What happened
OpenAI released GPT-6 Astra (Sept 3, 2026) with a published safety overview stating it is the first broadly-deployed OpenAI model to reach the 'Critical' cybersecurity capability level under its Preparedness Framework — able to autonomously find and exploit previously-unknown vulnerabilities in well-defended systems — shipping with new safeguards, restricted-access gating of the most powerful capabilities, and monitoring to stop unauthorized activity.
Why it matters
Marks a formal threshold crossing for frontier-model offensive cyber capability, forcing enterprises and defenders to reassess threat models for AI-assisted exploitation and requiring vendors of AI-security tooling to account for this new attacker capability tier.
Applicability
AI governance/security teams and Preparedness-Framework-adjacent policy teams should review the safety overview and adjust red-team/threat models now; frontier-model consumers with elevated access should audit safeguard compliance.