The OpenAI reported that its new model, called Astra, reached the maximum alert level in the Preparedness Framework, the first to attain this degree of risk. The decision was announced through the new edition of the AI Weekly bulletin and confirmed by TechCrunch on Wednesday, September 2, 2026. According to both publications, the model managed to exploit security vulnerabilities autonomously, even discovering a zero-day without human assistance. This level of proactivity in cyberattacks led the framework to classify Astra as 'Critical'. In response, the company announced that the model will be released to the public with serious usage restrictions, now selected to reduce immediate risks.
The Preparedness Framework is OpenAI's set of policies that defines threat levels associated with the capabilities of its systems, the same standard that now guides release decisions to date. The 'Critical' level sits at the top of the scale and signals that a model can cause harm in sensitive areas autonomously or with minimal oversight. In Astra's case, the core ability to find security flaws in third-party software was cited as the direct reason for the maximum classification. In a statement quoted by the publications, OpenAI says the security team had recommended accelerating usage investigations before any broad deployment occurs. For the sector, this is the first time an LLM system has independently reached this threshold, creating a precedent for other AI companies.

A zero-day is a vulnerability still unknown to the manufacturer and therefore without a ready patch — exactly the type of gap that drives serious attacks on servers, financial systems and governments. By finding them on its own, Astra demonstrates a technical leap that concerns part of the security community. On the other hand, the same capability could help legitimate companies actively search for vulnerabilities before criminals exploit them. OpenAI, however, enters a gray area that requires balancing technical capability with the obligation not to expose cyber weapons at scale. These restrictions should focus on limited access to accredited institutes, without release via open API. There are still no details on public testing windows or qualified rules for commercial partners.
This classification also repositions the AI-based security market, turning OpenAI from a provider of interfaces into an active protagonist in cyber-offense. In contrast, the approach of other labs such as DeepMind and Anthropic should now use the Astra case as a basis for their own standards, possibly accelerating internal reviews. Analysts note that the isolated identification of zero-days is a task that normally consumes time from professional teams and costs millions per year in research and automation. Now this step can fall to models trained like Astra, with controlled licenses. The only certainty published so far is that OpenAI prefers to limit early use rather than hinder executions. However, the highly sensitive nature of the topic suggests that new disputes will still arise for applications in this area.
The Astra case reopens the debate on how to validate models without closing the door to relevant benefits, especially in the field of cyber defense. The AI Weekly report and the independent TechCrunch analysis bring similar evidence, which reinforces the need for transparency when changes of this magnitude appear. Experts linked to OpenAI itself, under condition of anonymity, reinforce that the decision is taken on the premise of avoiding the risk that an advanced AI attacks global systems without control. Verification requirements, internal decision logs and adjusted training to prevent...? For these same reasons, the company's response is seen by regulators and the industry as an early step of intense ethical monitoring. The model remained heavy in fidelity tests, and new limitations may be disclosed as the scientific access round advances.
OpenAI confines Astra: first model to receive 'Critical' status in the Preparedness Framework; identified zero-days alone. OpenAI, Astra, Critical model, Preparedness Framework, zero-day, cybersecurity, AI security, restricted release AI, OpenAI, Astra, Preparedness Framework
Comments 0
Login to Comment
You need to be logged in to join the discussion
Loading comments...
No comments yet
Login to be the first to comment!