AI · Wednesday, September 2, 2026
OpenAI says Astra is its first model at “Critical” cybersecurity under its Preparedness Framework
The File desk · Sep 2, 2026, 2:14 PM UTC
Status
Confirmed as OpenAI’s company self-report. No independent evaluator was fetched. Live openai.com returned HTTP 403 (Cloudflare challenge); the text was read from an Internet Archive capture of the same URL (snapshot 20260901223610).
- Confirmed
OpenAI’s Sept. 1, 2026, post “Path to Astra” states that the company now believes Astra meets the Critical cybersecurity capability threshold under its Preparedness Framework, that it is the first model OpenAI is designating at that level, and that stronger safeguards were required during development and before release.
- Unverified
Whether NIST, CAISI, METR, or another independent evaluator has replicated that designation is not known from the materials fetched. OpenAI’s technical claims about previously unknown flaws are the company’s; they are not treated here as independently verified.
On Sept. 1, 2026, OpenAI published “Path to Astra,” stating upcoming model Astra meets the company’s Critical cybersecurity capability threshold — the first model it has designated at that level — and that it delayed parts of development while tightening safeguards. It plans to release Astra “soon,” with the most advanced cyber capabilities limited at first (testers, then Daybreak Blue). Technical claims about previously unknown flaws are OpenAI’s; they are not treated here as independently verified. Live openai.com returned HTTP 403 to this desk; the text is from an Internet Archive capture of that URL.
OpenAI wrote: “We now believe Astra meets the Critical cybersecurity capability threshold under our Preparedness Framework, meaning that with the right tools and access, it can find previously unknown security flaws and develop ways to exploit them across many well-protected systems without a person guiding each step. It is the first model we are designating at this level, and requires stronger safeguards during development and before release.”
The same Sept. 1, 2026, post says the company delayed parts of Astra’s development and release while it strengthened and tested protections, and that it believes those safeguards sufficiently minimize the risk of severe harm for release under its Preparedness Framework. OpenAI said it plans to make Astra available soon, with access to its most advanced cybersecurity capabilities more limited at first: advanced cybersecurity work initially to a group of testers, with access through Daybreak Blue following.
OpenAI said it will share more details about safety, security, and alignment testing in the model’s system card at launch. That system card was not posted in the materials fetched. This file does not restate OpenAI’s evaluation anecdotes beyond the company’s own Critical-threshold wording quoted above.
What is still unknown or disputed
- Public release date is not stated beyond “soon.”
- Whether NIST, CAISI, or METR has replicated the Critical designation is not known from the materials fetched.
- The system card is not yet posted; OpenAI said it would share that at launch.
- The live page at openai.com/index/path-to-astra/ returned HTTP 403 (Cloudflare) to this desk on Sept. 2, 2026. Text was read from Internet Archive snapshot 20260901223610 of that URL.
Primary sources
Every claim in this story is drawn from the documents below. If a fetch failed, that is recorded on the card.
Source 1 · fetch incomplete
Path to Astra: critical capabilities and frontier safeguards
OpenAI · September 1, 2026
We now believe Astra meets the Critical cybersecurity capability threshold under our Preparedness Framework, meaning that with the right tools and access, it can find previously unknown security flaws and develop ways to exploit them across many well-protected systems without a person guiding each step. It is the first model we are designating at this level, and requires stronger safeguards during development and before release. We plan to make Astra available soon, but access to its most advanced cybersecurity capabilities will be more limited. Advanced cybersecurity work will initially be available to a group of testers, with access through Daybreak Blue following to expand defensive use.
https://openai.com/index/path-to-astra/
Source 2
Path to Astra (Internet Archive capture of openai.com/index/path-to-astra/)
Internet Archive / OpenAI · September 1, 2026
Since our earlier assessment that Astra might reach a critical level of cybersecurity capability, we have gathered more evidence and run additional evaluations to assess the model’s capabilities. We now believe Astra meets the Critical cybersecurity capability threshold under our Preparedness Framework. Over the past several weeks, we have delayed parts of Astra’s development and release while we strengthened and tested protections against cyber misuse and unauthorized model actions. We plan to make Astra available soon, but access to its most advanced cybersecurity capabilities will be more limited. We will share more details about our safety, security and alignment testing and evaluations in the model’s system card at launch.
https://web.archive.org/web/20260901223610/https://openai.com/index/path-to-astra/