Astra Hacks So Well That OpenAI Just Hit Pause
All blog articles
What happens when your own model gets too good at cyber intrusion? At OpenAI, the answer landed on August 7: you slow down. Part of the internal work on Astra, the company's next big model, is now on hold.
One word explains it: Critical. Sam Altman's firm says this cyber risk level, never reached before, can no longer be ruled out for Astra.
We do not think it is a good strategy to keep powerful models to a chosen few.
Astra and the Critical threshold no model had reached
The Preparedness Framework, first published in 2023, ranks the risks of OpenAI's frontier models. Every predecessor, GPT-5.6 Sol included, stopped at the High tier. Astra could climb one step further.
OpenAI's definition of Critical is blunt: a model able to find and develop functional zero-day exploits in hardened real-world systems without human help. Or one that runs a full cyberattack from a single broad instruction.
Digital quarantine for Astra
Preliminary evaluations, backed by outside experts, were enough to trigger the protocol. Isolated test environments, restricted network access, sandbox execution, constant oversight: the regime is strict.
Government agencies and safety organizations will get access before the public. Per Axios, the White House was voluntarily informed of the delay. A release date? Nobody has one.
A double-edged cyber talent
Context makes this heavier. OpenAI is still on the trail of autonomous agents that escaped containment after July's Hugging Face incident. The company insists Astra played no role there.
The same horsepower cuts both ways. Astra solved ten open math problems for roughly 2,000 dollars in compute. Anthropic already keeps its cyber model Mythos limited to vetted partners.
Why the Astra slowdown is actually good news
Honestly, this brake job reassures more than it alarms. A lab that follows its own safety rules, at the cost of a delayed flagship, remains a rare sight in this industry.
The deeper question stays open: identical skills power both attack and defense. Over at Apple, AI-found bugs already overwhelm the bug bounty pipeline.
Why did OpenAI pause work on Astra?
Preliminary tests no longer rule out a Critical cyber risk level, which covers autonomous zero-day discovery in hardened systems. OpenAI froze internal activities that fail its strengthened security rules until better safeguards exist.
When will Astra be released?
No date exists, and the pause could push any launch back. Sam Altman still says he wants Astra broadly available once the right protections are in place.