OpenAI says it cannot rule out ‘Critical’ cyber capabilities in unreleased Astra model OpenAI said on August 7, 2026, that preliminary evaluations of its unreleased Astra model showed advances in agentic coding and cybersecurity significant enough that the company could not rule out the model meeting its highest cybersecurity capability threshold. The company is slowing development work that does not meet stricter security requirements and is preparing additional testing with government agencies and external safety organizations. The disclosure triggers additional controls under OpenAI's Preparedness Framework, which requires heightened safeguards during development when a model reaches or is forecast to reach a Critical capability threshold. OpenAI said on August 7, 2026, that preliminary evaluations of its unreleased Astra model showed advances in agentic coding and cybersecurity significant enough that the company could not rule out the model meeting its highest cybersecurity capability threshold. The company is slowing development work that does not meet stricter security requirements and says it is preparing additional testing with government agencies and external safety organizations. The disclosure is more consequential than prior model-risk notices because OpenAI’s Preparedness Framework requires additional controls during development—not only before deployment—when a model reaches or is forecast to reach a Critical capability threshold. OpenAI has not publicly released Astra’s scores, formal Safety Advisory Group determination or external evaluation results.