What happened
OpenAI disclosed (Aug 7, 2026) that internal evaluations of its upcoming Astra model showed agentic coding/cybersecurity performance strong enough that it cannot rule out the 'Critical' cybersecurity capability level under its Preparedness Framework — the first time OpenAI has attached that label to a specific model — triggering stricter security controls, a pause on some internal Astra work, and new safeguard commitments.
Why it matters
This is the first frontier-model disclosure of potential Critical-tier autonomous exploit/zero-day capability, forcing enterprises and defenders to reassess assumptions about AI-accelerated attack timelines and driving new containment/access-control precedents other labs will likely follow.
Applicability
CISOs and AI governance teams at organizations using or evaluating frontier coding/agentic models should track Astra's eventual safeguard and access requirements before deployment.