OpenAI said on September 1, 2026 that Astra now meets the Critical cybersecurity capability threshold in its Preparedness Framework. The company describes that bar as a model that, given the right tools and access, can find previously unknown flaws and build working exploits across many hardened systems without a person guiding each step. Astra is the first model OpenAI has placed at that level.

The lab says it delayed parts of Astra’s development and release while it hardened protections against cyber misuse and unauthorized model actions. It now believes those safeguards are strong enough to release the model under the framework. The most advanced cybersecurity workflows will not ship to every customer on day one. OpenAI plans a small alpha group first, then access through a program it calls Daybreak Blue for defensive use.

What the evals showed

OpenAI’s definition of Critical has two routes. Either the model can identify and develop functional zero-day exploits of all severity levels in many hardened real-world systems without human intervention, or it can plan and run end-to-end novel attacks against hardened targets from a high-level goal. The company says Astra meets that test.

On ExploitBench, which measures exploit development from known vulnerabilities, Astra scored 100 percent. Because of contamination risk, OpenAI also built an internal set of 20 high-severity V8 bugs disclosed between June and August 2026. Astra produced working arbitrary-code-execution exploits more often than GPT-5.6 Sol, and with fewer output tokens. During that run it found and used two zero-days in an exploit chain. OpenAI said it is disclosing those bugs to the maintainers.

In expert-led tests against a hardened browser and operating system, Astra built a full browser-compromise chain that escaped the sandbox and ran commands on the host when the browser opened an HTML file. It also chained local bugs into a privilege-escalation path from an unprivileged user to root. OpenAI notes that the published Astra numbers reflect Daybreak Blue access, not the default production configuration.

Safeguards and a delayed training run

The company frames two failure modes. A malicious user could ask Astra to write zero-days or run an end-to-end attack. The model could also take unauthorized cyber actions on its own if it is misaligned. After the OpenAI-Hugging Face incident, OpenAI paused some frontier training, including Astra work, for two weeks to tighten isolation, network controls, monitoring, and alignment thresholds. It says Astra was not involved in that incident, and that retrospective tests suggest the production stack at the time would have blocked it.

A larger reinforcement-learning run for future Astra versions stayed paused longer. OpenAI restarted that run on August 28 after the new training-environment rules were in place. Some smaller experimental runs remain held back.

On jailbreak evaluations, OpenAI says Astra refuses 91.5 percent of disallowed cyber requests, compared with 59 percent for GPT-5.6 Sol. Higher-risk accounts get a stricter refusal boundary. The company says launch-time safeguards will add more friction than it ultimately wants, and that a system card at launch will cover the rest of the safety and alignment testing.

Decoded Take

The news is not that a frontier model can find bugs. It is that OpenAI is willing to label one Critical, publish the eval story, and still put a ship date on the calendar. That combination is a product decision dressed as a safety paper: keep the default model useful, park the sharpest cyber tools behind Daybreak Blue, and tell defenders they will get there first. The numbers to watch are not the 100 percent ExploitBench score. Watch whether the two V8 zero-days are patched before launch, whether Daybreak Blue is a real access list or a waiting room, and whether the August 28 restart produces a follow-on Astra that OpenAI again has to hold. If the default product still writes working exploit chains, the Critical badge becomes a marketing line. If the alpha stays tiny, the badge becomes a reason to keep the model off most enterprise seats.