OpenAI flags possible critical cybersecurity risk in upcoming model Astra, tightens controls and slows development; 'cannot rule out Critical capability level'
Sam AltmanOpenAIHugging Face

OpenAI flags possible critical cybersecurity risk in upcoming model Astra, tightens controls and slows development; 'cannot rule out Critical capability level'

OpenAI has paused development of its upcoming AI model, Astra, after preliminary evaluations suggested it may possess 'critical' cybersecurity capabilities, which could allow it to autonomously execute complex cyberattacks. The company is tightening security controls and collaborating with government agencies to assess the model's risks.

The Indian Express The Indian Express+1 source8 August 2026 · 06:57 UTC
CuriousCats Full Story

OpenAI has flagged potential critical cybersecurity risks associated with its upcoming AI model, Astra, leading to a pause in development and enhanced security measures.123589

The company announced that preliminary evaluations indicated Astra might autonomously identify and exploit severe software vulnerabilities, known as zero-day exploits, and execute complex cyberattacks against highly secure targets without human intervention.

“While we continue to benchmark and assess this model, our preliminary evaluations indicate strong enough performance that we cannot rule out ‘critical’ capability level at this time,” OpenAI stated.

In response to these findings, OpenAI has implemented stricter security controls and moved Astra's development into isolated testing environments with restricted network access.4

CEO Sam Altman emphasized the importance of making powerful models available, stating, “we do not think it is a good strategy to keep powerful models to a chosen few.”

OpenAI clarified that Astra was not involved in a recent hack targeting the AI platform Hugging Face and is partnering with government agencies and select AI safety organizations to rigorously test the model's capabilities.

This disclosure marks a significant moment in the AI sector, where companies often hesitate to announce product delays due to safety and cybersecurity concerns. OpenAI's transparency reflects its commitment to public safety and security amidst growing scrutiny over AI technologies.

“It’s important to be transparent with the public and the safety and security communities about this potential shift in capabilities,” the company added.11

Key Insight
“The model reached the 'critical' threshold under OpenAI's Preparedness Framework, meaning it could autonomously exploit zero-day vulnerabilities. OpenAI has moved Astra to isolated testing environments and will partner with government agencies and select AI safety organizations to test its capabilities.”
CuriousCats studied:
1
The Indian ExpressThe Indian Express
“OpenAI said on Friday it cannot rule out that its upcoming AI model, Astra, has “critical” cybersecurity capabilities, prompting the startup to pause some internal development and trigger safety protocols.”
The Indian Express →
2
TechCrunchTechCrunch
“OpenAI said Friday it has suspended work on some aspects of its upcoming model Astra after an internal review found it had made significant advancements in agentic coding and cybersecurity — enough to warrant concern over its capabilities.”
TechCrunch →
Ask CuriousCats
What is OpenAI's model Astra?
Why has Astra's development been slowed?
How does the Preparedness Framework work?
Are there similar risks with other AI models?
How does Astra's risk compare to past models?
Get your CIA-level briefing,
in real time.
CuriousCats monitors the internet every minute for you and brings you the most personalized brief of videos, social media posts, news and more.
Download the App
Liked the depth here?
Get the full internet briefed for you any time of the day.
Get CuriousCats