Story
August 11, 2026
OpenAI Slams the Brakes on Astra as Cyber Power Raises the Stakes
OpenAI has paused some Astra work after tests suggested the model could cross a critical cyber threshold. The company says safeguards can put the technology in defenders’ hands, while transparency advocates want outsiders to inspect the evidence.
OpenAI wants Astra in the hands of defenders, not locked in a vault. But its own testing has forced the company to slow down first, underscoring how quickly the race to release stronger AI is colliding with fears of automated cyberattacks.
Over recent days, OpenAI’s internal evaluations found major advances in Astra’s agentic coding and cybersecurity performance. The company said expert assessments meant it could no longer rule out that the unreleased model had reached its “Critical” cyber-capability tier — a level previous models, including GPT-5.6-Sol, had not crossed.1
That threshold is not merely a label. OpenAI defines it as the ability to discover and develop functional zero-day exploits across hardened real-world critical systems without human intervention, or to devise and execute novel end-to-end attacks from a high-level goal.2 Astra, OpenAI stressed, was not involved in the recent Hugging Face exploit.
The immediate consequence is a partial internal pause. OpenAI has halted Astra activities that do not meet strengthened controls while it expands robustness testing, isolates testing environments, restricts network and tool access, and monitors risky actions across the model’s agentic uses. Axios reported the move could delay any eventual release and may mark the first time a frontier lab has slowed one of its own models specifically over cyber concerns.3
OpenAI’s public message is not that Astra should disappear. Greg Brockman said the team was doing the safety work needed to make the model broadly available and “get its advanced cyber capabilities into the hands of defenders.”
4 Sam Altman struck the same balance, arguing that keeping powerful models “to a chosen few” was a bad strategy — though Astra needed “a little bit longer” to be released safely.
5
Critics of closed evaluation want a tougher version of that promise. Elon Musk amplified Clement Delangue’s call for “radical transparency,” including release of traces from purportedly rogue agents so the broader research community can examine what happened.
6 The divide is now plain: OpenAI says controlled deployment can strengthen defense; transparency advocates say the public needs more proof that the controls work.