# OpenAI pauses some Astra work as it assesses critical cyber capabilities

> Source: <https://runtimewire.com/article/openai-pauses-astra-work-critical-cyber-capability>
> Published: 2026-08-10 11:23:09+00:00

[OpenAI](https://openai.com/?ref=runtimewire), led by co-founder and CEO [Sam Altman (@sama)](https://x.com/sama?ref=runtimewire), paused some internal activities involving Astra after preliminary evaluations left the AI developer unable to rule out a Critical cyber capability level under its safety framework.

OpenAI [disclosed the decision on August 7](https://openai.com/index/responding-next-frontier-critical-cyber-capabilities/?ref=runtimewire). Astra, an unreleased model, showed strong enough performance in preliminary evaluations that OpenAI could not rule out the Critical threshold. [CNBC reported on August 10](https://www.cnbc.com/2026/08/10/openai-astra-cybersecurity-risks.html?ref=runtimewire) that OpenAI halted some internal activities while continuing to test the model.

OpenAI said it moved Astra testing into isolated environments and implemented universal monitoring for risky actions and misalignment across the model's agentic applications, including training and evaluation. OpenAI is also adding monitoring and detection capabilities for higher-capability models.

The disclosure leaves Astra in an unusual operational state: development has slowed, some work has stopped, and OpenAI is applying controls associated with a capability level that remains unresolved. OpenAI has not said which internal activities it paused or how long the restrictions will remain.

### What a Critical assessment would mean

OpenAI's [Preparedness Framework](https://cdn.openai.com/pdf/18a02b5d-6b67-4cec-ab64-68cdfbddebcd/preparedness-framework-v2.pdf?ref=runtimewire) describes Critical cyber capability as the ability to conduct cyberattacks against sophisticated defenses autonomously, without a user supplying detailed instructions.

That description defines the threshold OpenAI is evaluating. It is not a finding that Astra has demonstrated each capability or carried out an attack. OpenAI's position is narrower: Astra's preliminary results were strong enough that the company cannot rule out the Critical level while benchmarking continues.

OpenAI said it was applying stricter security controls while that benchmarking continued. The company has not disclosed whether Astra will ultimately meet the Critical threshold.

The distinction matters for deployment. A model capable of finding vulnerabilities and executing long-horizon technical work could help security teams identify and patch serious flaws. Broad access to the same capabilities could reduce the expertise and supervision needed to attack hardened targets. OpenAI has not disclosed Astra's architecture, intended product form, customers, pricing, release date or eventual access policy.

[Axios reported on August 7](https://www.axios.com/2026/08/07/openai-astra-model-delay-cybersecurity-risks?ref=runtimewire) that OpenAI would expand safety testing, slow Astra's development and put safeguards in place before any release. The timing of a release was already unclear, and Axios said the restrictions could delay it.

### OpenAI's controls leave deployment choices open

Isolated testing and universal monitoring give OpenAI ways to observe Astra while limiting where it can act. The public disclosure does not explain the boundaries of those environments, who can authorize exceptions, or whether external evaluators will independently test the model's cyber capabilities.

OpenAI also has not said whether Astra could eventually be offered broadly, limited to vetted organizations or retained for internal research. Anthropic, another frontier AI developer, provides one comparison through [Claude Mythos 5](https://www.anthropic.com/claude/mythos?ref=runtimewire), its restricted-access cyber research model.

Anthropic says partners in its [Project Glasswing program](https://www.anthropic.com/news/expanding-project-glasswing?ref=runtimewire) found more than 10,000 high- or critical-severity vulnerabilities. The figure is Anthropic's own account, but the program shows how a developer can give selected security organizations access to advanced cyber capabilities without offering the model broadly. OpenAI has not indicated whether Astra will use a similar structure.

The Astra assessment is separate from the third-party evaluation incidents involving other models and testing environments. OpenAI told Axios that Astra was not involved in the earlier Hugging Face incident.

Altman has spent a decade arguing that increasingly capable AI can be distributed for broad benefit, a position reflected in [OpenAI's founding announcement](https://openai.com/index/introducing-openai/?ref=runtimewire). Astra creates a concrete test of that position: whether OpenAI can retain effective control of an unreleased model while determining what it can do and who, if anyone, should be allowed to use it.
