OpenAI says its forthcoming **Astra** model has become the first system it classifies at the **Critical cybersecurity capability** threshold under its Preparedness Framework. The company says Astra can identify previously unknown vulnerabilities and develop exploits across well-protected systems with less human guidance than current public models.\n\nThe key product news is not simply a benchmark result. OpenAI says the capability threshold changes how Astra will be deployed: the most advanced cybersecurity capabilities will have tighter access, while additional abuse detection, account risk controls and alignment monitoring will sit around the broader release.\n\n## A capability milestone with deployment consequences\n\nOpenAI reports that Astra scored 100% on ExploitBench and found two zero-day vulnerabilities in an internal recent-vulnerability evaluation. Those are first-party evaluation results and should not be treated as independent validation of real-world effectiveness. Independent reporting nevertheless confirms the more important operational point: OpenAI is preparing a restricted launch because the company itself believes the model has crossed its highest published cyber-risk threshold.\n\nOpenAI also warns that the extra safeguards may interrupt legitimate defensive work. Its launch material says long-running tasks can be paused or stopped when monitoring systems detect potential misuse or misalignment. In ChatGPT or Codex, users may be asked to review a paused action; on API surfaces, the task may stop outright.\n\n## What remains uncertain\n\nAstra is still forthcoming, so AiToolMap should not describe it as generally available or rewrite current ChatGPT model facts as though the launch has already happened. The announcement is best treated as a fresh deployment-and-safety update now, with a separate canonical review trigger only when the actual product availability and surface mapping are confirmed.
← ALL NEWS
UPDATE · 2026-09-03
OpenAI says Astra has crossed its critical cyber threshold and will launch with tighter safeguards
OpenAI says its forthcoming Astra model is the first to meet the company’s Critical cybersecurity capability threshold, prompting restricted advanced access and extra monitoring before release.