OpenAI stopped work on Astra after it crossed the Critical cybersecurity threshold
An internal review found the unreleased model had advanced far enough in agentic coding and cyber capability to meet the Critical bar in OpenAI's own Preparedness Framework — able to find and develop working zero-days in hardened real-world systems without human intervention. The company paused internal activities that did not yet meet strengthened security controls.
The threshold is written down, which is what makes this different from a vague safety gesture. Under the Preparedness Framework, Critical for cybersecurity means a model can identify and develop functional zero-day exploits of all severity levels across many hardened real-world critical systems without human intervention, or devise and execute end-to-end novel attack strategies against hardened targets given only a high-level goal.
OpenAI says Astra met it. The response was not a release with caveats. Internal activities involving the model that do not meet the strengthened control requirements are paused, universal monitoring is running across all agentic applications of Astra, and monitors read the chain of thought and can interrupt high-risk activity mid-run.
Two things are worth separating. A published threshold that a company then enforces against its own unreleased product is the first real test of whether these frameworks bind, and on the available evidence this one did. But the entire mechanism is self-administered — OpenAI wrote the bar, ran the evaluation, and graded itself, and no external party has seen the model or the results.
That is exactly the gap the federal machinery is trying to close. The executive order's benchmarking process would put a classified threshold and a government determination behind the same question. Today the only thing standing between a Critical-rated cyber model and the world is a company's own restraint, and it held.
TechCrunch — OpenAI says it slowed Astra model development over security concerns → · OpenAI — Responding to the next frontier of critical cyber capabilities → · OpenAI — Preparedness Framework version 2 →