AIToday
AI Business & IndustryOpenAI BlogPublished: Aug 8, 2026, 04:01 JST

OpenAI: Astra cannot rule out critical cyber risk

OpenAI: Astra cannot rule out critical cyber risk

3 Key Points

  1. What happened

    OpenAI's internal evaluations of Astra, one of its upcoming models, indicate significant advancements in agentic coding and cybersecurity. Based on these results and expert assessments, OpenAI concluded it cannot rule out critical cyber capabilities under its Preparedness Framework.

  2. Why it matters

    This is the first time an OpenAI model has reached this threshold; previous models, including GPT-5.6-Sol, were assessed at the High (rather than Critical) level. In response, OpenAI is implementing stricter security controls, pausing some Astra activities, and adding universal monitoring for risky actions.

  3. What to watch

    The assessment is preliminary, and OpenAI is scaling up robustness testing and will work with government agencies and select AI safety organizations to test Astra's capabilities. The outcome hinges on whether these tests confirm or rule out the Critical capability level.

Not sure about something? Ask the AI

Questions and answers are published on this page.

Summaries like this, in your inbox every morning.

Context & Analysis

OpenAI's announcement marks a notable shift in its capability assessments, as it is the first time the company says it cannot rule out Critical cyber capabilities for a model. The Preparedness Framework, first published in December 2023, was designed to guide the company's actions as models approach biological, chemical, cybersecurity, and AI self-improvement capabilities. Previous models, including GPT-5.6-Sol, were evaluated at the High threshold for frontier cyber capabilities.

The company is applying the same principle it used in June 2025 when models approached the high capability threshold for biology, outlining steps to strengthen safeguards and expand testing. Now, OpenAI is implementing stricter controls, pausing some Astra activities, and adding universal monitoring. The framework has already guided the company through other capability transitions.

The stakes hinge on whether further testing, in partnership with government agencies and AI safety organizations, will confirm the Critical assessment. If confirmed, it would represent a significant advancement in what AI models can do in cybersecurity, potentially outpacing current safeguards. The company's ability to balance transparency with secure development will be tested as it navigates this potential shift.

FAQ
What does 'Critical' mean under OpenAI's Preparedness Framework?
A model reaches the Critical cybersecurity threshold if it can identify and develop functional zero-day exploits of all severity levels in many hardened real-world critical systems without human intervention, or devise and execute end-to-end novel cyberattack strategies against hardened targets from a high-level goal.
Was Astra involved in the recent Hugging Face incident?
No, the article states that Astra was not involved in exploiting Hugging Face.

Get the latest AI Business & Industry news every morning

For example, today's edition would include:

  • Instinct raises $1B at $10B valuation for personal AI agentSiliconANGLE AI · 2h ago
  • Modulate raises $25M to push audio-native AI to developersSiliconANGLE AI · 2h ago
  • CoreWeave's top three customers drive 70% of revenue, Vellante saysSiliconANGLE AI · 2h ago

AI-summarized, only the topics you pick: one digest a day via Email, LINE, or Slack.

Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →

Ask AI

Ask AI anything about this article. The AI reads this article, earlier AIToday articles, and Wikipedia, and cites its sources. Q&As are published on this page for other readers too.

Questions and answers are published on this page.

Related Articles

Next articleCohere Health digitizes clinical policies using AWS Bedrock agents