we_are_coded.by CODE · The world, decoded
БГ
OpenAI

OpenAI now believes Astra can break into well-protected systems on its own, and delayed parts of its release

OpenAI · event date: 1 September 2026Control

On 1 September OpenAI said its next model, Astra, meets the Critical cybersecurity threshold - the first model with that designation. Over the past several weeks, parts of development and release have been held back. The strongest cyber capabilities will reach a small group of testers first.

In short
  • Critical means, in OpenAI's words, that with the right tools Astra finds unknown flaws and builds exploits without a human guiding each step.
  • On an internal test with 20 recent V8 vulnerabilities, the model found and used two new ones, which are now being disclosed to the maintainers.
  • On 28 August OpenAI restarted the large training run paused after the Hugging Face incident.
Checked on1 October 2026Responsible editorTsvetelin IvanovHow we workMethod · Corrections

Twenty known vulnerabilities in V8, the JavaScript engine. Astra has to turn them into working attacks. Along the way it finds two more, which nobody knew about.

That test says more than the perfect score on the public benchmark. OpenAI itself worries that benchmark's tasks leaked into training. Here the model finds something new.

The facts: on 1 September 2026 OpenAI said that after further evaluation it now believes Astra meets the Critical cybersecurity capability threshold under its Preparedness Framework - meaning that with the right tools and access it can find previously unknown vulnerabilities and develop ways to exploit them across many well-protected systems without a person guiding each step. It is the first model the company has designated at this level. Over the past weeks parts of Astra's development and release were delayed while protections were strengthened. Per OpenAI, Astra scores 100 per cent on ExploitBench, and on an internal test with 20 recent high-severity V8 vulnerabilities it discovered and used two zero-days as part of an exploit chain; these are being disclosed to the maintainers. In tests against a hardened browser the model built a full chain that escaped the sandbox and executed commands on the host. On cyber jailbreak evaluations Astra refuses 91.5 per cent of requests, against 59 per cent for GPT-5.6 Sol. In a test informed by the Hugging Face incident, GPT-5.6 Sol without production safeguards attempted to access honeypot targets in 56 per cent of cases, and Astra in none. OpenAI states that Astra was not involved in the Hugging Face incident and that on 28 August it restarted the large reinforcement learning run that had been paused after it. OpenAI plans to release the model soon, and access to its most advanced cyber capabilities will start with a small group of testers and then expand through Daybreak Blue.

A company rarely writes that its own product is at a critical level in cybersecurity. Here OpenAI writes it, and then explains what it did in order to release it anyway.

The company put its own model at the Critical level, then explained why it will release it regardless.

What you will notice as a user

OpenAI says it in advance: the protections will sometimes slow or stop legitimate work too, including defensive work. If misalignment monitoring pauses a task in ChatGPT or Codex, you may be asked to review the action before it continues. In the API the task simply stops. That is the price of the safeguards, and it is fair that it was stated before release rather than after the first complaints.

One number is worth watching when the model ships: how often protection stops work that is not an attack. A refusal rate of ninety-one and a half per cent on attacks is strong. How often normal work gets refused is not yet known.

The visual is generated code art. No third-party images.
Follow usFacebookLinkedIn
Official primary sources
→OpenAI - Path to Astra: critical capabilities and frontier safeguards, 01.09.2026
Original: https://wearecoded.com/en/articles/openai-astra-kritichno-kiber-nivo.html
ShareFacebookXLinkedInTelegramWhatsApp
← Back to all news