OpenAI slows new model 'Astra' – first-ever 'critical' cyber capabilities
OpenAI has slowed development of its frontier model Astra because it could reach the highest risk tier for offensive cybersecurity. It is the first time the company's internal safety framework has crossed that threshold.

Illustration · AI-generated (AI IN LIFE)
At a glance
- Reported: 7–8 August 2026 (Axios, TechCrunch, Bloomberg)
- Model: frontier model 'Astra'
- Trigger: first-ever 'critical' tier in the Preparedness Framework (cyber)
- Action: slowed release, additional safeguards
OpenAI has slowed part of the work on its next major model, codenamed Astra. The reason: the model could, for the first time, reach the highest risk tier of the company's own 'Preparedness Framework' – in cybersecurity, specifically offensive hacking and exploit capabilities.
According to reports by Axios, TechCrunch and Bloomberg on 7 August 2026, OpenAI classified Astra as potentially 'critical' and said it could not rule out that the model develops dangerous capabilities such as finding and exploiting zero-day vulnerabilities. The previous flagship of the GPT-5 series remained one level lower at 'High'.
What is remarkable is less the single model than the precedent: for the first time, OpenAI's own safety grid triggers the top warning level. The company is responding by slowing the release and adding extra safeguards before the model becomes more widely available.
The case illustrates the core dilemma of the frontier labs: the very capabilities that make a model a brilliant coding assistant can also make it a dangerous tool for attackers. The line between 'helps secure software' and 'helps attack software' is blurry.
For companies, the message is twofold: AI assistants in software development keep getting stronger – while AI-assisted cyber defense moves from optional to essential. Anyone building systems today should assume that attackers will soon have tools at this level too.
FAQ
Is Astra available yet?
No. OpenAI deliberately slowed development and broader release until additional safety measures are in place.
What does 'critical cyber capability' mean?
The highest risk tier in OpenAI's internal safety grid – for example the ability to autonomously find and exploit software vulnerabilities.
Why is it a precedent?
It is the first time OpenAI's Preparedness Framework has triggered its top warning level.


