OpenAI says it can no longer rule out that Astra, an upcoming model, has reached the Critical cybersecurity capability threshold in its Preparedness Framework. Preliminary internal evaluations conducted over the past few days found major gains in agentic coding and cybersecurity, prompting the company to tighten controls while benchmarking continues.
After evaluating one of our upcoming models, Astra, we're treating it as our first "critical" model for cybersecurity under our Preparedness Framework.
— OpenAI (@OpenAI) August 7, 2026
This is a scenario we've planned for, and we're putting additional controls in place to ensure Astra's further development…
The finding is not a final Critical classification. Under OpenAI’s framework, that level covers models capable of discovering and building working zero-day exploits across many hardened, real-world critical systems without human help, or of devising and executing novel end-to-end attacks against hardened targets from only a high-level goal. OpenAI says Astra’s current performance is strong enough that this level cannot yet be excluded. The company also states that Astra was not involved in exploiting Hugging Face.
astra is a powerful model and we are working to make it generally available.
— Sam Altman (@sama) August 7, 2026
we do not think it is a good strategy to keep powerful models to a chosen few.
given its cyber capabilities, we need a little big longer to do do this safely. but hopefully not too long!
Astra remains unreleased, with no availability timeline disclosed. OpenAI has paused internal work involving the model when it does not meet the new control requirements. Development and testing will use isolated environments, restricted network and tool access, stronger model-weight protection and encryption, additional monitoring and detection, and sandboxed execution.
The company has also introduced universal monitoring for risky actions and misalignment across Astra’s agentic uses, including training and evaluation. These monitors assess the model’s chain of thought and can trigger a security response to review and interrupt high-risk activity. OpenAI plans to work with government agencies and selected AI safety organizations on capability testing, while giving third-party testing partners recommended controls for higher-risk evaluations and workloads.
OpenAI launched its Preparedness Framework in 2023 to track frontier risks in biological, chemical, cybersecurity, and AI self-improvement capabilities and guide its response as models advance. Earlier systems, including GPT-5.6-Sol, were assessed at the High cyber threshold, placing Astra’s possible Critical capability beyond the company’s previous cyber assessments.
The company frames the shift as both an urgent security problem and a defensive opportunity. Its stated aim is for cyber-capable models to help defenders find and fix vulnerabilities before attackers can exploit them, with deployment shaped in collaboration with governments, safety institutes, and civil society.