OpenAI Pauses Some Astra Work as Tests Raise Critical Cyber Question
OpenAI says preliminary testing means it cannot rule out that its upcoming Astra model reaches its Critical cyber-capability threshold. The company has paused internal Astra activity that lacks strengthened security controls, making its voluntary preparedness framework an immediate constraint on development—but not yet a finding that Astra can autonomously attack hardened systems or a decision to cancel it.
- OpenAI has not designated Astra a Critical cyber-capability model; its preliminary evaluation says only that the company cannot rule that threshold out.
- The company is pausing internal Astra activities that do not meet new controls, while continuing benchmarking and robustness testing.
- The test for the policy is practical: whether safeguards hold during continued development before any future release.
OpenAI, the developer of ChatGPT whose earlier models including GPT-5.6-Sol were assessed at the lower High cyber threshold, has put a security gate around its upcoming Astra model. The company said in its announcement that recent internal evaluations and expert assessments show enough progress in agentic coding and cybersecurity that it cannot rule out Critical capability.
That is not a declaration that Astra has reached the level. OpenAI says it is still benchmarking and assessing the unreleased model; a contemporaneous account likewise describes the findings as preliminary. The firm has announced no release date, and says Astra was not involved in the Hugging Face exploitation.
The concrete change is that OpenAI has paused internal activities involving Astra that do not meet strengthened security requirements. That converts a preparedness policy into a present development condition without establishing that the model has performed the attacks used to define the threshold.

OpenAI’s company-reported framework defines its Critical cybersecurity threshold and associated safeguard requirement. Source: OpenAI.
The claim is narrower than an autonomous-hacking finding
Astra is an upcoming OpenAI model, not a released product. Under OpenAI’s Preparedness Framework, Critical cyber capability means a model could either identify and develop functional zero-day exploits of every severity level across many hardened, real-world critical systems without human help, or devise and execute novel end-to-end attacks against hardened targets from a high-level goal.
Those are demanding tests. OpenAI says its preliminary results are strong enough that the threshold cannot yet be excluded, not that Astra has satisfied either definition. The distinction matters because the same framework had put earlier models, including GPT-5.6-Sol, at High rather than Critical.
