OpenAI's Astra Model Labeled Critical Cyber Risk as Release Nears
OpenAI's Astra model is the first AI system rated a critical cybersecurity risk, prompting limited access and growing concern among researchers as its public release approaches.
By Priya Raghunathan · First published 3 Sept 2026
In brief
- OpenAI's Astra model has been rated as a critical cybersecurity risk for its ability to autonomously find and exploit vulnerabilities.
- The company has chosen to restrict access to Astra's most powerful cyber features to a small group of trusted users.
- Researchers and security experts have voiced concerns that Astra could worsen existing AI safety and cybersecurity issues.
- Despite the risks, OpenAI intends to move forward with Astra's launch after adding new safety measures.
- The rollout is underway, with Astra's capabilities and safeguards under close scrutiny by the tech and security communities.
Timeline · 7 moments
OpenAI announces plans to limit Astra's advanced cyber tools
Technology ↗Astra rated 'critical' cyber risk after internal testing
The Wall Street Journal Tech ↗Astra becomes first AI model at critical cybersecurity threshold
SecurityWeek ↗OpenAI says Astra needs more safety before launch
The Hill ↗Researchers warn of safety disaster ahead of Astra release
The Verge - All Posts Tech ↗OpenAI begins rolling out Astra model to select users
CNBC ↗OpenAI launches GPT-6 Astra amid scrutiny over agent safety
World News CNA ↗How it started
OpenAI has been developing increasingly advanced AI models, with Astra representing its latest leap in capability. Internal testing revealed that Astra could independently find and exploit zero-day vulnerabilities, a first for an AI system.
This discovery led OpenAI to classify Astra at the 'critical' level in its cybersecurity risk framework. The model's sophistication raised immediate red flags about its potential for misuse, setting off debates within the company and the wider AI research community.
How it unfolded
On September 1, 2026, OpenAI confirmed it would limit access to Astra's most advanced cybersecurity tools, citing the model's unprecedented risk level. According to internal reports, Astra was found capable of executing complex cyberattacks with minimal human input.
By September 2, outlets reported Astra had officially crossed the critical cybersecurity threshold, which applies to systems able to autonomously discover and exploit vulnerabilities across highly protected networks. This marked Astra as the first model to reach such a designation.
Researchers began to express significant concern about the safety implications of releasing Astra, warning that it could amplify ongoing AI-driven security and safety challenges. OpenAI responded by stating that stronger safeguards would be in place before Astra's public launch.
The company began restricting Astra's advanced features to select alpha testers, aiming to balance continued research with risk mitigation. Other tech companies, including Google and Anthropic, also announced new cybersecurity-focused AI models, but Astra's critical risk rating set it apart.
By early September, OpenAI started rolling out Astra, despite ongoing debates about its safety, and continued to highlight the model's advanced capabilities and the new security measures being applied.
Where it stands
Astra has now launched, but access to its most powerful cybersecurity tools remains tightly controlled. OpenAI maintains that it has introduced new safeguards and is actively monitoring the model's real-world use.
Researchers and cybersecurity experts continue to scrutinize Astra's rollout, watching for signs that the new safety measures are effective. The model's capabilities and the adequacy of OpenAI's restrictions are ongoing points of discussion as the release continues.
What to watch
Key questions remain about how well Astra's safeguards will prevent misuse, especially as more users gain access to its advanced features. Ongoing evaluation by both OpenAI and external researchers will be crucial in determining whether the company's risk management approach is sufficient.
The broader impact of Astra's release on the AI and cybersecurity landscape, and whether similar models from other companies will face comparable scrutiny, are also being closely watched.


