OpenAI makes bold Astra claim, says AI model has crossed critical cybersecurity capability | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


OpenAI says its upcoming AI model Astra has crossed a major cybersecurity milestone. The company revealed that its newest model, which is still under development, is the first OpenAI model to reach the “Critical” cybersecurity threshold under its Preparedness Framework. In simple terms, the ChatGPT maker is claiming that Astra is now capable of carrying out some highly advanced hacking tasks with limited human help.

According to OpenAI, Astra can look for weaknesses in computer software, including flaws that were previously unknown, and then work out how those weaknesses could be used to break into a system. The model can also connect multiple vulnerabilities together, allowing it to move deeper into a computer system after gaining an initial foothold.
“With the right tools and access, it can find previously unknown security flaws and develop ways to exploit them across many well-protected systems without a person guiding each step,”OpenAI wrote in the official blog post.

OpenAI says Astra reached this level after a series of fresh evaluations and expert-led tests. Under the company’s framework, a model reaches the Critical threshold if it can independently find and develop working “zero-day” exploits in many well-protected real-world systems, or create and execute an end-to-end cyberattack strategy from a high-level goal.

In one test, Astra scored 100 per cent on ExploitBench, a benchmark that tests a model’s ability to develop exploits from known vulnerabilities. OpenAI also tested it on an internal benchmark containing 20 recently disclosed, high-severity V8 vulnerabilities. “Astra achieved a much higher arbitrary code execution rate than GPT-5.6 Sol, while using fewer output tokens, and discovered and exploited two zero-day vulnerabilities as part of an exploit chain,” the company said.

Meanwhile, in expert testing, OpenAI claims Astra found previously unknown flaws in a protected browser and operating system, using them to bypass security and gain deeper access.

But what about the concerns? A model that can find and exploit vulnerabilities on its own could be extremely useful to security researchers looking for weaknesses before criminals find them. But the same capabilities could also be misused to attack real systems.

OpenAI says it is aware of that risk and has been adding stronger safeguards before Astra is released. The company also paused parts of Astra’s development while it worked on these safety and security measures, resuming them after the new controls were in place.

The company says that the Astra is already following these restrictions. In cyber jailbreak tests, it reveals that the model refused 91.5 per cent of requests, compared with 59 per cent for GPT-5.6 Sol. In another test inspired by the Hugging Face incident, Astra did not attempt to target surrounding security infrastructure.

When is Astra launching?

Astra has not been released yet. OpenAI says the model will be available soon, but it has not announced a specific launch date.

But when it does arrive, OpenAI says its most advanced cybersecurity capabilities will not immediately be available to everyone. Access will initially be limited to a small group of alpha testers, before expanding through OpenAI’s Daybreak programme for defensive cybersecurity use.

OpenAI plans to share more details about Astra’s capabilities and safety testing in its system card when the model launches.

– Ends

Published On:

Sep 2, 2026 17:08 IST

——————————————————-


Click Here For The Original Source.