OpenAI’s Astra Model Reaches ‘Critical’ Cybersecurity Level

Astra-nomical risk.
Elizabeth Rigsby
Contributing Writer
Abstract illustration of a brain filled with colorful neural pathways, surrounded by digital waveforms on a dark background.
stock.adobe.com - Who is Danny

OpenAI says its upcoming Astra model has reached a cybersecurity capability level no previous model from the company has crossed.

Under the company’s Preparedness Framework, Astra now carries a “Critical” classification, the highest level for cybersecurity. The designation applies to capabilities that could create new ways to cause serious cyber harm if misused.

A release is still planned soon, though the model will arrive with tighter controls following several weeks of additional safety and security work.

Why It Matters: Astra introduces a different timeline for vulnerability discovery and response. If a model can move from finding an unknown flaw to building a working exploit with limited human guidance, organizations may have less time between a vulnerability being discovered and becoming usable. OpenAI’s decision to restrict access acknowledges that tension. The same capability that could help defenders find weaknesses faster could also make advanced exploit development easier to carry out.

  • What Critical Means: The classification applies when a model can independently find and exploit zero-day vulnerabilities across hardened systems or develop new end-to-end attack methods from a high-level objective. Astra is the first OpenAI model to meet that threshold, outperforming GPT-5.6 Sol in vulnerability identification and exploit development while using fewer tokens.
  • Zero-Days in Testing: Astra scored 100% on ExploitBench, which tests whether models can develop exploits for known vulnerabilities. OpenAI followed with an internal benchmark built around 20 recently disclosed high-severity flaws, where Astra discovered two previously unknown vulnerabilities and used them in an exploit chain. The company is working with the affected maintainers to disclose the flaws.
  • Building Working Exploits: Expert-led evaluations tested the model against a hardened browser and operating system. In one case, Astra built an exploit chain that escaped the browser sandbox and executed commands on the host. In separate testing, the model found and combined operating-system vulnerabilities to move from an unprivileged account to root access.
  • Lessons From Hugging Face: Although Astra was not involved in the July incident where OpenAI agents escaped a training environment and compromised Hugging Face systems, the event changed how the company approached its development. Certain frontier training was paused for two weeks while isolation, network controls and monitoring were strengthened. OpenAI later tested whether Astra would access prohibited systems when faced with difficult tasks. The model stayed within its assigned task, while GPT-5.6 Sol attempted to access honeypot targets in 56% of comparable tests without production safeguards.
  • A Controlled Rollout: Advanced cybersecurity workflows will initially go to a small group of testers before access expands through Daybreak Blue, OpenAI’s defensive security program. Cyber jailbreak evaluations also found that Astra refused 91.5% of prohibited requests, compared with 59% for GPT-5.6 Sol. Those protections may occasionally interrupt legitimate work, and more detail about the model’s testing and safeguards is expected in its system card at launch.

Go Deeper -> Path to Astra: critical capabilities and frontier safeguards – OpenAI

OpenAI says Astra AI model is its first that crosses ‘Critical’ cybersecurity capability – CNBC

OpenAI’s Astra model is on the way — and very good at breaking into computer systems – TechCrunch

Cybersecurity updates, executive insights, and the stories shaping the enterprise.

Browse past editions of TNCR newsletters. 

Technology news, cybersecurity, & executive insights.

×
You have free article(s) left this month courtesy of the CIO Professional Network.

Enter your username and password to access premium features.

Don’t have an account? Join the community.

Would You Like To Save Articles?

Enter your username and password to access premium features.

Don’t have an account? Join the community.

Thanks for subscribing!

We’re excited to have you on board. Stay tuned for the latest technology news delivered straight to your inbox.

Save My Spot For TNCR LIVE!

Thursday April 18th

9 AM Pacific / 11 PM Central / 12 PM Eastern

Register for Unlimited Access

Already a member?

Digital Monthly

$12.00/ month

Billed Monthly

Digital Annual

$10.00/ month

Billed Annually

Would You Like To Save Books?

Enter your username and password to access premium features.

Don’t have an account? Join the community.

Log In To Access Premium Features

Sign Up For A Free Account

Name
Newsletters