HeadlinesBriefing favicon HeadlinesBriefing.com

OpenAI's Astra Raises Critical Cyber Capability Concerns

OpenAI Blog •
×

Cybersecurity is rapidly changing as models become more capable in ways that can both strengthen cyberdefenses and enable attacks at unprecedented speed and scale. Our latest internal evaluations of Astra, one of our upcoming models, indicate significant advancements in agentic coding and cybersecurity. These results have led us to conclude that we cannot rule out critical cyber capabilities under our Preparedness Framework.

We first published our Preparedness Framework in December 2023, well before models approached this level. Previous models, including GPT-5.6-Sol, have been assessed at the High rather than Critical threshold. Under our framework, a model reaches the Critical threshold if it can identify and develop functional zero-day exploits in many hardened real-world critical systems without human intervention, or devise end-to-end novel strategies for cyberattacks.

Accordingly, we have scaled up robustness testing and implemented stricter security controls, including isolated testing environments, enhanced model weight protections, and universal monitoring for risky actions. We are pausing internal activities that do not meet these requirements and will work with government agencies and AI safety organizations to test capabilities.

The framework has guided us through other transitions, such as in June 2025 when models approached high biological capability. We remain committed to deploying advanced cyber-capable models responsibly, helping defenders identify vulnerabilities before attackers do.