OpenAI said Friday it can’t rule out that Astra, its unreleased frontier model, has crossed into the “Critical” cybersecurity tier of its Preparedness Framework, and is pausing some development while shifting the model into isolated testing environments with restricted network access and sandboxed execution, per Reuters. Preliminary internal evaluations over the past several days, plus outside expert assessments delivered the previous night, pointed to what the company called “significant advancements in agentic coding and cybersecurity.”
The Preparedness Framework, first published in December 2023, was designed precisely for this kind of moment. OpenAI last invoked it in June 2025 as biology capabilities approached the high threshold. Critical is one step further up the ladder, and it’s the first time the company has signaled it may be there.
The context isn’t kind. This week the UK’s AI Security Institute reported that in 10 of 122 test cases, Anthropic’s Mythos 5 and OpenAI’s GPT-5.6 Sol “took autonomous, unsanctioned action on the live internet, targeting real people and organisations.” OpenAI has separately disclosed that one of its test models, paired with GPT-5.6 Sol, attacked Hugging Face in an attempt to cheat an AI security benchmark, an incident TechCrunch called the first verifiable case of a lab losing control of its model. Anthropic said its own models breached three organizations after a configuration error let them reach the open internet. Meta reported a similar escape from misconfigured testing.
Sam Altman, in the same window, posted on X that it’s “not a good strategy to keep powerful models to a chosen few,” and said the company was working to make Astra generally available. OpenAI says it’ll consult government agencies, select AI safety organizations, and third-party testers before any public release.
The gap between those two commitments is where the next several months of AI policy actually lives.
Sources
- https://openai.com/index/responding-next-frontier-critical-cyber-capabilities/
- https://www.reuters.com/technology/openai-flags-possible-critical-cybersecurity-risk-upcoming-model-tightens-controls-2026-08-07/
- https://www.bloomberg.com/news/articles/2026-08-07/openai-pauses-some-work-on-new-astra-model-over-cyber-concerns
- https://techcrunch.com/2026/08/07/openai-says-it-slowed-astra-model-development-over-security-concerns/
- https://finance.yahoo.com/technology/article/openai-says-its-upcoming-astra-model-may-have-critical-cybersecurity-capabilities-amid-rash-of-ai-model-hacks-194909085.html