, not a reason to panic.
Can hackers use AI to attack my small business? Increasingly, yes, and cheaply. Automated tools can now scan for and exploit common weaknesses at scale. The businesses that get hit are almost always the ones missing the basics like multi-factor authentication and current updates, not the ones targeted by a genius hacker.
Is my small business actually a target now? More than before. Automation removes the "too small to bother with" protection that used to keep smaller businesses off the radar. You do not need to be singled out to be caught by an automated sweep.
What is the single most important thing to do first? Turn on multi-factor authentication across email, finance and your core business systems. It is free, takes an afternoon, and blocks the large majority of automated attacks by itself.
The bottom line
GPT-6 did not create a new kind of threat. It made an existing one faster, cheaper and available to anyone. The response is not fear, it is finally doing the boring basics you have been meaning to get to, before the cost of finding your open doors drops to nothing.
If you want a clear, jargon-free picture of where your business is exposed and what to fix first, that is exactly what a free AI Game Plan session covers: an honest look at using AI to grow, safely, without the scare tactics or the shopping list.

