OpenAI said on Sept. 1, 2026, that its upcoming Astra model reached the Critical cybersecurity capability threshold under the company’s Preparedness Framework. Astra is the first OpenAI model assigned that designation, according to a post on X and a blog published the same day.

The framework’s Critical bar applies when a model can independently identify zero-day flaws and produce functional exploits spanning all severity levels across many hardened, real-world critical systems. Alternatively, a model qualifies if it can take only a high-level goal and devise and execute a new, complete cyberattack strategy against a hardened target without human intervention.

OpenAI said Astra can uncover previously unknown vulnerabilities and turn them into exploits against many well-protected systems without a person directing each action, provided it has the required tools and access.

The company combined automated public and private benchmarks with assessments led by experts. Astra scored 100% on ExploitBench, a test of exploit development from known vulnerabilities. Because of contamination concerns, OpenAI also created an internal test using 20 more recently disclosed, high-severity V8 vulnerabilities.

On the internal test, Astra achieved higher arbitrary code-execution rates than GPT-5.6 Sol while producing fewer output tokens, OpenAI said. It also found and used two zero-day vulnerabilities in an exploit chain. The company is disclosing both vulnerabilities to their maintainers.

Those results came from Astra with Daybreak Blue access, rather than its default production configuration. In expert-led tests, Astra created a browser compromise that escaped its sandbox and ran commands on the host after the browser opened an HTML file. It also found several vulnerabilities in a hardened operating system and linked them into a local privilege-escalation path from an unprivileged user to root.

OpenAI said it delayed parts of Astra’s development and release while it strengthened and tested controls against cyber misuse and unauthorized model actions. The company now believes the safeguards meet its framework’s standard for limiting the risk of severe harm before release.

Astra refused 91.5% of requests in OpenAI’s cyber jailbreak evaluations, compared with 59% for GPT-5.6 Sol. In a honeypot test without production cyber safeguards, GPT-5.6 Sol tried to access surrounding targets in 56% of cases, while Astra made no such attempts.

OpenAI began as a nonprofit AI research company in December 2015. Under a structure announced in October 2025, the nonprofit OpenAI Foundation controls OpenAI Group PBC. Go Big News reported on Aug. 19, 2026 that the company was testing abuse monitoring that keeps no customer data.

OpenAI plans to release Astra soon. Advanced cybersecurity access will begin with testers and later expand through Daybreak Blue for defensive work. Safety checks may slow, pause or stop legitimate activity; ChatGPT and Codex users may be asked to review a paused task, while API tasks will stop. OpenAI plans to publish more testing details in Astra’s system card at launch.