DevOps / SRE / Platform · 07.08.2026, 21:10 UTC
The AI model OpenAI won’t release yet — and what it found in testing
| Schweregrad | info |
|---|---|
| Kategorie | DevOps / SRE / Platform |
| Quelle | The New Stack ↗ |
| Veröffentlicht | 07.08.2026 UTC |
Sicherheitsmeldung mit Schweregrad noch nicht bewertet. Technische Details im Tab „Originaltext“; empfohlene Schritte in der Checkliste.
OpenAI is reducing work on Astra after internal testing indicated the upcoming model may have reached a cybersecurity limit that no previous OpenAI model has ever hit. Although no official release date has been set, the speed bump could push back its ensuing release.
The company said it “cannot rule out critical cyber capabilities” in Astra, Axios first reported. It has paused internal activities that do not meet strengthened security requirements while it expands testing and tightens controls around the model.
What “critical” actually means
Under OpenAI’s Preparedness Framework, a model reaches the Critical cybersecurity threshold when it can identify and develop functional zero-day activities of all severity levels in many hardened, real-world critical systems without human involvement.
A model can also qualify by developing and performing a novel end-to-end attack against a hardened target after receiving only a high-level goal. Preliminary results were strong enough that the company could not confidently place it below that level.
For developers, the worry is that the skills making coding agents more useful can be turned against the software they were built to work on.
the skills making coding agents more useful can be turned against the software they were built to work on.
Testing in tighter isolation
Previous models, including GPT-5.6 Sol, were measured at the High cybersecurity level. OpenAI now treats Astra differently by testing it in isolated environments with tighter limits on the networks and tools it can access, because a Critical model requires …