OpenAI Pauses Parts of Astra Over 'Critical' Cyber Risk
OpenAI has paused internal work on parts of Astra, the unreleased model behind its recent math breakthroughs, after preliminary evaluations found it may have crossed a "Critical" cybersecurity capability threshold — the first time in nearly three years of testing that any OpenAI model has come close.
What OpenAI found
In an August 7 post, OpenAI said its latest internal evaluations of Astra showed significant advances in agentic coding and cybersecurity, strong enough that the company "cannot rule out" Astra has reached the Critical threshold defined in its Preparedness Framework. Under that framework, a model is Critical for cybersecurity if it can independently identify and build working exploits for previously unknown vulnerabilities across many hardened real-world systems, or can plan and carry out an entire cyberattack against a hardened target from nothing more than a high-level goal, without a human directing each step.
OpenAI was explicit that this is a preliminary finding, not a confirmed capability, and that Astra was not involved in the unrelated incident where OpenAI models were used to breach Hugging Face's servers earlier this year. Previous models, including GPT-5.6 Sol, were assessed at the lower "High" threshold for cyber capability, not Critical.
What OpenAI is doing about it
The company says it is now requiring isolated testing environments, restricted network and tool access, stronger model weight protections and encryption, and sandboxed execution for any higher-capability work on Astra, and has paused all internal Astra activities that don't yet meet those new controls. It has also rolled out monitoring across every agentic use of Astra that reviews the model's reasoning in real time and can interrupt high-risk activity, and says it will work with government agencies and outside AI safety organizations to independently test the model's capabilities before it ships.
Why this matters to small and medium businesses
Treat this as an early warning about how fast offensive AI cyber capability is moving, not just an OpenAI story. Small businesses are frequently the easiest targets precisely because they lack dedicated security teams — if a leading AI lab is worried about its own unreleased model autonomously finding and exploiting vulnerabilities, that's a good prompt to shore up basic protections now: patched software, multi-factor authentication, and tested backups.
OpenAI pausing itself and publishing the findings is a genuinely good sign, but it doesn't mean the risk goes away. Similar capability will eventually show up in models built by less careful actors. The gap between "a responsible lab is being cautious" and "this capability exists somewhere" is exactly where small businesses tend to get caught off guard.
Watch for follow-on guidance. OpenAI says it will work with government agencies on testing Astra's capabilities, which could feed into new official best practices or compliance expectations, especially if your business handles sensitive customer or financial data.
Sources: