ModelsPolicy OpenAI

OpenAI pauses internal Astra activity over possible critical cyber capability

Illustration for the OpenAI Astra safety pause story

OpenAI says it cannot rule out that its next model hits the highest cyber risk tier the company has ever defined, and it has paused internal activity on that basis.

What OpenAI published

On August 7, 2026, OpenAI disclosed that internal evaluations of Astra, an upcoming model, showed significant advances in agentic coding and cybersecurity. Expert assessment led the company to conclude it cannot rule out critical cyber capabilities under its Preparedness Framework.

The definition matters. A model hits the Critical cybersecurity threshold if it can identify and develop functional zero-day exploits of all severity levels in many hardened real-world critical systems without human intervention, or devise and execute end-to-end novel attack strategies against hardened targets given only a high-level goal.

No model has been placed there before. Previous ones, including GPT-5.6-Sol, were assessed at High.

The controls now in place

OpenAI’s response runs on several tracks. Internal activity involving Astra that does not meet strengthened security controls is paused. The model runs in isolated testing environments with restricted network and tool access, encrypted weights and sandboxed execution. Its chain of thought is under universal monitoring, backed by a security response that can interrupt high-risk activity. Government agencies and outside safety organizations have been brought in to test it.

The company also notes that Astra was not involved in the Hugging Face incident.

Reading the hedge correctly

Precision helps here. OpenAI is not saying Astra is Critical. It is saying it can no longer prove the model is not, and it hit the brakes on that basis. That is a different kind of statement than a capability announcement, and arguably a more consequential one: the burden of proof has flipped from showing danger to showing safety.

A frontier lab slowing itself down before shipping is rare enough to notice. Whether the pause reads as caution or as a preview of what Astra can do, the framework OpenAI wrote for itself is now doing exactly what it was designed to do, and the next question is how long a model stays paused when the evidence stays ambiguous.

Sources

ANOTHER News is published by ANOTHER, an AI-native content agency. Daily coverage also runs on Instagram.