
What happened
OpenAI's internal evaluations of Astra, one of its upcoming models, indicate significant advancements in agentic coding and cybersecurity. Based on these results and expert assessments, OpenAI concluded it cannot rule out critical cyber capabilities under its Preparedness Framework.
Why it matters
This is the first time an OpenAI model has reached this threshold; previous models, including GPT-5.6-Sol, were assessed at the High (rather than Critical) level. In response, OpenAI is implementing stricter security controls, pausing some Astra activities, and adding universal monitoring for risky actions.
What to watch
The assessment is preliminary, and OpenAI is scaling up robustness testing and will work with government agencies and select AI safety organizations to test Astra's capabilities. The outcome hinges on whether these tests confirm or rule out the Critical capability level.
Summaries like this, in your inbox every morning.
OpenAI's announcement marks a notable shift in its capability assessments, as it is the first time the company says it cannot rule out Critical cyber capabilities for a model. The Preparedness Framework, first published in December 2023, was designed to guide the company's actions as models approach biological, chemical, cybersecurity, and AI self-improvement capabilities. Previous models, including GPT-5.6-Sol, were evaluated at the High threshold for frontier cyber capabilities.
The company is applying the same principle it used in June 2025 when models approached the high capability threshold for biology, outlining steps to strengthen safeguards and expand testing. Now, OpenAI is implementing stricter controls, pausing some Astra activities, and adding universal monitoring. The framework has already guided the company through other capability transitions.
The stakes hinge on whether further testing, in partnership with government agencies and AI safety organizations, will confirm the Critical assessment. If confirmed, it would represent a significant advancement in what AI models can do in cybersecurity, potentially outpacing current safeguards. The company's ability to balance transparency with secure development will be tested as it navigates this potential shift.
For example, today's edition would include:
AI-summarized, only the topics you pick: one digest a day via Email, LINE, or Slack.
Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. The AI reads this article, earlier AIToday articles, and Wikipedia, and cites its sources. Q&As are published on this page for other readers too.
Instinct, officially Spear Street Technology Inc., announced a $1 billion Series C joined by Sequoia Capital…
On theCUBE Pod, Dave Vellante said CoreWeave disclosed that 70% of its revenue came from its top three custome…
Modulate raised $25 million, led by Future Ventures with returning investors Hyperplane and Lakestar, bringing…
Google Cloud revenue hit $24.77 billion, up 82%

MGX, an Abu Dhabi-backed technology investor, is looking for data center assets in the Asia Pacific

At Semafor's The Next 3 Billion on Sept
