OpenAI says Astra crosses its critical cybersecurity capability threshold
Astra can chain zero-day exploits across hardened systems, prompting OpenAI to restrict early access and strengthen safeguards.
OpenAI says its upcoming Astra model has reached the Critical cybersecurity capability threshold in its Preparedness Framework—the first model it has classified at that level. The company detailed the findings in OpenAI News on September 1, 2026.
The designation means Astra can, with suitable tools and access, identify previously unknown flaws and develop exploits across well-protected systems without step-by-step human guidance. OpenAI says the model scored 100% on ExploitBench, a benchmark focused on exploiting known vulnerabilities.
What the evaluations found
To address potential benchmark contamination, OpenAI created an internal test set containing 20 recently disclosed, high-severity V8 vulnerabilities. Astra achieved substantially higher arbitrary-code-execution rates than GPT-5.6 Sol while using fewer output tokens. During testing, it also found and used two zero-day vulnerabilities in an exploit chain; OpenAI says those flaws are being disclosed to maintainers.
Expert assessments produced more serious results: Astra built a browser-compromise chain that escaped a sandbox and executed commands on the host, and combined operating-system flaws into a privilege-escalation path from an unprivileged user to root.
Restricted rollout
OpenAI says it delayed parts of Astra’s development and release while adding stronger refusal training, misuse protections, monitoring, and controls against unauthorized actions. The company paused some frontier training for two weeks after the Hugging Face incident, restarted a large frontier reinforcement-learning run on August 28, and is still holding back some smaller experiments.
Astra is expected to become available soon, but its most advanced cybersecurity capabilities will initially be limited to testers, with broader defensive access planned through Daybreak Blue. The model’s system card will provide more safety and evaluation details at launch.
Source: OpenAI News
Comments
Log in to join the discussion