{"slug": "openai-astra-arrives-soon-and-the-company-is-already-promoting-its-critical", "title": "OpenAI Astra arrives soon, and the company is already promoting its critical risks", "summary": "OpenAI confirmed on Tuesday that its unreleased Astra model has reached a 'critical' cyber capability threshold, the first time any of its models has been evaluated at that level, while announcing the model will be 'available soon' with its most advanced cybersecurity skills reserved for select testing partners. OpenAI CEO Sam Altman acknowledged the tension between the model's capabilities and safety, stating the company is 'pacing our progress' to meet safety standards. Tal Kollender, CEO of AI cybersecurity firm Remedio, said the limitation is a fair mitigation and that OpenAI is not being reckless.", "body_md": "# OpenAI Astra arrives soon, and the company is already promoting its 'critical' risks\n\n[Timothy Beck Werth](/author/timothy-beck-werth)\n\n[Read Full Bio](/author/timothy-beck-werth)\n\n[OpenAI](https://mashable.com/category/openai) confirmed on Tuesday that its [unreleased Astra model](https://mashable.com/tech/openai-astra-model-release-date-everything-we-know) has reached a dangerous new milestone, while simultaneously confirming that it was forging ahead with a public launch.\n\nIn a [blog post](https://openai.com/index/path-to-astra/), OpenAI said that Astra has reached a \"critical\" cyber capability threshold, meaning the model could pose existential risks to cybersecurity. OpenAI's [Preparedness Framework](https://cdn.openai.com/pdf/18a02b5d-6b67-4cec-ab64-68cdfbddebcd/preparedness-framework-v2.pdf) tracks risk levels in three categories: biological/chemical, cybersecurity, and AI self-improvement.\n\nOpenAI said that this is the first time any* *of its models has been evaluated at the critical level in the cyber domain.\n\n**You May Also Like**\n\nThe same blog post also stated that Astra will be \"available soon,\" but that its most advanced cybersecurity skills will be reserved for select testing partners, in the interest of public safety. The AI company said it was still preparing to safely release Astra and would be transparent about the potential threat level.\n\nOn X, Sam Altman addressed the tension between declaring Astra uniquely dangerous while also pushing ahead with a public launch. Altman said that \"Astra has been done training for a while now\" but that OpenAI has been \"slowing things as needed to ensure that we can do sufficient work on safety and alignment.\"\n\n[This Tweet is currently unavailable. It might be loading or has been removed.]\n\n\"There is an obvious tension here: on one hand, Astra is very good and we are excited to see what people will build with it,\" Altman wrote. \"On the other hand, we are clearly in a phase of development where we believe caution is warranted, and we are pacing our progress to ensure that we can meet the safety standards required by new capability levels.\"\n\nOf course, this isn't the first time an AI company has hyped up one of its models as dangerously powerful ahead of a big launch.\n\n\"Limiting access to the most advanced cybersecurity features to select partners is a fair mitigation, and I don't think OpenAI is being reckless here,\" said Tal Kollender, Founder and CEO of [AI cybersecurity firm Remedio](https://remedio.io/). \"Their framework is built to allow release with the right safeguards, but the security story is that defense hasn't caught up to any version of this, gated or public.\"\n\n[Terms of Use](https://www.ziffdavis.com/terms-of-use)and\n\n[Privacy Policy](https://www.ziffdavis.com/ztg-privacy-policy).\n\n## What makes Astra potentially dangerous?\n\nOpenAI previously rated [GPT-5.6-Sol](https://mashable.com/tech/openai-gpt-56-sol-terra-luna) as a \"high\" risk in the cyber domain, but Astra is even more capable. OpenAI says it scored 100 percent on the ExploitBench benchmarking test.\n\n\"Under our Preparedness Framework, a model reaches the Critical cybersecurity threshold if it can identify and develop functional zero-day exploits of all severity levels in many hardened real-world critical systems without human intervention, or can devise and execute end-to-end novel strategies for cyberattacks against hardened targets given only a high level desired goal,\" an Aug. 7 [OpenAI blog post stated](https://openai.com/index/responding-next-frontier-critical-cyber-capabilities/).\n\nIn recent months, advanced frontier models from Anthropic and OpenAI have developed rapidly at agentic coding and cybersecurity hacking. As a result, the prospect of AI agent swarms hacking critical infrastructure no longer seems far-fetched, especially after the [Hugging Face hack](https://mashable.com/tech/hugging-face-openai-rogue-agent-hack-explained). In that incident, swarms of AI agents developed by OpenAI escaped a secure testing environment and hacked Hugging Face, acting autonomously in order to pass a test. Meanwhile, thanks to a deluge of AI-discovered bugs, some [zero-day bug bounty programs ](https://mashable.com/article/ai-discovered-zero-day-bug-reports-crisis)have been forced to shut down entirely.