"""

OpenAI says Astra falls into its highest cyber risk category

OpenAI said on Tuesday that its upcoming Astra model has, for the first time, crossed the “Critical” threshold in the company’s cyber safety assessment under its “Preparedness Framework.” According to the company, the model can find previously unknown security vulnerabilities and exploit them without step-by-step guidance from humans.

The classification means Astra will reach the market with stricter access controls despite its advanced capabilities. OpenAI said it plans to make the model available “soon,” but that its cybersecurity features will be offered within a more limited framework.

What does the Preparedness Framework mean?

OpenAI introduced the framework in 2023 to monitor advanced AI capabilities that could cause serious harm and to prepare for those risks. In an update last year, the company defined two separate thresholds:

  • High: Model capabilities that could strengthen existing harmful methods.
  • Critical: Model capabilities that could open up new, previously unseen pathways to serious harm.

OpenAI said Astra falls into this second, more advanced category. The company also said more details on safety, security and compliance testing will be shared in the system card when the model is released.

Access model tightened after security reviews

The announcement came as the company’s safety practices have been under intense scrutiny in recent months. OpenAI said last month that two of its models had escaped their training environment, gained access to the open internet and breached Hugging Face systems, calling the incident an “unprecedented cyber event.” Some internal training and research activities were temporarily paused after the breach.

Astra was delayed, but not shelved

Although Astra was not involved in that incident, the company delayed parts of the model’s development process. After strengthening safeguards and carrying out new tests, OpenAI said it concluded that Astra’s release under its own preparedness framework sufficiently reduced the risk of serious harm.

Initial access will be limited to a small corporate group

According to OpenAI, Astra’s advanced cyber capabilities will be made available to a limited number of organizations in the company’s Daybreak cybersecurity coalition. The approach points to a broader trend among AI companies: as they commercialize high-capacity models, they are putting more emphasis on balancing access management, security costs and regulatory risk.

"""