
OpenAI Says Astra Has Reached a Critical Cybersecurity Capability
OpenAI says Astra can find and exploit previously unknown flaws, prompting stronger safeguards before broader release.
OpenAI says OpenAI Astra has reached the Critical cybersecurity capability threshold in its Preparedness Framework, marking the first model the company has designated at this level. The company says Astra can identify previously unknown security flaws and develop exploit chains across hardened systems with limited human guidance.
The assessment follows several weeks of additional evaluations and safety work. OpenAI says it delayed parts of Astra's development and release while strengthening protections against cyber misuse and unauthorized model actions.
Astra showed advanced cyber capabilities
OpenAI says Astra achieved a 100% score on the ExploitBench benchmark for developing exploits from known vulnerabilities. In a newer internal benchmark using recently disclosed high-severity vulnerabilities, the model achieved higher arbitrary code-execution rates than GPT-5.6 Sol while using fewer output tokens. Evaluators also observed Astra discovering and using two zero-day vulnerabilities as part of exploit chains.
Expert-led testing found Astra could combine vulnerabilities into working attack chains against a hardened browser and operating system. OpenAI says these results led it to conclude that Astra meets the Critical threshold under its Preparedness Framework.
The update follows OpenAI's earlier Astra cybersecurity assessment, which warned in August that the model might meet the Critical threshold and led the company to pause some Astra work while stronger security controls were put in place. Astra's capabilities also represent a significant increase over GPT-5.6, according to OpenAI's latest evaluation.
Release will start with tighter access
OpenAI says Astra will be made available soon, but its most advanced cybersecurity capabilities will initially be limited to a small group of testers. Access through Daybreak Blue will follow to expand defensive cybersecurity use.
The company says Astra will launch with stronger model refusals, system-level monitoring, additional protections against misuse, and monitoring designed to detect and contain potentially unauthorized actions. OpenAI also says some legitimate cybersecurity work may be slowed, paused, or stopped while these safeguards are calibrated.