From identifying unknown IT vulnerabilities, to developing ways to exploit them and link multiple flaws. To the point of compromising a protected system, without a human being having to guide every single step. Astra, the new model of artificial intelligence by OpenAIhas achieved capabilities in the field of cybersecurity that the company itself considers to be of a high level “Critical”the highest step in its risk assessment system.
It is the first time that OpenAI has assigned this classification to one of its models. Astra is expected to be made available “soon”, but its more advanced cyber capabilities will initially only be accessible to a limited group of users, while the launch will be accompanied by stricter security systems.
As we prepare to release Astra, we’re focused on making increasingly capable AI safe and broadly accessible.
Astra represents a significant advance in cybersecurity capability, reaching the Critical threshold under our Preparedness Framework.
We’re previewing how we evaluated…
— OpenAI (@OpenAI) September 1, 2026
OpenAI’s critical threshold
The classification falls under Preparedness Frameworkthe system with which OpenAI evaluates the capabilities of models that could introduce risks of serious damage. In the field of cybersecurity, the “Critical” threshold is reached when a model is able to, among other things, independently identify and develop working exploits for zero-day vulnerabilities in protected real systems, or conceive and execute end-to-end cyber attack strategies starting from only an overall objective.
Astra’s discoveries
What pushed OpenAI towards this evaluation were above all the results obtained during the tests. On ExploitBencha benchmark used to measure the ability to develop exploits from known vulnerabilities, Astra achieved a score of 100%.
The company then created an internal benchmark based on 20 high-severity vulnerabilities made public between June and August 2026, to reduce the risk that the results were influenced by data already present in the training. In this test Astra showed significantly superior capabilities to GPT-5.6 Sol and, above all, it has identified and exploited two zero-day vulnerabilities within an exploit chain. OpenAI has begun the process of communicating these to affected developers.
In other expert evaluations, Astra was able to discover unknown vulnerabilities in a protected browser and combine them into an attack chain capable of breaking out of the sandbox and executing commands on the host system. In an operating system subjected to strengthened security measures, the model instead chained together multiple flaws to obtain aprivilege escalationswitching from a normal user to root access.
Fears about AI after Hugging Face
The launch of Astra also comes after the cyber incident involving it Hugging Face. Astra was not involved, but OpenAI explained that it had used what happened to strengthen the security measures of the new model and that it had slowed some of its development while new protections were tested.
The company identifies two main risks. The first is for malicious actors to use Astra to find unknown flaws and construct attacks against protected systems. The second concerns the possibility that a model with such advanced capabilities can perform unauthorized or misaligned actionseven in the absence of a user intending to cause damage. To reduce these risks, OpenAI says it has strengthened both training and monitoring systems. In tests of attempts to bypass cyber protections, Astra rejected 91.5% of prohibited requests, compared to 59% for GPT-5.6 Sol.
Limited access to the most powerful abilities
However, OpenAI plans to proceed with the launch, arguing that the protections introduced sufficiently reduce the risk of serious damage. However, the most advanced cyber features will initially be reserved for a small group of testers and subsequently made available through Daybreak Bluethe company’s program dedicated to the defensive uses of cybersecurity.
The new protections may also affect legitimate users. OpenAI warns that some activities may be slowed, paused or blocked if control systems interpret them as potentially dangerous. In ChatGPT or Codex the user may be asked to verify an action before continuing, while through the API the task can be interrupted.
Astra therefore represents a double leap: in the offensive and defensive capabilities of artificial intelligence and in the systems needed to try to control them. OpenAI claims the model is ready for release, but recognizes that the arrival of increasingly autonomous systems will increasingly blur the line between what an AI can do and what it should be allowed to do.
My cousin sent me a Telegram
So There I Was In The Waiting Room At The Dentist
Untitled22333 | Caramella
Servicing your car outside of the dealer network
What a ridiculous weekend
U of G – Foundations in Agricultural Management Course
Evening folks, sitting on the
52753
Your potential is limitless, let us help you find your place in the workforce
Writtle Jazz Festival Returns!
Главная страница
Alright guys, I was reading a t· Customer Self-Service
The Value of Scrap Silver: From Waste to Workshops
What a bizarre evening it turned | Project WET
I Was Scrolling Through Instagram
Spring is coming, just look at these tom turkeys.
So there I was in the waitin
What a ridiculous Sunday
Summer of Fun at the Farm
Evening everyone, I was lurking – Official Fulqrum Publishing forum
Clase muestra del diplomado en Feminicidio. Aspectos criminológicos
8888779.Htm
I was reading a blog reviewing the – Blog Writing
SCC HelpDesk Update
Titan Blast XR – Reviews,Cost and Side Effect | Throne Forum
(+2347044417593) I want to join illuminati occult for money ritual – theorchestrafornow.com
The Lobster Invitational Winners are Here
BORGWARD OWNERS' INTERACTIVE MESSAGE BOARD: What a bizarre evening
Top 5 Home Renovation Challenges Montreal Homeowners Face (and How to Solve Them)
Bloody hell, what a miserable