AI Models, Software & Research
OpenAI’s Astra assessment could not exclude “critical” cyber capability; activities lacking strengthened controls were paused before release.
· ComputeLabs Research · from the August 7, 2026 edition
OpenAI said its Preparedness Framework assessment could not rule out that the unreleased Astra model has reached “critical” cybersecurity capability. Under OpenAI’s stated definition, that level could include autonomously finding and developing effective zero-day vulnerabilities against multiple hardened real-world critical systems, or planning and executing novel end-to-end attacks against highly protected targets from high-level objectives.
The assessment triggered strengthened controls before Astra’s release. OpenAI paused Astra-related internal activities that did not meet those controls and cited isolated testing environments, restrictions on network and tool access, stronger model-weight protection and encryption, and additional monitoring and detection.
OpenAI said Astra was not involved in the previously referenced Hugging Face security incident. It also said it would work with relevant government agencies and selected AI-safety organizations on testing, provide recommended controls to third-party testing partners, and comprehensively monitor high-risk behavior and misalignment across Astra’s agentic applications.
Additional reporting
- OpenAI’s Astra assessment

