Three weeks after the public debut of OpenAI’s GPT-6 Astra, independent evaluation metrics circulating among artificial intelligence researchers indicate a stark functional divergence between the leading frontier models. Performance data published by Shattered.io demonstrates that Astra has established a decisive lead over Anthropic’s Claude Fable 5.1 in offensive cybersecurity tests, while Fable 5.1 continues to retain its advantage in standard software engineering tasks. This performance split is restructuring enterprise procurement evaluations and reportedly prompting Anthropic to evaluate an accelerated model release schedule rather than maintaining its planned development timeline.
Enterprise Purchasing Split: Offensive Cyber vs Software Engineering
The performance divergence between GPT-6 Astra and Claude Fable 5.1 is forcing corporate security and engineering departments to decouple their technology evaluations. Rather than selecting a single universal model provider, enterprise buyers are increasingly treating offensive security capabilities and software development functionality as distinct procurement decisions. Data compiled in a comparative review by CodingFleet shows that GPT-6 Astra achieved an 88.0% success rate on the SRE-Bench reverse-engineering evaluation on a single attempt, compared to 12.5% for Anthropic’s Claude Fable 5.1. When granted four solution attempts, Astra’s resolution rate rose to 99.2%.
A similar disparity emerged in ExploitBench testing, which evaluates a system’s ability to convert documented software vulnerabilities into functional exploit payloads. In an unsafeguarded test environment, GPT-6 Astra recorded a 100.0% completion rate, whereas Claude Fable 5.1 and Claude Opus 5 both scored 70.0%. On a subset of vulnerabilities logged between June and August 2026, Astra achieved 39.0% accuracy compared to 5.5% for OpenAI’s previous generation model, GPT-5.6 Sol. On the broader ExploitGym test suite, Astra reached 42.4%, while GPT-5.6 Sol registered 30.3%.
OpenAI’s System Card and the ‘Critical’ Cyber Risk Classification
OpenAI published Astra’s official system card through its Deployment Safety Hub on September 3, 2026. Coverage by BleepingComputer noted that Astra is the first broadly deployed model to reach the ‘Critical’ threshold for cybersecurity capabilities under OpenAI’s internal Preparedness Framework. This classification indicates that the model possesses autonomous capabilities to identify previously unrecorded zero-day vulnerabilities and construct multi-stage exploitation sequences against protected infrastructures without step-by-step human intervention.
Under OpenAI’s deployment guidelines, entering the Critical tier triggers heightened access controls, enhanced real-time usage monitoring, and restricted default tool integrations rather than a release halt. To support its claims regarding model control, OpenAI disclosed internal testing results spanning over 54,000 Codex execution tasks. The data revealed that Astra produced 34 severity-3 or higher misalignment flags (a rate of 0.063%), representing a 53% decrease compared to GPT-5.6 Sol, which generated 73 flags (0.135%). Furthermore, Astra recorded zero severity-4 safety flags. However, independent analysts caution that these alignment metrics reflect self-reported internal testing rather than third-party audit verification.
Software Engineering Resilience: Where Claude Fable 5.1 Holds Ground
Despite Astra’s dominance in vulnerability exploitation, Anthropic maintains a clear lead in primary software development benchmarks. Model-tracking platform Hokai reported that Claude Fable 5.1 occupies the top position on the September 2026 SWE-bench Pro leaderboard with an 81.2% resolution rate. This places Fable 5.1 ahead of Claude Fable 5 (80.0%), Claude Opus 5 (79.2%), and OpenAI’s GPT-5.6 Sol (64.6%). Notably, OpenAI has not published fully verified SWE-bench Pro figures for Astra, creating a noticeable gap in comparative general coding metrics.
In broader cognitive reasoning and code maintenance benchmarks, Fable 5.1 recorded 97.5% on ARC-AGI-1 and 90.0% on ARC-AGI-2 under maximum compute configurations, as well as 89.1% on SWE-bench Multilingual. Anthropic also documented an architectural reliability improvement: the model’s unintended fallback rate—instances where the core system unexpectedly routes requests to an alternate model architecture mid-task—decreased from 7.8% in Fable 5.0 to 2.1% in Fable 5.1. This stability gain is critical for infrastructure engineers requiring predictable model responses during code compilation and deployment pipeline tasks.
Strategic Implications for Anthropic and Enterprise Security Strategy
The dramatic gap in vulnerability research capability has created strategic pressure for Anthropic. According to Shattered.io, Anthropic leadership is reviewing whether to expedite its next model iteration to address the 75.5 percentage-point disparity on SRE-Bench. Anthropic’s current position follows a period of heightened caution, during which the firm paused certain red-teaming cyber evaluations after several cybersecurity breaches were reported earlier in 2026. Anthropic previously acknowledged structural limitations in its evaluation framework, noting in a technical publication that it had over-relied on single-layer defensive controls during internal red-teaming exercises.
For enterprise technology executives, the choice between Astra and Fable 5.1 presents operational trade-offs. Organizations seeking automated defensive security tools, automated patch generation, and vulnerability discovery are prioritizing Astra’s capabilities while implementing strict API access boundaries. Conversely, software development organizations focused on repository-level code generation, bug fixing, and multi-language software architecture continue to favor Fable 5.1 due to its superior SWE-bench Pro performance and lower operational error rates.