\n\n\"While Astra was not involved in the [ Hugging Face incident](https://openai.com/index/hugging-face-incident-and-the-road-ahead/), we have incorporated our\n\n[from that incident into our safety approach,\" OpenAI's blog post states. \"Based on retrospective testing, we believe our production safeguards at the time would have prevented the Hugging Face incident. We have since implemented even stronger safeguards for Astra, including training the model to more reliably refuse harmful cyber requests and respect safety restrictions, additional protections against misuse, and monitoring that can stop potentially unauthorized activity.\"](https://cdn.openai.com/pdf/67869394-cb91-4c12-888c-5cbd85c7814c/OpenAI-Hugging-Face%20Incident-Technical-Report.pdf)\n\n__learnings__In its blog post, OpenAI also detailed some of the other safety precautions developed around Astra, with two goals in mind: preventing bad actors from accessing the model and stopping Astra from taking unwanted actions on its own. The company said it's tightened its secure sandboxes and stepped up \"offline detection and threat disruption\" efforts.\n\n\"Nation-states and well-funded attackers aren't waiting on Sam Altman's release calendar,\" Kollender told Mashable. \"If a frontier lab's internal model can find and chain zero-days without a human in the loop, assume adversaries are within a generation of the same capability, gatekept or not.\"\n\nOn the same day OpenAI made these announcements, [Anthropic announced the launch of Fable 5.1](https://mashable.com/tech/anthropic-fable-5-1-launch-announcment), an update to its latest frontier-level model. Fable is based on Claude Mythos, the model Anthropic [deemed too dangerous to release](https://mashable.com/article/claude-mythos-preview-project-glasswing-pr-stunt-cybersecurity-experts) because of its cybersecurity coding abilities.\n\nIf the pace of AI development is starting to remind you of *War Games*, keep one other fact in mind: While advanced frontier models do pose escalating cybersecurity risks, the same models will also benefit cybersecurity defenders in the long run.\n\n**UPDATE: Sep. 2, 2026, 1:26 p.m. EDT **This article has been updated with comments from Sam Altman shared to X and quotes from a cybersecurity expert.\n\n**UPDATE: Sep. 2, 2026, 9:29 a.m. EDT **A previous version of this article stated that Astra was the first OpenAI model to be evaluated as a \"critical\" threat in any of the three categories in the company's Preparedness Framework (chemical/biological, cyber, self-improvement). The company has only said that Astra is the first model to reach the \"critical\" threshold in the cyber domain.\n\n*Disclosure: Ziff Davis, Mashable’s parent company, in April 2025 filed a lawsuit against OpenAI, alleging it infringed Ziff Davis copyrights in training and operating its AI systems.*\n\nTimothy Beck Werth is the Tech Editor at Mashable, where he leads coverage and assignments for the Tech and Shopping verticals. Tim has over 15 years of experience as a journalist and editor, and he has particular experience covering and testing consumer technology, smart home gadgets, and men’s grooming and style products. Previously, he was the Managing Editor and then Site Director of SPY.com, a men's product review and lifestyle website. As a writer for GQ, he covered everything from bull-riding competitions to the best Legos for adults, and he’s also contributed to publications such as The Daily Beast, Gear Patrol, and The Awl.\n\nTim studied print journalism at the University of Southern California. He currently splits his time between Brooklyn, NY and Charleston, SC. He's currently working on his second novel, a science-fiction book.", "url": "https://wpnews.pro/news/openai-astra-arrives-soon-and-the-company-is-already-promoting-its-critical", "canonical_source": "https://mashable.com/tech/openai-astra-critical-cyber-capabilities", "published_at": "2026-09-02 17:54:35+00:00", "updated_at": "2026-09-02 18:22:18.908096+00:00", "lang": "en", "topics": ["artificial-intelligence", "ai-safety", "ai-policy", "ai-products"], "entities": ["OpenAI", "Astra", "Sam Altman", "Tal Kollender", "Remedio", "GPT-5.6-Sol", "Hugging Face", "Anthropic"], "alternates": {"html": "https://wpnews.pro/news/openai-astra-arrives-soon-and-the-company-is-already-promoting-its-critical", "markdown": "https://wpnews.pro/news/openai-astra-arrives-soon-and-the-company-is-already-promoting-its-critical.md", "text": "https://wpnews.pro/news/openai-astra-arrives-soon-and-the-company-is-already-promoting-its-critical.txt", "jsonld": "https://wpnews.pro/news/openai-astra-arrives-soon-and-the-company-is-already-promoting-its-critical.jsonld"}}